[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
Cisco Zero-Day Highlights API Endpoint Authentication Issues
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
MFA Won't Save You From OAuth Consent Abuse
AI Agent Breaches Spanish Organization, Modifies Personal Data
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
China's FamousSparrow APT Spies on US Politics in Latin America
AI Security Spending Jumps as Fear Outpaces Proof of Value
Ars Technica
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
CyberScoop
Early Scattered Spider member pleads guilty to cybercrime spree
Researchers use AI to find widespread software decoder flaw
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
Cisco alerts customers to second actively exploited zero-day in as many days
The AI hacking apocalypse is not inevitable
Authorities seize popular, long-running DDoS-for-hire service domains
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
Treasury’s Scott Bessent says no liability exemptions for AI labs
InfoSecurity Magazine
Google Hit with €403m GDPR Fine Over Location Data Practices
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Revolut Customers Targeted with New Wave of Phishing Attacks
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
CISA Upgrades Vulnerability Reporting Platform with More Automation
Manufacturing Accounts for 22% of all Ransomware Victims
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
SecurityWeek
CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal
RatHat Android Trojan Uses AI for Automation
Rust Team Members and Popular Crate Owners Targeted via Video Calls
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Google Confirms Gemini AI Breached Three Firms
TigerByte Cyber Emerges From Stealth With $3 Million in Funding
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
ZDNet
The AI models that cheat the most, according to new CAIS benchmark
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
Roku rolls out over 30 subscription bundles for up to 30% off, plus a new Labs feature
Claude Code’s revised projects adds AI orchestration, but local developers must wait
Bose returns with new open earbuds (and a refreshed favorite)
I recommend you don’t run these appliances on your power station – even if you can
Anthropic merges Claude chat and Cowork into one
How September’s Pixel Drop changes the way you call and message important contacts
I’ve used both iPhone 18 Pro models – here’s how my buying advice is changing in 2026
The Hacker News
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
Identity Visibility in 2026: The Foundation of Identity Security
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
BleepingComputer
Microsoft fixes broken Excel copy and paste for all Office users
FBI's CJIS v6.1: What Security Teams Need to Know.
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft: September updates break File History backup feature
Malicious npm packages evade install-script defenses at runtime
Researchers escape OpenAI Codex sandbox to run commands on host
BragJack attacks hijack AI browser agents through malicious extensions
North Korean WaterPlum hackers infected 30,000 devices worldwide
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Viral AI actress' hotline face-scans every caller, watches their mood
gbhackers
NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers
10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
Cybersecurity Dive
More CVEs than ever. The same old ones keep getting exploited.
Security’s 30-year habit: layering around the problem
Settra ransomware variant deployed in recent attacks
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
Manufacturers make patching progress, but identity management still major weakness
Hackers exploit zero-day flaw in Cisco email gateway
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
AI is now leading driver of new cybersecurity spending
Companies’ AI strategies don’t account for agentic tools
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
Rustaceans warned of job interviews with a malicious payload
Agentic security is the billion-dollar challenge for some clever startup to solve
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
North Korea's fake job interviews infected 30,000 devices
FBI: Fake cop and government impersonation scams cost victims $1.6B
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
Researchers find way to listen in on headphones from afar
China's Salt Typhoon backdoors Latin American orgs with new snooping malware
VentureBeat
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
AI agents breached 395 organizations using credentials your IAM policy still treats as human
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
AI is changing the economics of software supply chain attacks
AI governance is moving to runtime — and regulated industries are getting there first
Why AI shouldn't be the one repairing your data pipelines
TechCrunch
Google’s Gemini is the latest AI model to hack other companies
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Researchers used Anthropic’s Claude to hack into OpenAI
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
US military says it has launched weapons into space
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
New Italian unicorn Exein rides the physical AI wave
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Revolut confirms customer data breach through fake government requests
Network World Security
Huawei aims to deliver faster AI chips, faster
Practical quantum computers are over a decade away, says NEC
Local AI is getting small enough to make every app multilingual
The amount of e-waste caused by AI is underestimated: we can’t only include the servers
Cisco patches max-severity ISE flaw, the second critical zero-day this week
Riverbed bolsters network performance monitoring with agentic AI
Axelera Europa targets enterprise data centers with far more efficient AI
European cloud watchdog slams Broadcom over VMware licensing practices, issues warnings about SAP
Critical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco brings Splunk AI on premises, expands agent observability, monitors token costs
Help Net Security
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Fastly gives enterprises real-time control over AI models and agents
North Korea’s job interview scam runs both ways
Google hit with €403 million GDPR fine over location tracking
Scammers impersonate cops, use arrest threats to extort victims
Siemba brings continuous IDOR testing to production APIs
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Know what was tested before your SAP ECC migration goes live
Product showcase: Helmit alerts parents when online conversations show signs of trouble
Gopass: Open-source command-line password manager for teams
SC Magazine
Humans are the real AI risk – and accountability – not more regulation – can keep big tech honest
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477
What model access failure costs the business
Spear Phishing: How the attack works and how to stop it
How to build an OT security operating model
What OT Resilience Actually Controls
The AI Security Control Problem: Why AI Requires a Different Security Discipline
New CISA-hosted VINCE-NT system revealed for coordinated vulnerability disclosure
Closing the AI control gap: From shadow AI to continuous protection
Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617
© 2026 RiskDiscovery | Sponsored by:
Deception Logic