[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
How AI Agents Can Trigger Runaway Costs for Enterprises
ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
Cisco Zero-Day Highlights API Endpoint Authentication Issues
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
MFA Won't Save You From OAuth Consent Abuse
Ars Technica
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
CyberScoop
Citing China, President Trump doubles down on hands-off approach to AI regulation
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Another worry for water systems: infostealer exposure
Dems seek top-to-bottom assessment of CISA workforce
Early Scattered Spider member pleads guilty to cybercrime spree
Researchers use AI to find widespread software decoder flaw
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
Cisco alerts customers to second actively exploited zero-day in as many days
The AI hacking apocalypse is not inevitable
Authorities seize popular, long-running DDoS-for-hire service domains
InfoSecurity Magazine
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds
Network Segmentation Failures Are Expanding the Corporate Attack Surface
AI Drives Surge in Bot and API Threats
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Google Hit with €403m GDPR Fine Over Location Data Practices
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
SecurityWeek
Cyera Raises $400 Million at $12+ Billion Valuation
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Only 13% of OT Network Segments Are Fully Isolated: Analysis
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Malicious B-tree NPM Package Accumulates Millions of Downloads
WordPress Patches ‘Click2Shell’ Vulnerability
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
US Proposes AI Incident Alert System in Talks With China, Bessent Says
Google Hit With $463 Million Fine for EU Location Data Rule Breach
Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
ZDNet
Claude Opus 5.5 delivers Fable 5.1 performance – and costs 40% less
Claim up to $95 today from Apple’s Siri AI settlement – here’s how
The AI models that cheat the most, according to new CAIS benchmark
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
Roku rolls out over 30 subscription bundles for up to 30% off, plus a new Labs feature
Claude Code’s revised projects adds AI orchestration, but local developers must wait
Bose returns with new open earbuds (and a refreshed favorite)
I recommend you don’t run these appliances on your power station – even if you can
Anthropic merges Claude chat and Cowork into one
The Hacker News
AI Agents Are Rewriting the Rules of Lateral Movement
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
DORA Year Two: Can Your SOC Actually See the Attack?
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
BleepingComputer
Check Point warns of Management Server zero-day exploited in attacks
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Webinar tomorrow: Inside real-world Google Workspace breaches
D-Link warns of max severity zero-day bug in DIR-822A routers
New Windows Defender zero-day blocks Microsoft antivirus updates
CISA orders feds to patch Zyxel flaw exploited for data theft
BigCommerce alerts merchants of data breach linked to Ribon apps
CISA alerts of active exploitation of three Linux kernel flaws
WordPress Click2Shell flaw lets hackers execute PHP on the server
Microsoft to retire Microsoft 365 Companion apps in December
gbhackers
Critical Linux KVM Flaw Enables Guest-to-Host Escape on ARM64 Systems
TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows
Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration
Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands
Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
CISA Flags Actively Exploited Flaw in Zyxel GS1900 Switches
Cybersecurity Dive
Insurance sector begins to offer clarity on AI-related cyber claims
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Google AI models broke out of sandbox, hacked three companies
More CVEs than ever. The same old ones keep getting exploited.
Security’s 30-year habit: layering around the problem
Settra ransomware variant deployed in recent attacks
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
Manufacturers make patching progress, but identity management still major weakness
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
Z.ai says sorry for slurping up your code, open sources ZCode
Who signed off on that AI agent? Nobody? Thought so.
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Anthropic-linked CVEs pile up, attackers mostly shrug
Meta Muse AI app flaw lets local malware redirect dictation traffic
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
Rustaceans warned of job interviews with a malicious payload
Agentic security is the billion-dollar challenge for some clever startup to solve
VentureBeat
Companies are putting Jev in charge of AI agent decisions — and prompt injection can influence the verdict
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
AI agents breached 395 organizations using credentials your IAM policy still treats as human
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
AI is changing the economics of software supply chain attacks
AI governance is moving to runtime — and regulated industries are getting there first
TechCrunch
Stolen passwords are exposing America’s water providers to hackers
Google’s Gemini is the latest AI model to hack other companies
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Researchers used Anthropic’s Claude to hack into OpenAI
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
US military says it has launched weapons into space
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
New Italian unicorn Exein rides the physical AI wave
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Network World Security
9 career-boosting Wi-Fi certifications
Lenovo expands virtualization portfolio for AI
2026 network outage report and internet health check
California joins US states clamping down on data center gold rush
Huawei aims to deliver faster AI chips, faster
Practical quantum computers are over a decade away, says NEC
Local AI is getting small enough to make every app multilingual
The amount of e-waste caused by AI is underestimated: we can’t only include the servers
Cisco patches max-severity ISE flaw, the second critical zero-day this week
Riverbed bolsters network performance monitoring with agentic AI
Help Net Security
Researchers uncover malware that uses AI to choose its next move
Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
The latest deepfake numbers give CISOs plenty to worry about
The next intellectual property thief may sound like your CEO
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
Somewhere in your traffic logs, a bot is doing more than looking
Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
A cheap fake base station can still track 5G subscribers
Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit
European AI spending is on track to reach nearly $470 billion by 2030
SC Magazine
The US can take down the hackers – but it’s up to us to make OT environments safe
Microsoft and Google dismantle major cybercrime marketplace RedVDS
How Cloud Privilege Escalation Paths Form
LDAP, Active Directory, and Entra ID: Directory Services for Security Teams
North Korean hackers target IT firm with macOS backdoors
Biometric Authentication: Methods, Risks, and Behavioral Signals
Secrets, Certificates, and Tokens: Choosing the Right Credential for Machine Identity
Authentication Fundamentals: Factors, Methods, and Trust Models
Simulation highlights OWASP LLM Top 10 risk of unbounded consumption
Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401
© 2026 RiskDiscovery | Sponsored by:
Deception Logic