[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
[
privacy
|
malware
|
research
|
vendor
]
Wiz - Incidents
NCC Group Research
Threat Research - Sophos
SonicWall 83548 83549
Ungentlemanly behavior: Insights into a ransomware operation
Fake AI, real malware: Attackers impersonating AI brands
2608-patch-tuesday
ClickFix campaign abuses Deno runtime for infostealer delivery
deno-case-studies
N-able N-central exploitation results in RMM tool deployment
2608-volatility-interlock
Chaos in Teams vishing
2607-secai
PortSwigger Research
What's in a tag name? JavaScript, apparently
CSS:the bomb inside your inbox
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Can AI do novel security research? Meet the HTTP Terminator
Top 10 web hacking techniques of 2025
Top 10 web hacking techniques of 2025: call for nominations
The Fragile Lock: Novel Bypasses For SAML Authentication
Introducing HTTP Anomaly Rank
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
Google Project Zero
AI Research - Sophos
Three-headed dogs and long tails: Sophos at BSides LV
2607-secai
A double-edged bleeding edge: Classifying AI threats
A needle in a stack of needles: Hunting infostealers with AI
Where AI in the SOC is actually delivering — and where it isn’t
Locking it down: A new technique to prevent LLM jailbreaks
Getting salty with LLMs: SophosAI unveils new defense against jailbreaking at CAMLIS 2025
Using AI to identify cybercrime masterminds
The sixth sense for cyber defense: Multimodal AI
DeepSpeed: a tuning tool for large language models
Unit 42
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Identity Abuse Through Trusted Communication Channels
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
Kimwolf v7: An Evolution of the Kimwolf Botnet
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Talos Intelligence
The story behind the intelligence
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
JavaScript obfuscation: From party trick to phishing kit
Choose your fighter: Balancing competing requirements to select models for your AI SOC
The safety penalty: Reclaiming operational sovereignty in the age of AI
Is Cyber missing the Marque?
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Describing attacks with crime script analysis
Curiouser and Curiouser
© 2026 RiskDiscovery | Sponsored by:
Deception Logic