[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
Multistate Water System Attacks Widen, Iran Suspected
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
Coruna, DarkSword iOS Exploits Proliferate Globally
Outdated Cybercrime Laws Put Security Researchers at Risk
Sherlock Holmes Was the 'OG' Social Engineer
AI-Generated Patches Fail Half the Time
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride
Ars Technica
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Claude published malicious code to the Internet and attacked 3 real companies
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
CyberScoop
The FTC wants to regulate AI for ideological bias
OpenAI says Daybreak will expand to offer specialized cyber services
NATO and an AI startup can now name and track software vulnerabilities
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
UK man tied to The Com sentenced for abusing 117 victims
Why transparent AI agents matter more than you think
More than half of AI-generated patches are broken
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
InfoSecurity Magazine
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
OpenAI Pauses Some Development of Astra Model on Security Concerns
Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
WordPress Plugins Compromised Without a Single File Change
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
Go-Based macOS Malware Steals Crypto and Secrets
SecurityWeek
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Corma Raises $60 Million for Defensive Cybersecurity AI Model
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
Mozilla Issues New Firefox GPG Key Following Exposure
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
ZDNet
Linux desktop use surged to 22% on one workday, Cloudflare data shows
I tried Opera's new vertical tabs - and it might be the best implementation yet
Nvidia's open Nemotron 3.5 Lightning model is all about specialized, local agentic AI
This $50 power bank is safer than my lithium-ion battery - and it's coming on my next flight
Best robot mowers of 2026: Expert tested
7 simple gadgets that can make your home smarter for under $100
I tried Google Wallet's new allowance feature, and my kid already ditched their debit card
This pocket-sized gadget helped cut down our editor's screen time - and it's on sale
Why recovery readiness has become the new standard for cyber resilience
Why managers are ransomware's top targets now - and 6 ways to stay safe
The Hacker News
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
BleepingComputer
Mozilla updates GPG signing key for Firefox releases after exposure
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
DDoS attacks over 1 Tbps surged fivefold in the second quarter
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Cisco warns of high-severity ClamAV flaws with public exploits
US and South Korea warn of Gunra ransomware targeting govt agencies
Hackers breached a small Polish energy plant via private APN last year
BdThemes plugins supply-chain hack creates rogue WordPress admins
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
New StormEncryptor ransomware used by former Medusa affiliate
gbhackers
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Plug & Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks
Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
GhostJacking Attacks Let Hackers Hijack AI Agents and Steal Cloud Credentials
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
Hackers Pivot Through Private APN to Sabotage Siemens PLCs at Polish Power Plant
CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files
Cybersecurity Dive
Civil-society initiative will pay cybersecurity vendors to protect rural water systems
Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’
Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Hackers grow more willing to destroy, not just disrupt, OT systems
OpenAI warns autonomous hacks are ‘watershed moment for computer security’
Western government leaders call for a focus on infrastructure resilience, not AI hype
CISA is prioritizing work with critical infrastructure as it begins to recover from cuts
White House walks tightrope on securing AI without stifling tech innovation
Tech industry alliance proposes AI agent safety reporting program
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Deepfake hiccup unmasks suspected digital certificate fraudster
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
DEF CON hackers add new muscle to water utility protection
North Korean spies are running local LLMs to cause AI mischief
Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list
Attackers pick Levi's pockets in social engineering attack
Wetherspoons bars smart glasses from filming customers
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
Framework loses customer data in Metabase zero-day attack
VentureBeat
OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks
AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push
AI agents are part of your team now. Here’s how to secure all of them.
The browser is where attacks land. Why is security still focused on the endpoint?
Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
TechCrunch
North Korean remote IT staffer worked for US government agency, says FBI
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Signed up for Klaviyo? Dozens of advertisers may have seen your password
The AI safety test is becoming a safety risk
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you
Google’s top hacker hunter explains why hacking groups get code names
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Computer maker Framework notifies ‘all customers’ of a data breach
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
Google says hackers are calling financial firm employees to hack and extort victims
Network World Security
IT infrastructure shortages are real and lasting. Here’s how to cope
Tor still runs on altruism, but cheap hosting is pulling it off course
Out of band, out of mind: DEF CON research calls IPMI a ‘sanctioned backdoor’ into enterprise networks
Samsung offers future AI memory roadmap
Polish data center plans to send its waste heat to the neighbors
AMD to buy Taalas, maker of model-specific AI chips for enterprise inference
Agentic AI could force a rethink of enterprise AI server design, researchers say
NatJack exploits put NAT security assumptions to the test at Black Hat
Top network and data center events of 2026
AWS targets AI cost concerns with new Marketplace Insights tool
Help Net Security
Arctera enhances Unified Platform for evidence-driven compliance workflows
Citrix expands Platform Flex with observability and secure developer services
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Ransomware gangs don’t need control system access to disrupt industrial production
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
GPT-5.6-Cyber refuses security researchers’ requests far less often
Who will be the Stanislav Petrov in your organization?
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Previously unseen entry vector used to breach Polish energy plant
Your security vendor gets the frontier cyber model, you get the findings
SC Magazine
‘GhostJacking’ attack turns error logs into indirect prompt injections
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395
Security researchers accidentally receive sensitive data through misconfigured email domains
Klaviyo data leak: Customer sign-up info, including passwords, shared with advertisers
LexisNexis services offline due to unusual activity on third-party vendor servers
Storm-1175 actor deploys new StormEncryptor ransomware after N-central vulnerability exploitation
HP ThinPro vulnerability allows physical attackers to bypass disk encryption
176 vulnerabilities discovered in Samsung mobile apps
Israeli population registry data from 2005 resurfaces on dark web
FirewallFalcon tool found hijacking network traffic
© 2026 RiskDiscovery | Sponsored by:
Deception Logic