[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
SWIFT Banking & Government Middleware Enables RCE
Is Your Organization Ready for 2027's AI Accountability Era?
Is It Fair to Blame 'Rogue' AI for Security Failures?
Vulnerability Backlogs Are an Ownership Problem
Malicious Linux Implants Mimic Asian Mail Security Products
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Ars Technica
Apple changes full-disk access permissions to curb abuse from AI agents
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Memory executives expect RAM shortage to continue through 2028
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
There's a new way to break RSA that's faster than anything we've seen before
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
CyberScoop
The legal questions raised by agentic AI hacks
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
AI policy circles targeted in China-linked phishing operation
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
WaterISAC reckons with range of threats after summer of cyberattacks
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Alleged ShinyHunters leader arrested in the Netherlands
InfoSecurity Magazine
More UK Schools Are Recovering Faster from Cyber Incidents
Frontline Education Breach Impacts K-12 School District Staff
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Police Target KillSec Ransomware Group with Arrests and Seizures
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
MI5 Warns Over 100 Academics Helped China's Espionage Plans
SecurityWeek
Alleged ShinyHunters Leader Arrested in Jordan
Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
Fortra Patches Critical Vulnerabilities in BoKS
In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Crypto Scammers Hijack Microsoft’s Official X Account
In Rare Move, Alleged Iranian State Hacker Extradited to US
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
ZDNet
iPhone 18 Pro Max can’t call or text on AT&T? Apple will replace it for free
This new ChatGPT scam tricks you into installing malware – how to spot the trap
Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
Pearson’s Workera deal targets a big workplace problem: No time to AI upskill
LLMjacking can run up your business’ AI bill fast – how to stop it
Is ChatGPT your new Google Workspace alternative? Meet Space, Pages, and slides
Get Kindle Unlimited free for 3 months with this early Prime Day deal
The Hacker News
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
BleepingComputer
Google halts open-source bug bounty program amid AI spam surge
Citrix patches NetScaler SAML zero-day exploited in attacks
Anthropic asks Claude users to share voice data for AI model training
Google Gemini could soon get full access to your Mac’s files, apps and the web
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
Danish university DTU breach exposes data of up to 200,000 people
Frontline Education breach exposes school district employee data
Warlock ransomware breach SharePoint in water, telecom operator attacks
GitLab warns of critical RCE vulnerability in AI Gateway service
US sanctions Tren de Aragua gang members in ATM hacks crackdown
gbhackers
Autonomous AI Agent Chains Two Zammad Zero-Days in Machine-Speed Cyberattack
12 Best ITDR Tools Compared (2026): Features & Pricing
CISA Adds Zammad Vulnerabilities to KEV Following Active Exploitation
11 Best CIAM Solutions Compared (2026): Features & Pricing
12 Best Passwordless Authentication Solutions Compared (2026): Features & Pricing
GlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes
Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access
Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940
South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks
Google PageBreak AI Agent Finds Over 500 XSS Vulnerabilities Across Its Web Applications
Cybersecurity Dive
Modernizing data security with DSPM, AI and fewer tools
Why permissions must be the foundation for next-gen identity security
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Fortinet warns that critical flaw in FortiMail is facing exploitation
SOC staffers generally pleased with AI’s impact, but worries remain
State-linked actor targets US AI policy experts in credential phishing campaigns
Mass exploitation of Citrix NetScaler: What we currently know
National cyber director defends private-sector hacking program, urges focus on security basics
Citrix NetScaler exploitation began days before public notification
Dotted Line: How construction is dealing with cybersecurity in the age of AI
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse
Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval
OpenAI's wandering AI agents earn it a California subpoena
Fortinet sounds the alarm over actively exploited FortiMail zero-day
AI agents hacked the hackers, stealing email addresses from security research org
EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Microsoft catches hackers exploiting Zimbra bug before disclosure
MI5 warns UK academics their research may have helped Chinese spies
VentureBeat
AI agents need more than access control — they need identity at runtime
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
AI agents are exposing a security gap between the data they read and the systems they can change
AI agents have routed around access blocks. Only 9% of companies in VentureBeat's August survey isolate high-risk agents
TechCrunch
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Federal judge calls Flock ‘indiscriminate mass surveillance’
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
OpenAI cuts ties with 3 safety researchers, WSJ reports
California governor vetoes bill banning use of ‘pervert glasses’ to secretly record people
Hackers stole millions of US military personnel records during months-long data breach
Meta disputes claim that Muse read a user’s private messages without permission
Network World Security
From automated response to reasoning: Building confidence in AI-driven NetOps
Startup doxx.net hands the network controls to AI
IBM’s Bob wants to move in: Agent available for on-prem deployment
$6T in annual AI revenue needed to pay off data center investments
HPE’s Rahim: Pace of change in the data center is ‘extraordinary’
CoreWeave brings Nvidia Vera Rubin, AI tools to its cloud services
Nvidia built the AI factory. Now it’s building the locks for the doors
Memory squeeze set to tighten through 2028, Micron says
Cisco SD-WAN Manager hit by zero-day admin access attack
LiquidStack unveils liquid-cooling platform targeting AI data centers
Help Net Security
Apple tightens macOS disk access as AI agents become more powerful
doxx.net opens Agentic Defined Networking public beta, raises $38 million
AI slop submissions force Google to freeze its open-source bug bounty
Three questions a hospital CISO should ask a healthcare fintech vendor
Keyorix: Open-source secrets management for teams that can’t use SaaS
How RMM abuse gives attackers a way in that looks like business as usual
Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
AI is giving attackers a head start, Microsoft warns
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
SC Magazine
State of the AI SOC, regulating AI, and can AI agents feel pain? - Aqsa Taylor - ESW #479
Scammers increasingly target mobile users with banking fraud
Frontline Education data breach exposes employee Social Security numbers
Researchers bypass AI agent protections with JavaScript obfuscation
Microsoft X account hijacked for crypto scam
New Linux malware mimics network edge appliances to evade detection
Epic pauses product development amid cybersecurity concerns
AI agent control emerges as infrastructure priority amid rapid development
GitLab warns of critical AI Gateway vulnerability allowing command execution
Cybersecurity concerns rise for physical access control systems
© 2026 RiskDiscovery | Sponsored by:
Deception Logic