[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
What We Missed: Google Gemini Joins the AI Escape Party
Stopping IT Worker Scams Requires Revamped HR Process
Russia's Hybrid Cyber-Physical War in Europe Heats Up
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
SectopRAT Returns, Hiding Inside a Legitimate Application
3 Cyber Threats That Defined the Summer of 2026
How to Build a SASE Framework for Modern Cybersecurity
Ghost Service Accounts Enable M365 Data Theft in Chile
Ars Technica
There's a new way to break RSA that's faster than anything we've seen before
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
CyberScoop
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
New bill would create federal investigative body for AI-driven hacks
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
How tax policy can stop threat actors from breaching US water systems
CISA outlines improvement plan for CVE program
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Pentagon cyber chief: The demand far exceeds supply
Ryuk ransomware operator sentenced to 2 years in prison
InfoSecurity Magazine
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
CISA Unveils Election Security Plan Ahead of 2026 Midterms
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
Researchers Identify AliExpress Phishing Domains Before Registration
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
CISA Charts New "Quality Era" for Global CVE Program
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
OpenAI Agent Hacks Australian Medicare Portal
Over 75% of Organizations Experience Microsoft 365 Governance Issues
Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds
SecurityWeek
In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
North Korea Suspected in $351 Million Bitget Crypto Heist
CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Windows, Linux, Android File Notification Systems Leak User Activity
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
ZDNet
This one WatchOS 27 feature just solved my biggest issue with Apple Watch
Your LG TV is constantly collecting your data – here’s how to stop it
Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’
Google Wallet got a lot of new tricks in 2026 – these 5 are my favorites
Microsoft’s Surface Mouse is back, now with haptic feedback – and I need it
AI agent kill switch urged by Okta-led alliance – how businesses could make it work
Is your Apple Watch 12 or Ultra 4 randomly restarting? Here’s the fix
How to fix your Windows File History if the September update broke it
Nearly 70% of workers use AI regularly now – but many get no time to upskill
Claude Opus 5.5 delivers Fable 5.1 performance – and costs 40% less
The Hacker News
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
The SOC Doesn't Need to Start Over with Every Alert
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
BleepingComputer
Elementor WordPress flaw lets attackers create admin accounts
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
Microsoft plans to deprecate Windows Deployment Services
Rydox marketplace admin pleads guilty, faces 22 years in prison
Microsoft: Recent Windows updates cause desktop loading issues
Hackers steal $351.6 million in Bitget crypto exchange hack
MacSync malware uses public iCloud calendars to deliver new payloads
gbhackers
Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed
CISA Flags WSO2 Security Flaw Under Active Exploitation
CISA Adds Multiple Check Point Product Flaws to Exploited Vulnerabilities List
Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
Sudo Vulnerability Lets Attackers Bypass Time-Based Authorization Controls
Duelbits Hot Wallet Hack Drains $7 Million, Forces Platform Offline
Attackers Drain Payy Network After Exploiting Ethereum Bridge Contract
Cybersecurity Dive
Businesses expand AI’s cybersecurity uses as comfort with technology grows
Wiz uses AI to find vulnerabilities in critical infrastructure
Rogue OpenAI agent targeted Australian government site
FBI probes cyberattack tied to third-party jobs portal
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries
Industrial leaders face cyber resilience gap as attacks shake confidence
Insurance sector begins to offer clarity on AI-related cyber claims
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Google AI models broke out of sandbox, hacked three companies
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
Crooks use fake desktop apps to fool HR staff into giving them remote access
Bitget blames North Korea for $387.5M crypto wallet raid
Which copy of that file is the real one? Dinner, off the record, in Midtown
Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
Decades-old file security flaws found in Android, Linux, macOS, and Windows
CVE flood pushes Ubuntu onto weekly kernel release cycle
Someone went shopping in ASUS's eShop – for customer data
VentureBeat
Monorepos make coding agents more useful — but compromised accounts are harder to contain
AI coding tools are accelerating dependency sprawl and expanding malware risk with it
AI has created a new identity problem. Agentic IAM is how we solve it.
Meta patched Muse’s zero-day, but security teams still lack visibility into what the agent can access
Companies are putting Jev in charge of AI agent decisions — and prompt injection can influence the verdict
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
TechCrunch
Some Supabase customers are publicly exposing reams of people’s data to the web
Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
North Korean hackers suspected in $351M crypto theft, the largest so far this year
Australia to investigate if OpenAI hack of government health website broke the law
What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
LinkedIn adds new tools to fight fake profiles and bogus work histories
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
Stolen passwords are exposing America’s water providers to hackers
Google’s Gemini is the latest AI model to hack other companies
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Network World Security
Can Nvidia’s GeForce gaming GPU really be repurposed for AI computing?
Meta floats project to lay first petabit submarine fiberoptic cable
IP Fabric 8.1 adds application-aware mapping and cloud-native data model
On-prem VeloCloud Orchestrator under attack, only some versions patched
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Selector brings Git-based workflows and incident replay to network AI agents
80% of network pros are OK with giving AI an autonomous role in network operations
Inside Buffalo’s Highmark Stadium: How the Bills and Cisco built one network to run an entire venue, and what IT leaders can learn from it
9 career-boosting Wi-Fi certifications
Lenovo expands virtualization portfolio for AI
Help Net Security
Threat detection dashboards are masking security coverage gaps
MacSync info-stealing malware hides malicious commands in an iCloud calendar
Docker introduces OCI-based Kits to package agents and their guardrails
Fake payroll desktop apps hand attackers a route to company paychecks
Abnormal AI brings governance, cloud security, and threat investigation into one suite
SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads
Dataiku Agent Management reveals unmonitored AI agents
Stop watching what AI agents say and start watching what they do
Half of threat hunters say bad data is their biggest problem
Your incident count is missing a few incidents
SC Magazine
Gemini hacked three companies. The AI isn't the part that should scare you.
Kiteworks warns customers to shut down servers due to possible imminent attack
The four AI questions CISOs will hear from the board the next time they meet
Workload identity and Non-human identity in cloud environments
Privileged Access Management: vaulting, session control, and break glass
Why ransomware is so dangerous for healthcare
Retiring an endpoint: the difference between decommissioned and disappeared
How to prove ransomware recovery works: clean-room restoration and recovery assurance
Decentralized identity: verifiable credentials, identity wallets, and DIDs
How endpoint control layers interact — and where they conflict
© 2026 RiskDiscovery | Sponsored by:
Deception Logic