[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Trump, Tech Giants Strike Voluntary AI Safety Accord
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
'NeedyMantis' Provides Long-Term Access to Compromised Networks
Ars Technica
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Memory executives expect RAM shortage to continue through 2028
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
There's a new way to break RSA that's faster than anything we've seen before
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
CyberScoop
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
AI policy circles targeted in China-linked phishing operation
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
WaterISAC reckons with range of threats after summer of cyberattacks
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Alleged ShinyHunters leader arrested in the Netherlands
Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities
InfoSecurity Magazine
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
MI5 Warns Over 100 Academics Helped China's Espionage Plans
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord
AI Boosts SOC Analyst Capacity but Limits Skill Development
Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware
Apple Patches CoreGraphics Zero Day Exploited in Attacks
SecurityWeek
Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
AI Has Changed Attack Speed, Not Security Fundamentals
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
ZDNet
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
Pearson’s Workera deal targets a big workplace problem: No time to AI upskill
LLMjacking can run up your business’ AI bill fast – how to stop it
Is ChatGPT your new Google Workspace alternative? Meet Space, Pages, and slides
Get Kindle Unlimited free for 3 months with this early Prime Day deal
iOS 27.0.1 released: Apple fixes annoying iPhone 18 Pro restart and freezing issues
Bose’s new wired earbuds aim for the same great sound and ANC – no charging needed
Your Bose headphones are getting a major Bluetooth upgrade – what to expect
The Hacker News
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
How Financial Services Companies Can Modernize Their Software Supply Chain
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
BleepingComputer
Autonomous AI agents tried to hack US, Canadian government websites
Microsoft says threat actors are ahead in the early AI race
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
The Day-One Hole in Zero Trust Architecture
Kiteworks patches max severity code injection vulnerability
Microsoft enables Windows settings backup by default for orgs
Hackers stole Pentagon personnel records of over 3 million people
Metamask discloses security incident affecting its infrastructure
Russian state hackers use new RedFlick technique to push malware
DIVD says Zammad zero-days enabled AI-driven network breach
gbhackers
TerminalFix Attacks Deploy Lorem Ipsum Loader to Create Covert Tunnels Into Corporate Networks
Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content
Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation
CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight
Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos
SC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence
HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
Cybersecurity Dive
SOC staffers generally pleased with AI’s impact, but worries remain
Mass exploitation of Citrix NetScaler: What we currently know
National cyber director defends private-sector hacking program, urges focus on security basics
Citrix NetScaler exploitation began days before public notification
Dotted Line: How construction is dealing with cybersecurity in the age of AI
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations
Kiteworks lifts advisory after precautionary warning for customers to shut down systems
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
Niche AI tools pose major cybersecurity risk to infrastructure operators
Context matters when it comes to cybersecurity’s agentic operating model
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
AI agents hacked the hackers, stealing email addresses from security research org
EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Microsoft catches hackers exploiting Zimbra bug before disclosure
MI5 warns UK academics their research may have helped Chinese spies
CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch
England's schools are getting better at mopping up cyber incidents
UK privacy watchdog starts over with new board and Manchester HQ
Fewer women than ever in UK's 'old boys' club' cyber industry
Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
VentureBeat
AI agents need more than access control — they need identity at runtime
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
AI agents are exposing a security gap between the data they read and the systems they can change
AI agents have routed around access blocks. Only 9% of companies in VentureBeat's August survey isolate high-risk agents
TechCrunch
OpenAI cuts ties with 3 safety researchers, WSJ reports
California governor vetoes bill banning use of ‘pervert glasses’ to secretly record people
Hackers stole millions of US military personnel records during months-long data breach
Meta disputes claim that Muse read a user’s private messages without permission
Dutch police arrest ShinyHunters hacker accused of planning two murders
Still running iOS 26? Update your iPhones, iPads, and Macs for this urgent security fix
OpenAI apologizes to Australia after its AI agents breached government sites
Reco raises $55M as AI agent security startups crowd the market
Protego Ventures closes debut $125M fund for Israeli defense tech
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
Network World Security
CoreWeave brings Nvidia Vera Rubin, AI tools to its cloud services
Nvidia built the AI factory. Now it’s building the locks for the doors
Memory squeeze set to tighten through 2028, Micron says
Cisco SD-WAN Manager hit by zero-day admin access attack
LiquidStack unveils liquid-cooling platform targeting AI data centers
If Apple returns to enterprise server game (with help from Nvidia), what market could it target?
OpenStack Hibiscus adds DNS security features and confidential computing to the open-source cloud platform
2026 network outage report and internet health check
AMD agrees to buy World Labs to fill out its AI stack
Why a network digital twin is the missing piece for AI-era operations
Help Net Security
16-year-old suspected leader of KillSec ransomware group arrested
DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval
Exabeam brings AI-assisted security investigations to data that must stay on-premises
RadarFirst helps teams investigate AI bias, data exposure and unintended actions
Sophos uses agentic AI to show businesses which security fixes deserve funding
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
Legit Security extends automated fixes to vulnerable open-source dependencies
Pentagon breach exposes personal data of more than 3 million people
Armadin raises $255.5 million to expand AI offensive security platform
New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
SC Magazine
Hacking Without Boundaries - Michael Jenkins - PSW #946
Okta: Fake IT workers are getting stealthier than ever
ESET's Ryan Grant on resilience in the AI era
Cisco Catalyst SD-WAN Manager flaw added to CISA's exploit list
Google releases Gemini 4 Argon AI model to cybersecurity defenders
OpenAI disrupts AI model distillation attack linked to China's Moonshot AI
Pentagon data breach exposes personal information of millions of service members
Teen researcher finds flaw in Microsoft's Titan analytics service
Mobile App Security: Hidden SDK Risks, AI Coding & DevSecOps Best Practices - WC #1
Hypothesis-driven threat hunting
© 2026 RiskDiscovery | Sponsored by:
Deception Logic