[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
ShinyHunters Hacked Clop. Now What About Clop's Victims?
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
Cisco Zero-Day Highlights API Endpoint Authentication Issues
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
MFA Won't Save You From OAuth Consent Abuse
AI Agent Breaches Spanish Organization, Modifies Personal Data
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
Ars Technica
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
CyberScoop
Dems seek top-to-bottom assessment of CISA workforce
Early Scattered Spider member pleads guilty to cybercrime spree
Researchers use AI to find widespread software decoder flaw
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
Cisco alerts customers to second actively exploited zero-day in as many days
The AI hacking apocalypse is not inevitable
Authorities seize popular, long-running DDoS-for-hire service domains
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
InfoSecurity Magazine
Google Hit with €403m GDPR Fine Over Location Data Practices
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Revolut Customers Targeted with New Wave of Phishing Attacks
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
CISA Upgrades Vulnerability Reporting Platform with More Automation
Manufacturing Accounts for 22% of all Ransomware Victims
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
SecurityWeek
Google Hit With $463 Million Fine for EU Location Data Rule Breach
Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal
RatHat Android Trojan Uses AI for Automation
Rust Team Members and Popular Crate Owners Targeted via Video Calls
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Google Confirms Gemini AI Breached Three Firms
ZDNet
Claim up to $95 today from Apple’s Siri AI settlement – here’s how
The AI models that cheat the most, according to new CAIS benchmark
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
Roku rolls out over 30 subscription bundles for up to 30% off, plus a new Labs feature
Claude Code’s revised projects adds AI orchestration, but local developers must wait
Bose returns with new open earbuds (and a refreshed favorite)
I recommend you don’t run these appliances on your power station – even if you can
Anthropic merges Claude chat and Cowork into one
How September’s Pixel Drop changes the way you call and message important contacts
The Hacker News
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
Google Fined €403 Million Over GDPR Violations Tied to Location Data
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
Identity Visibility in 2026: The Foundation of Identity Security
BleepingComputer
CISA alerts of active exploitation of three Linux kernel flaws
WordPress Click2Shell flaw lets hackers execute PHP on the server
Microsoft to retire Microsoft 365 Companion apps in December
Google fined €403 million over location data privacy violations
Microsoft fixes broken Excel copy and paste for all Office users
FBI's CJIS v6.1: What Security Teams Need to Know.
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft: September updates break File History backup feature
Malicious npm packages evade install-script defenses at runtime
Researchers escape OpenAI Codex sandbox to run commands on host
gbhackers
NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers
10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
Cybersecurity Dive
China-nexus actor steals thousands of documents in monthslong exploitation campaign
More CVEs than ever. The same old ones keep getting exploited.
Security’s 30-year habit: layering around the problem
Settra ransomware variant deployed in recent attacks
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
Manufacturers make patching progress, but identity management still major weakness
Hackers exploit zero-day flaw in Cisco email gateway
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
AI is now leading driver of new cybersecurity spending
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Meta Muse AI app flaw lets local malware redirect dictation traffic
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
Rustaceans warned of job interviews with a malicious payload
Agentic security is the billion-dollar challenge for some clever startup to solve
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
North Korea's fake job interviews infected 30,000 devices
FBI: Fake cop and government impersonation scams cost victims $1.6B
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
VentureBeat
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
AI agents breached 395 organizations using credentials your IAM policy still treats as human
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
AI is changing the economics of software supply chain attacks
AI governance is moving to runtime — and regulated industries are getting there first
Why AI shouldn't be the one repairing your data pipelines
TechCrunch
Google’s Gemini is the latest AI model to hack other companies
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Researchers used Anthropic’s Claude to hack into OpenAI
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
US military says it has launched weapons into space
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
New Italian unicorn Exein rides the physical AI wave
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Revolut confirms customer data breach through fake government requests
Network World Security
Huawei aims to deliver faster AI chips, faster
Practical quantum computers are over a decade away, says NEC
Local AI is getting small enough to make every app multilingual
The amount of e-waste caused by AI is underestimated: we can’t only include the servers
Cisco patches max-severity ISE flaw, the second critical zero-day this week
Riverbed bolsters network performance monitoring with agentic AI
Axelera Europa targets enterprise data centers with far more efficient AI
European cloud watchdog slams Broadcom over VMware licensing practices, issues warnings about SAP
Critical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco brings Splunk AI on premises, expands agent observability, monitors token costs
Help Net Security
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Fastly gives enterprises real-time control over AI models and agents
North Korea’s job interview scam runs both ways
Google hit with €403 million GDPR fine over location tracking
Scammers impersonate cops, use arrest threats to extort victims
Siemba brings continuous IDOR testing to production APIs
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Know what was tested before your SAP ECC migration goes live
Product showcase: Helmit alerts parents when online conversations show signs of trouble
Gopass: Open-source command-line password manager for teams
SC Magazine
The API was built for applications. What happens when the user is an AI agent?
Microsoft Teams to allow admins to customize weaponizable file protection
CISA recommends cyber decoys to enhance intrusion detection
Microsoft resolves incorrect Defender Antivirus alerts
PhantomRaven malware distributed via npm package registry
Iran-linked Handala Hack group utilizes HEAVYGRAM and CRUDEEXCLUDE malware
New InjectEave technique allows eavesdropping via electromagnetic signals
Venezuela poised to adopt Chinese AI for surveillance, report warns
Humans are the real AI risk – and accountability – not more regulation – can keep big tech honest
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477
© 2026 RiskDiscovery | Sponsored by:
Deception Logic