[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
SWIFT Banking & Government Middleware Enables RCE
Is Your Organization Ready for 2027's AI Accountability Era?
Is It Fair to Blame 'Rogue' AI for Security Failures?
Vulnerability Backlogs Are an Ownership Problem
Malicious Linux Implants Mimic Asian Mail Security Products
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Trump, Tech Giants Strike Voluntary AI Safety Accord
Ars Technica
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Memory executives expect RAM shortage to continue through 2028
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
There's a new way to break RSA that's faster than anything we've seen before
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
CyberScoop
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
AI policy circles targeted in China-linked phishing operation
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
WaterISAC reckons with range of threats after summer of cyberattacks
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Alleged ShinyHunters leader arrested in the Netherlands
Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities
InfoSecurity Magazine
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Police Target KillSec Ransomware Group with Arrests and Seizures
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
MI5 Warns Over 100 Academics Helped China's Espionage Plans
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord
SecurityWeek
In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Crypto Scammers Hijack Microsoft’s Official X Account
In Rare Move, Alleged Iranian State Hacker Extradited to US
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
AI Agents Aimed SQL Injection at US and Canadian Government Sites
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
ZDNet
Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
Pearson’s Workera deal targets a big workplace problem: No time to AI upskill
LLMjacking can run up your business’ AI bill fast – how to stop it
Is ChatGPT your new Google Workspace alternative? Meet Space, Pages, and slides
Get Kindle Unlimited free for 3 months with this early Prime Day deal
iOS 27.0.1 released: Apple fixes annoying iPhone 18 Pro restart and freezing issues
Bose’s new wired earbuds aim for the same great sound and ANC – no charging needed
The Hacker News
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
How Financial Services Companies Can Modernize Their Software Supply Chain
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
BleepingComputer
GitLab warns of critical RCE vulnerability in AI Gateway service
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Dell asks admins to patch max severity CSM flaws as soon as possible
Microsoft’s X account hacked in crypto pump-and-dump scheme
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Autonomous AI agents tried to hack US, Canadian government websites
Microsoft says threat actors are ahead in the early AI race
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
The Day-One Hole in Zero Trust Architecture
gbhackers
Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF
Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations
Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking
Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust
OpenAI Blocks 15,000 Requests Trying to Extract Protected Model Reasoning
Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware
TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA
Cybersecurity Dive
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Fortinet warns that critical flaw in FortiMail is facing exploitation
SOC staffers generally pleased with AI’s impact, but worries remain
State-linked actor targets US AI policy experts in credential phishing campaigns
Mass exploitation of Citrix NetScaler: What we currently know
National cyber director defends private-sector hacking program, urges focus on security basics
Citrix NetScaler exploitation began days before public notification
Dotted Line: How construction is dealing with cybersecurity in the age of AI
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations
Kiteworks lifts advisory after precautionary warning for customers to shut down systems
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval
OpenAI's wandering AI agents earn it a California subpoena
Fortinet sounds the alarm over actively exploited FortiMail zero-day
AI agents hacked the hackers, stealing email addresses from security research org
EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Microsoft catches hackers exploiting Zimbra bug before disclosure
MI5 warns UK academics their research may have helped Chinese spies
CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch
England's schools are getting better at mopping up cyber incidents
VentureBeat
AI agents need more than access control — they need identity at runtime
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
AI agents are exposing a security gap between the data they read and the systems they can change
AI agents have routed around access blocks. Only 9% of companies in VentureBeat's August survey isolate high-risk agents
TechCrunch
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
OpenAI cuts ties with 3 safety researchers, WSJ reports
California governor vetoes bill banning use of ‘pervert glasses’ to secretly record people
Hackers stole millions of US military personnel records during months-long data breach
Meta disputes claim that Muse read a user’s private messages without permission
Dutch police arrest ShinyHunters hacker accused of planning two murders
Still running iOS 26? Update your iPhones, iPads, and Macs for this urgent security fix
OpenAI apologizes to Australia after its AI agents breached government sites
Reco raises $55M as AI agent security startups crowd the market
Network World Security
IBM’s Bob wants to move in: Agent available for on-prem deployment
$6T in annual AI revenue needed to pay off data center investments
HPE’s Rahim: Pace of change in the data center is ‘extraordinary’
CoreWeave brings Nvidia Vera Rubin, AI tools to its cloud services
Nvidia built the AI factory. Now it’s building the locks for the doors
Memory squeeze set to tighten through 2028, Micron says
Cisco SD-WAN Manager hit by zero-day admin access attack
LiquidStack unveils liquid-cooling platform targeting AI data centers
If Apple returns to enterprise server game (with help from Nvidia), what market could it target?
OpenStack Hibiscus adds DNS security features and confidential computing to the open-source cloud platform
Help Net Security
AI is giving attackers a head start, Microsoft warns
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Criminal recruiters want people on your payroll
Android 17 makes it harder for spyware to cover its tracks
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
AI agents keep access to company data after their work is done
New infosec products of the week: October 2, 2026
16-year-old suspected leader of KillSec ransomware group arrested
DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval
SC Magazine
Four ways to close the AI security gap
Accenture plans $5 billion in acquisitions over the next year
Armadin raises $255.5 million for AI-powered cybersecurity platform
Pentagon's new cyber pay initiative faces criticism and confusion
AI's 'Babel 2.0' risk highlights need for intent assurance in security
UK cybersecurity workforce sees decline in female representation
EU urged to strengthen risk assessment for critical infrastructure vendors
Mimecast's Beth Miller: Leading others to make the right decisions
Cyber resilience is becoming a supply-chain problem
MSPAlliance updates certification standard to include AI and third-party services
© 2026 RiskDiscovery | Sponsored by:
Deception Logic