[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
[Virtual Event] Building a Secure AI Strategy for the Enterprise
EU Cyber Resilience Act to Enforce New Reporting Requirements
Mythos Vulnerability Firehose Hits a Human Bottleneck
US Government Accuses Chinese AI Firms of Distilling Frontier Models
Identity-Based AI Attack Threatens Security of Enterprise Data
Patch Tuesday Sets Another Record With 974 CVEs
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Ars Technica
4 groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent
I rented a car, and within hours, my driver's license was for sale
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Think twice before installing this device promising free movies
CyberScoop
Chinese espionage groups swarm to exploit triple-link chain of zero-days
FTC rescinds policy requiring health apps to notify customers after a breach
Lawmakers call on Treasury to sanction hackers-for-hire
FBI cyber chief worries private sector not sharing enough cyber threat information
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Feds accuse China of ‘systematic’ distillation of U.S. AI models
Russian national extradited to US for alleged involvement in bank-account takeover scheme
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Why federal cyber defense demands an offense-driven mindset
InfoSecurity Magazine
MantaxOtax Android Malware Combines Ransomware With Spyware
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
Anthropic Reveals Yet Another Cybersecurity Incident
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Gigabud Uses Android App Cloning to Evade Fraud Detection
ClickFix Moves into the Browser to Steal Cryptocurrency
NHIs Now the Number One Corporate Entry Point for Hackers
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
SAP Patches Maximum Severity “Overpass” Flaw
SecurityWeek
Critical NetScaler Vulnerability Exploited in Attacks
Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
4.1 Million Impacted by AdaptHealth Data Breach
Organizations Warned of Cisco Secure FMC Exploitation
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
HelmGuard Raises $7.3 Million for Agentic GRC and Security
AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
Android’s September 2026 Updates Patch 180 Vulnerabilities
Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
ZDNet
The Hacker News
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
BleepingComputer
Microsoft says September updates fix mouse settings reset issues
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
Microsoft fixes bug that wiped Windows desktop settings
Trezor warns users of email provider breach, phishing attacks
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
AdaptHealth confirms 4.1 million people exposed in July cyberattack
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
US says Chinese firms extracted billions of tokens from frontier AI models
Veradigm warns of patient data breach after ransomware gang claims attack
MFA's Weakest Link: Account Recovery Is the New Attack Path
gbhackers
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
OpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits
Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
12 Best Application Control & Allowlisting Tools Compared (2026): Features & Pricing
Cybersecurity Dive
CISOs are feeling the security burden of accelerated AI use
New FBI cyber strategy promises increase in adversary disruptions
N-able issues patch for zero-day flaw
Don’t let AI distract from cybersecurity basics, officials and executives warn
Essential AI agent security questions
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
OpenAI pledges $1B to provide resources, training for frontline cyber defenders
SonicWall urges immediate patching of chained vulnerabilities
Government, industry partner to shut down long-running Sality botnet
Government lacks ability to verify AI labs’ claims, experts say
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
ShinyHunters expose 6.4M in attack on medical supplier McKesson
Dental contractor set up secret account with access to 4,000 patient records then left the company
Anthropic reveals fourth likely crime committed by its AI
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Serial Microsoft 0-day hunter drops yet another Defender exploit
WeChat worm could pwn a friend before they even answered the call
Microsoft breaks Patch Tuesday record with 974-CVE deluge
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Boston Scientific left nursing its bottom line after cyberattack
How to secure hybrid meeting rooms without sacrificing user experience
VentureBeat
Agents identifying as OpenAI systems wrote 17,000 posts to a wiki no one was supposed to write to
Most security teams don't know how many AI agents they're running. Falcon Guardian found 18,000 at one company that had approved only 300.
MCP's new spec turns a planted prompt into a stolen credential
China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using
Google’s Gemini 3.8 Flash is built for agents, while its Cyber twin hunts vulnerabilities
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.
TechCrunch
‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
A hacker stole $340M in a crypto heist, then returned most of it
OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure
US military disabled ad tracking on troops’ devices following reports of targeted attacks
Abliteration.ai is making a business out of removing AI guardrails
It sure looks like hackers breached a major ID card verification service
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
Network World Security
MikroTik patches flaws currently being exploited to take over routers
Leap second proposal will keep software stacks in sync
Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
BackBox brings AI to network automation but keeps humans in control
2026 network outage report and internet health check
AI data boom fuels tape storage resurgence
Nvidia lets you build your own AI clusters locally with PAIR software
When analyst benchmarks miss the mark: Why Nvidia doesn’t fit Forrester’s data center matrix
HPE’s record Q3: AI infrastructure, networking demands drive growth, but supply constraints tap the brakes
VMware Cloud Foundation 9.1 adds transit gateway flexibility, segmentation, and native EVPN VXLAN support
Help Net Security
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
Scytale expands vendor risk management with AI-powered TPRM tools
WordPress adds automated security checks to block risky plugin releases
Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Apple is building photo verification for the people who need it most
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Cybercriminals are building phishing pages that exist only inside victims’ browsers
AI adoption brings new security headaches for already stretched CISOs
A new open standard locks AI weights to approved hardware
Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity
SC Magazine
Gigabud banking trojan uses app cloning to evade fraud detection
Over 36,000 Plex media servers remain unpatched against security vulnerabilities
US lawmakers ask government to ban 3 hack-for-hire firms
Pentagon weighs CMMC reforms after industry feedback
Orchid Security adds AI agent controls to identity platform
Web DDoS attacks more than double in 1st half of 2026, Radware report finds
Shai-Hulud npm worm resurfaces, bypassing security scans
Geordie AI launches cost intelligence for enterprise AI spending
Chinese state-linked hackers exploit Chrome vulnerability
New WeWorm tool hacks Android and iOS phones via WeChat calls
© 2026 RiskDiscovery | Sponsored by:
Deception Logic