[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Thousands of Data Center Controllers Open to Takeover
When AI Agents Escape Sandboxes, Old Security Rules Apply
Stronger AI Safety Requires Peeking Inside the 'Black Box'
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Former Citigroup CISO Blauner on What Makes A Great Security Leader
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Agentic Browsers Rewind Web Security by 20 Years
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
Ars Technica
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
Sheetz is quitting VMware, migrating 11,000 virtual machines
Windows 0-day drops the same day Microsoft releases record number of patches
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
The US government warns that Russia state hackers are coming after your router
CyberScoop
OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems
Here’s what Anthropic found when it turned Mythos loose on encryption algorithms
Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
FBI sees Anthropic’s Mythos as a law enforcement challenge
AI-assisted security tools are finding more bugs, but the threat level has not changed
Microsoft debuts AI cybersecurity offerings as competition heats up
Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms
Google’s solution to hacker name confusion? Yet another naming system
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
InfoSecurity Magazine
The Average Cost of a Data Breach Rises to $5 Million
Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
NCSC Publishes Guidance to Aid Incident Response and Recovery
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
SecurityWeek
Mate Security Raises $35 Million for Agentic SOC
ThreatLocker Raises $190 Million in Series F Funding
Critical VM Escape Vulnerability Patched in VMware ESXi
US, Australia Release OT Isolation Guidance for Critical Infrastructure
OpenAI’s Rogue AI Ventured Beyond Hugging Face
Spur Raises $200 Million for IP Intelligence Platform
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
ShinyHunters Claims Ernst & Young Hack
Cyera Acquiring Oasis Security in $1 Billion Deal
ZDNet
I tested a premium Linux laptop that's as light as it is powerful - here's why I love it
How to remap the Windows 11 Copilot key and restore your missing Right Ctrl button
I tried ArchEZ to see if it really makes Arch Linux easy for beginners - and it delivered
75% of workers ask AI questions instead of colleagues - with potentially serious consequences
Get Apple Music's student discount plus Apple TV for just $6 a month - here's how
I tested the Ultrahuman Ring Pro: Rich in features, but still a hard sell
5 ways I speed up my Android phone beyond clearing system cache - all for free
12 keychain gadgets worth carrying every day (and why they're worth it)
You can lease an iPhone through Klarna now - but should you? I did the math
How much storage does your phone really need in 2026? Probably less than you think
The Hacker News
Mythos Asks the Right Question. It Doesn't Answer It.
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
BleepingComputer
These near-mint ASUS Chromebook refurbs are only $145
CubePilot drone software dev hit by DNS hijacking to intercept traffic
OpenAI models used Artifactory zero-days to escape to the internet
CISA shares advice on isolating vital systems during cyberattacks
vBulletin fixes critical pre-auth RCE flaw with public exploit
Is Your SSO Protected Against Modern Credential Attacks?
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Data breach at medical billing firm MCBS affects 1.26 million people
Hackers target US firms in FastJson RCE zero-day attacks
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
gbhackers
macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets
Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks
NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages
Threat Actor Claims Revolut Data Breach Exposes Financial Records of 75 Million Users
CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
Joyfill npm Supply-Chain Attack Deploys RAT and Developer Credential Stealer
Houston City College Data Breach Impacts 832,000 Students and Alumni
Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords
Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Cybersecurity Dive
Authorities investigating a coordinated cyberattack against Minnesota water systems
Microsoft launches agentic security platform designed to combat AI-based attacks
Companies fear AI risks more than common cybersecurity threats
Coca-Cola restores most production capacity at dairy unit after ransomware attack
Tech industry giants say US must embrace openness, transparency in AI
What the Trojan horse gets right (and wrong) about AI security
In the Mythos era, security belongs at runtime
Zero-day flaw in Check Point SmartConsole is under exploitation
The most vulnerable AI products are also some of the most commonly exposed online
Russia-backed threat actor targets Western organizations in phishing campaign
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
America bans imported robots due to supply chain and security risks
MCP gets an enterprise makeover
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face
Microsoft and Wiz mind-meld agents catch more than 90% of bugs
DEF CON bans Meta-style 'pervert glasses'
AI-found bugs aren't proving any easier to exploit despite the hype
Bank for charities pulls online services over security fears
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Microsoft's solution to AI security: more AI and more acronyms
VentureBeat
Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
Snowflake launches Cortex AI Gateway to control AI agents and prevent runaway enterprise costs
Fiduciary AI: Agents need to prove trustworthiness, not just ability
Microsoft launches AI cybersecurity model, agentic defense platform to cut enterprise security costs
New ransomware targets AI model weights and can't even collect the ransom
Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 — but no one's measured if the judge is right
TechCrunch
Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
PSA: Your Claude shared chats and Artifacts may have ended up on Google
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
The hacker who humiliated spyware makers and was never caught
US accuses American of allegedly wiping his phone using a ‘duress’ password during border search
How AI guardrails are impeding the work of offensive cybersecurity researchers
AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
US government says Iran-linked hackers are disrupting American water and energy providers
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
Network World Security
AI data centers in the US may face power cuts under PJM reliability proposal
A 13-year-old flaw is exposing tens of thousands of data center management systems
Arista patches maximum severity vulnerability that is already being exploited
Fortinet’s new FortiGate platform converges firewall, SASE technologies
2026 network outage report and internet health check
Netscout doubles DDoS defense capacity to counter AI-driven botnets
Up to 50% of data center capacity slated for 2026 could be delayed
Network jobs watch: Hiring, skills and certification trends
Cisco, AMD bring enterprise-level security, visibility to Ryzen AI Halo systems
Cloudflare Internal DNS puts public and private DNS on one policy engine
Help Net Security
Stairwell launches Backstory, pioneering agentic investigation for malware blast radius
ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility
MIND AI DLP Agents automate DLP classification, investigations and remediation
Contrast CVE Shield aims to protect applications while security teams deploy patches
Cloudflare reveals what’s behind major internet outages
Accuris uses AI to improve BOM decisions and supply chain resilience
FortiGate 1200G brings FortiSASE Outpost to customer-controlled environments
Stolen Meta and Google ad accounts are worth more than the money they hold
1Password targets standing privileges with new access management capabilities
WhatsApp brings end-to-end encrypted voice and video calls to the web
SC Magazine
Loss of control: The AI agent governance crisis
Seven controls enterprise teams need in place to avoid another OpenAI-Hugging Face incident
Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458
Proof-of-concept exploit released for Certighost Windows AD CS vulnerability
Arista patches critical command injection flaw in VeloCloud Orchestrator exploited in attacks
Operation Cronos dismantled LockBit ransomware group by undermining affiliate trust
Hackers exploit FastJson vulnerability for remote code execution
German government report details Windows Hello for Business biometric security limitations
Italian organizations targeted by 148 ransomware attacks in first half of 2026
Malicious Steam workshop map delivered malware to MECCHA CHAMELEON players
© 2026 RiskDiscovery | Sponsored by:
Deception Logic