[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
SpiderSilk Hunts External Threats With AI-Based Scanner
Why AI Is So Good at Scamming Humans
AI Governance Can't Wait
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
Indonesia Hit by Android Banking App-Cloning Campaign
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Ars Technica
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent
I rented a car, and within hours, my driver's license was for sale
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
CyberScoop
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
GitLab’s critical flaw is already drawing internet-wide probes
Conti ransomware crew member sentenced to four years in prison
Hawley probes OpenAI over Hugging Face breach
AI lets small actors run state-level hacking campaigns, Anthropic report finds
Governments ‘buying time’ in race between innovation, security, national cyber director says
Chinese espionage groups swarm to exploit triple-link chain of zero-days
FTC rescinds policy statement requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
InfoSecurity Magazine
Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
Revolut Confirms Data Breach Through Fake Government Requests
Hackers Exploit Maximum Severity Flaw in GitLab
OpenAI Agent Swarm Hacks RubyGems Package Manager
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
Most Organizations Skip Permissions Reviews Before Deploying AI Tools
CISA Updates Insider Threat Guide With New Mitigation Advice
MantaxOtax Android Malware Combines Ransomware With Spyware
SecurityWeek
Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
Personal, Financial Info Exposed in Revolut Data Breach
The Race to Control AI and Protect What Makes Us Human
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
CISOs Race to Control AI Agents Without Destroying Their Value
Telus Warns Customers of Account Breaches
Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
ZDNet
Switzerland takes a Swiss Army knife to Microsoft 365
Your older iPhone just got free satellite service for another year – here’s why
This CIO doesn’t ‘hire engineers to write code’: 3 AI fundamentals he prioritizes instead
I’ve been an Android user all my life, but I’m jealous of 3 things Apple just announced
Eager to try iOS 27’s cool AI features and upgraded Siri? Get ready for usage limits
Your friend with ‘nothing to hide’ is more likely to spy on you, study shows
The iPhone 17 and other older models just got a surprise $100 price hike
5 biggest Apple announcements from the iPhone Duo event
This LG TV jailbreak turns smart devices into spies, say researchers
T-Mobile will give you the iPhone 18 Pro for free – here’s how to preorder
The Hacker News
AI Changed the Exposure Problem. Validation Needs to Change With It.
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
When the Whole Company Adopts AI: What It Does to Your SOC
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
BleepingComputer
Why Patch Automation Needs Brakes, Not Just an Accelerator
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
Microsoft: September updates cause RDS failures on Windows Server
Revolut discloses data breach exposing financial info, passports
Microsoft: September updates break audio on some Windows PCs
CISA: Hackers now exploit max severity GitLab flaw in attacks
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Hackers abused Claude to extract secrets from 1.8M Android apps
Florida confirms DMV database breached via stolen police account
gbhackers
Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
Cybersecurity Dive
Malicious actors already using critical GitLab flaw, CISA and others warn
Security teams are adopting AI faster than they trust it
Zero trust is the future. But enterprises still need their VPNs.
State authorities warn they lack resources to address cyber threat to critical sectors
Accountability, oversight and AI: Inside Microsoft’s security transformation
Threat groups enhance cyberattack capabilities with AI
White House sees water cybersecurity partnership in Texas as national blueprint
CISA is on the verge of filling hundreds of critical vacancies
How AI anxieties dominated the summer’s big cybersecurity conference
CISOs are feeling the security burden of accelerated AI use
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Perfect-10 GitLab bug under attack days after patch lands
UK.gov begins killing off passwords for 23 million users
Security through obscurity is dead, and AI delivered the fatal blow
More JFrog Artifactory bugs under attack, and all 3 have patches
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
EU's Cyber Resilience Act starts the 24-hour vulnerability clock
Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
ShinyHunters expose 6.4M in attack on medical supplier McKesson
VentureBeat
AI governance is moving to runtime — and regulated industries are getting there first
Why AI shouldn't be the one repairing your data pipelines
Anthropic CEO says AI swarm could ‘take over the entire Internet’ in 6-12 months, commits to AI slowdown plan
Security vendors use AI to rank Patch Tuesday CVEs — and rarely tell customers
Anthropic's safety monitor missed a live cyberattack because Mythos 5's reasoning said everything was fine
Agents identifying as OpenAI systems wrote 17,000 posts to a wiki no one was supposed to write to
Most security teams don't know how many AI agents they're running. Falcon Guardian found 18,000 at one company that had approved only 300.
TechCrunch
Revolut confirms customer data breach through fake government requests
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
A hacker stole $340M in a crypto heist, then returned most of it
OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure
US military disabled ad tracking on troops’ devices following reports of targeted attacks
Network World Security
AI inferencing is headed for the network edge
The waste heat paradox: How data centers can cool AI with the heat AI creates
Broadcom hampers VMware migration by blocking downloads of key SDK
Nvidia will use Palantir to gain insight its supply chain
The race to 1.6T: Ethernet and coherent optics tackle AI’s bandwidth crunch
Network complexity is outpacing NetOps teams: How AI can help
Nvidia invests $3.5B in MediaTek to extend its grip on AI
MikroTik patches flaws currently being exploited to take over routers
Leap second proposal will keep software stacks in sync
Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
Help Net Security
Entrust turns cryptographic inventory data into security action
Bitsight connects threat intelligence and exposure monitoring across the supply chain
Dataminr uses agentic AI to predict and verify security threats
ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities
Airrived adds Agentic Observability to track AI agent actions and risks
WhatsApp Restricted Chat locks a conversation to your primary phone
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages
What we know about the Revolut data breach so far
Turn it off and on again, but for critical infrastructure
Permify: Open-source authorization as a service
SC Magazine
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
Max severity GitLab path traversal flaw under active reconnaissance
9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615
Check Point patches two critical VPN gateway bugs
Dead drops in public: What the AI agent stashed on Hugging Face
Anthropic finds 4th real-world attack by Claude agent, details models’ ‘biased reasoning’
AI governance needs to become part of the CISO’s GRC program
Ping YOUniverse: How to classify and manage AI agents
How coding agents are changing application risk
It's More Secure When It's Disabled - PSW #943
© 2026 RiskDiscovery | Sponsored by:
Deception Logic