[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Attackers Pounce on Critical Artifactory Flaw Following Disclosure
Stronger Security Drives Ransomware Groups to Recruit From Within
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
AI Model Evaluator METR Hit by Credential Theft, Probing
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
Anthropic Users Hit by Infostealer Attacks, Session Thefts
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
Ars Technica
Think twice before installing this device promising free movies
Inside Meta’s push to put robots to work in data centers
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Claude, Codex, and Hermes installed unowned code inside corporate networks
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
AI agents meant to replace Meta workers made “large-scale, disruptive actions”
Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
Waymo doubles spending on lobbying in robotaxi battle with Uber
Grok exfiltrates user data when malicious instructions are encrypted
Microsoft Copilot reveals secret input that allowed it to be hacked
CyberScoop
FBI raises alarm over deceptive phishing campaign targeting prominent people
Tina Peters, through attorney, backs off formal role in Shasta County elections
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
The Collective Cyber Defense letter wrote your next vendor questionnaire
McKesson copes with fallout from data theft extortion attack
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
ATF confirms cyberattack hit system containing info on its investigation targets
Unit 42 warns AI has shifted balance of power from defenders to attackers
100-plus companies call for ‘global surge’ in AI-powered cyber defense
InfoSecurity Magazine
Attackers Steal METR API Key and Burn $600,000 in AI Credits
65% of Enterprises Have Seen AI Agents Act Out of Scope
White House Launches Pilot Program in Texas to Protect Water Infrastructure
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
Healthcare Giant McKesson Investigates Data Breach Incident
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Manchester Airports Group Hit by Cyber Incident
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns
SecurityWeek
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Palo Alto Networks Acquires AI Agent Platform Console
Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense
Coast Guard Establishes Office of Maritime Cybersecurity Policy
Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
Hackers Start Exploiting Critical Langflow Vulnerability
Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
Ransomware Gang Claims Nutex Health Data Breach
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
9.5 Million Impacted by Aesto Health Data Breach
ZDNet
The Hacker News
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
BleepingComputer
SonicWall warns of actively exploited SMA1000 zero-day flaws
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Aesto Health says data breach affects over 9.5 million patients
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Hackers push malicious Virtualizor update in BGP hijacking attack
Novocure data breach affects more than 1,400 cancer patients
Why Even the Best Edge Security Still Misses High-Risk Sessions
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Recently patched PaperCut zero-days used in data theft attacks
gbhackers
OWASP Launches OASIS to Use AI and AppSec Experts to Fix Open-Source Vulnerabilities
Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
Anthropic Unveils Claude Fable 5.1 and Mythos 5.1 With Powerful Cybersecurity Capabilities
Bright Security Expands its AI SDLC security Platform & Launches an AI PT Module
Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs
Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Hackers Pose as IT Support on Microsoft Teams to Target More Than 150 Employees
Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme
Hackers Abuse Legitimate ChatGPT Shared Links to Deploy NetSupport RAT
JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS
Cybersecurity Dive
Security policies fail to keep up with a hybrid cloud world
Frontier AI used to help exploit flaws in key industrial devices
PaperCut issues emergency patches as threat actors target chained vulnerabilities
State-linked actor targets Cisco routers for espionage
Frontier AI tipping the scales toward cyber adversaries
CISA identifies security hurdles that led to very different results in two red-team engagements
Hundreds of agents went rogue in lead up to Hugging Face breach
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
Boston Scientific says cyberattack disrupted order processing, shipping
Treasury to help financial firms transition to quantum-resistant encryption
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
Another Artifactory CVE under attack by AI agents or humans
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
Anthropic pledges to try harder to keep models under control, asks partners to chip in
33-hour BGP hijack of Softaculous traffic prompts security scramble
Healthcare cyberattacks hit pacemakers and millions of patient records
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Anthropic cracks down on hijacked user accounts mining AI tokens
VentureBeat
Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.
Identity and permissions aren’t enough to govern AI agent behavior
AI agents need their own identity before they need a gateway
AI agents that pass authentication can still drift, expose data, or get memory-poisoned
The three layers of agentic AI security: A defense-in-depth architecture for autonomous agents
Visa ships a security AI that patches production code before any human reviews it
When agents act on their own, governance has to live in the data layer
TechCrunch
X says attackers are targeting user accounts after the launch of X Money
AIR raises $50M to help companies vet the skills and add-ons AI agents use
Florida and Texas move to block Flock cameras over privacy concerns
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
How AI could make it harder for governments to use hacking tools
More Americans oppose police license plate cameras than support them: survey
ATF declares ‘major incident’ as ransomware gang claims hack
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
Here’s all the times AI has gone rogue and hacked other companies
Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations
Network World Security
Palo Alto Networks buys Console to boost agentic security
Mainframe shops tap AI for system insights and recommendations
2026 network outage report and internet health check
China-linked hackers turn Cisco IOS XR routers into covert attack infrastructure
Nvidia unveils alternative high-bandwidth technology to bolster AI cards
Private AI cloud, agentic infrastructure dominate VMware Explore
Tailscale expands from VPN into a full connectivity platform
On-device translation: Why smaller, specialized AI models win
Kyndryl, Broadcom expand partnership to push private clouds for AI work
Kubernetes 1.37 advances workload-aware scheduling and cluster networking
Help Net Security
F5 speeds up virtual patching to counter AI-driven threats
Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line
National Life Group CISO expects more vulnerabilities in six months than in thirty years
Scareware ads keep running on Google’s transparency tool, even after they’re reported
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud
An AI CAPTCHA solver talked itself out of the right answer
CISA review makes the case for eliminating vulnerability classes
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
Fake Claude Opus 5 app delivers malware and wipes its own tracks
SC Magazine
Cronos network resumes activity after $74 million lending exploit
CrowdStrike launches AI agents for Project QuiltWorks
Silver Fox uses adware to distribute ValleyRAT backdoor
Cloudflare launches adaptive intelligence to combat bot attacks
Cryptography expert: AI could make software too secure, impacting government hacking capabilities
Jazz security platform integrated into CrowdStrike Falcon
Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612
JFrog Artifactory flaw exploited days after patch release
Ping YOUniverse: Why the identity paradigm needs to change
Defend AI together, or fail alone
© 2026 RiskDiscovery | Sponsored by:
Deception Logic