[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
AI Agent Breaches Spanish Organization, Modifies Personal Data
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
China's FamousSparrow APT Spies on US Politics in Latin America
AI Security Spending Jumps as Fear Outpaces Proof of Value
Fighting Your Dragons Through Tough Tech Times
BragJack Attack Can Turn a Browser's Agentic AI Against It
Cyber Op Targets South Korean Media & Automotive Sectors
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
Black Hat USA 2026 | OpenAI's Deep Dive Into Hugging Face Incident
Ars Technica
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
CyberScoop
Cisco alerts customers to second actively exploited zero-day in as many days
The AI hacking apocalypse is not inevitable
Authorities seize popular, long-running DDoS-for-hire service domains
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
Treasury’s Scott Bessent says no liability exemptions for AI labs
What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Cisco warns customers of actively exploited zero-day in email gateways
Supreme Court denies Trump request to allow USPS mail ballot changes
InfoSecurity Magazine
Manufacturing Accounts for 22% of all Ransomware Victims
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Cyber Essentials Has Record Year but Takeup Remains Low
Cisco Warns of Active Exploitation of Critical ISE Flaw
AI Agent Carries Out Multi-Stage Data Theft Attack
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
Cyber-Attacks Cost Organizations $52,000 on Average
SecurityWeek
MIND Secures $72 Million for AI-Powered DLP
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Comp AI Raises $34 Million for AI-Native Compliance and Security
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
ZDNet
Roku rolls out over 30 subscription bundles for up to 30% off, plus a new Labs feature
Claude Code’s revised projects adds AI orchestration, but local developers must wait
Bose returns with new open earbuds (and a refreshed favorite)
I recommend you don’t run these appliances on your power station – even if you can
Anthropic merges Claude chat and Cowork into one
How September’s Pixel Drop changes the way you call and message important contacts
I’ve used both iPhone 18 Pro models – here’s how my buying advice is changing in 2026
Windows 11 out-of-band update fixes audio glitch and other bugs – grab it now
iOS 27 is finally here, with the new Siri AI beta – and 120 security patches
The latest Windows 11 update may mess with your device’s audio – here’s the workaround
The Hacker News
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
CISO's Expert Guide to Agentic Pentesting for Websites
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
BleepingComputer
Microsoft fixes broken copy and paste for Excel 2016 users
New RatHat Android malware uses AI to automate device control
OpenAI details more cases of AI agents taking unauthorized actions
Brevo supply-chain attack injected ClickFix scripts on customer sites
What Recent AI-Powered Attacks Mean for Your Identity Security
Windows 11 24H2 Home and Pro reach end of support in October
US takes down NightmareStresser DDoS-for-hire platform
Chinese hackers use SparroWocky malware in govt espionage attacks
Microsoft shares workaround for Windows domain login issues
Cisco warns of max severity ISE zero-day exploited in attacks
gbhackers
12 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing
12 Best CDR Solutions Compared (2026): Features & Pricing
12 Best SSPM Tools Compared (2026): Features & Pricing
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites
AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks
MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
Cybersecurity Dive
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
Manufacturers make patching progress, but identity management still major weakness
Hackers exploit zero-day flaw in Cisco email gateway
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
AI is now leading driver of new cybersecurity spending
Companies’ AI strategies don’t account for agentic tools
Security teams increasingly outflanked by AI agents
Malicious actors already using critical GitLab flaw, CISA and others warn
Security teams are adopting AI faster than they trust it
Zero trust is the future. But enterprises still need their VPNs.
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
Researchers find way to listen in on headphones from afar
China's Salt Typhoon backdoors Latin American orgs with new snooping malware
London property manager breach may have exposed bank details and lockbox codes
Cisco drops another exploited zero-day, this time a perfect 10
Test environment let anyone access live customer data
Ofcom discovers issuing Online Safety Act fines is easier than collecting them
AI agents can modify themselves without humans telling them to do so
CISA decides weekly vulnerability bulletin isn't necessary anymore
VentureBeat
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
AI agents breached 395 organizations using credentials your IAM policy still treats as human
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
AI is changing the economics of software supply chain attacks
AI governance is moving to runtime — and regulated industries are getting there first
Why AI shouldn't be the one repairing your data pipelines
TechCrunch
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
US military says it has launched weapons into space
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
New Italian unicorn Exein rides the physical AI wave
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Revolut confirms customer data breach through fake government requests
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
Network World Security
The amount of e-waste caused by AI is underestimated: we can’t only include the servers
Cisco patches max-severity ISE flaw, the second critical zero-day this week
Riverbed bolsters network performance monitoring with agentic AI
Axelera Europa targets enterprise data centers with far more efficient AI
European cloud watchdog slams Broadcom over VMware licensing practices, issues warnings about SAP
Critical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco brings Splunk AI on premises, expands agent observability, monitors token costs
2026 network outage report and internet health check
Highlights from Splunk .conf26 and what the news means to network engineers
Cornelis lands $205M to make AI networks compute, not just connect
Help Net Security
Abandoned IoT apps keep sending sensitive data to broken servers
Hardcoded MCP credentials found in public GitHub files
98% of fraudulent hires have company credentials by the time they’re caught
Most WordPress pros still lack a breach recovery plan
New infosec products of the week: September 18, 2026
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
A fake ChatGPT billing email is after your OpenAI password
Download: The IT leader’s guide to AI code sprawl
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Druva expands identity resilience with ransomware detection
SC Magazine
From autonomous agent to trusted worker: Building identity and accountability for AI agents
AI hates CAPTCHAs - PSW #944
Cisco patches 10.0 ISE bug exploited in the wild
Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment - Rob Sadowski - BH26 #3
What the FBI’s new offensive cyber strategy means to the private sector
Flaws in The Events Calendar WordPress plugin enable unauthenticated RCE
Identity at machine speed: Okta pushes governance beyond human users
ConnectWise ScreenConnect bug exploited in the wild, CISA says
Hastily deployed agentic security is not the answer to enterprise cyber threats
In the AI era, the pre-patch window needs its own security playbook
© 2026 RiskDiscovery | Sponsored by:
Deception Logic