[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
The Morning After We Pull a Root of Trust, Nobody Owns It
Interpol Leverages Global System to Curtail Fraud Payments
DROP Platform Lets Californians Reduce Digital Footprint
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
AI Harnesses Burst With Potential Exploit Opps
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
SE Asian Cybercriminal Syndicates Become a Global Power
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
Ars Technica
Claude published malicious code to the Internet and attacked 3 real companies
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
Sheetz is quitting VMware, migrating 11,000 virtual machines
CyberScoop
CrowdStrike: AI is now both the weapon and the target in cyberattacks
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
What the Hugging Face breach reveals about defense in the age of agentic AI
Anthropic says its AI accidentally hacked three companies during safety tests
Okta’s deal for Permiso aims to close gaps in identity threat detection
CISA issues recommendations to federal agencies on open-source software security
We know how to protect our troops from telecom attacks. We’re just not doing it.
Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims
A little-known npm package was North Korea’s warm-up act for the axios hack
Supply chain challenges loom large in quantum race, White House official says
InfoSecurity Magazine
HollowFrame Loader Uses Fake Python DLL to Evade Defender
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AI and Automation Fall Short of Sysadmin Expectations
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
SecurityWeek
River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
Horizon3 Raises $250 Million to Fund Continuing Growth
N‑able Patches Vulnerability Exploited to Hack N-central Servers
Brinks Home Discloses Data Breach as Hackers Leak Files
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments
Ruby on Rails Patches Critical Vulnerability
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
ZDNet
The 7 tech travel hacks I swear by - after years of learning the hard way
Duress passcodes explained: How they work and why they can land you in court
How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 days
I went running with the Galaxy Watch 9 in London, and it taught me something new
My favorite MacBook accessory gives my keyboard a simple but useful upgrade for cheap
Framework Laptop 13 Pro review: Plenty premium, but pummeled by RAM crisis
Why your Windows installation files keep getting bigger - AI is filling up smaller drives
The 5 laptop features worth spending extra on (and 3 that are mostly hype)
AI in Formula One: Competitive advantage is all about the human in the loop
One of our favorite Bluetooth trackers is on sale with this exclusive deal
The Hacker News
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
BleepingComputer
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
Google Chrome may soon block New Tab hijacker extensions by default
Rails patches critical Active Storage flaw with RCE potential
Amgen says cloud data breach exposed patient health, proprietary info
Arch Linux disables AUR package adoption to stop malware flood
Online ad firm Adform’s script compromised to steal cryptocurrency
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
CISA warns of cyberattacks disrupting U.S. water utilities
gbhackers
TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks
Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw
CareCloud Data Breach Exposes Patients’ Health, Social Security and Credit Card Data
SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
Hackers Exploit Critical Arista VeloCloud Flaw to Execute OS Commands
Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform
Cybersecurity Dive
Anthropic says human error let Claude AI models escape test environment and hack third parties
Hackers abuse Microsoft Teams in ransomware campaign through fake IT support
Shadow AI, leadership resistance make AI governance tough for worried CISOs
As data breaches grow costlier, ungoverned AI creates new risks
Authorities investigating a coordinated cyberattack against Minnesota water systems
Microsoft launches agentic security platform designed to combat AI-based attacks
Companies fear AI risks more than common cybersecurity threats
Coca-Cola restores most production capacity at dairy unit after ransomware attack
Tech industry giants say US must embrace openness, transparency in AI
In the Mythos era, security belongs at runtime
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
UK government investment arm cops to 40-hour leak of officials' contact details
AI is 'both the weapon and the target' in latest wave of cyberattacks
The most famous brand in physical security got pwned by ShinyHunters
Anthropic and OpenAI are competing to see whose agents can go rogue harder
Charities remain locked out of CAF Bank online accounts
Anthropic’s Claude escaped test sandbox to attack three organizations
Jailed Flock vandal wipes out three cameras, racks up thousands in damages
Russian spies take their half-click email attack from Zimbra to Outlook
Headteacher had the most guessable username-password combo you could imagine
VentureBeat
Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
Mastercard spent decades training its fraud system to see bots as thieves. Now bots are the ones doing the buying.
Hush Security says the AI security problem has shifted from protecting models to governing identities as autonomous agents spread
The lineage behind 69% of open models was never verified. Cisco just fingerprinted almost 900 for free
NTT DATA AIVista and Snowflake: Identity alone won’t secure enterprise AI agents
Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
Snowflake launches Cortex AI Gateway to control AI agents and prevent runaway enterprise costs
TechCrunch
Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate
Samsung bans smart TV apps that share users’ internet connections with strangers
CareCloud begins to notify hundreds of thousands after hackers stole medical records
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
Okta buys AI security startup Permiso — source says for about $200M
In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap
US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
PSA: Your Claude shared chats and Artifacts may have ended up on Google
Network World Security
Cato Networks launches agentic threat prevention
Groundcover raises $100M as observability pivots from monitoring to AI infrastructure
From dangling DNS records to reverse DNS gaps, attackers find new blind spots
Data center developer eyes disused newpaper printing plant
Broadcom patches vulnerabilities all over VMware
Microsoft doubles down on multi-model AI as it builds a Copilot super app
How Port Nelson overhauled its operations with private 5G
Most corporate IT is off premises. Data center costs, staffing remain difficult, Uptime reports
CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks
Dell, Nutanix combo expands virtualization, private cloud choices
Help Net Security
Horizon3.ai hits $2 billion valuation in $250 million funding round
CISA lays out new guidance for using open-source software
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
Qodana 2026.2 adds post-quantum crypto checks for JVM code
Simbian adds AI threat hunting agent to expand autonomous SecOps platform
OpenAI reveals how criminals used ChatGPT to run scams
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Mapping the malware blast radius a single alert won’t show you
SkillSpector: NVIDIA’s open-source security scanner for AI agent skills
AI cut phishing from hours to seconds, which is where DMARC and BIMI come in
SC Magazine
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470
Anthropic Claude models compromised 3 companies during testing
New HollowFrame loader and Matryoshka malware family discovered
Fuyao operation uses Android TV boxes for ad fraud
Italy's new facial recognition policy sparks EU law debate
Interpol's I-GRIP mechanism intercepts millions in fraud attempts
AI chatbots outperform humans in building trust for scams
Rogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603
Unspecified threat actors targeting US water systems, CISA warns
Non-human identity (NHI) programs stall on detection, not policy
© 2026 RiskDiscovery | Sponsored by:
Deception Logic