[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Thousands of Data Center Controllers Open to Takeover
When AI Agents Escape Sandboxes, Old Security Rules Apply
Stronger AI Safety Requires Peeking Inside the 'Black Box'
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Former Citigroup CISO Blauner on What Makes A Great Security Leader
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Agentic Browsers Rewind Web Security by 20 Years
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
Ars Technica
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
Sheetz is quitting VMware, migrating 11,000 virtual machines
Windows 0-day drops the same day Microsoft releases record number of patches
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
The US government warns that Russia state hackers are coming after your router
CyberScoop
Here’s what Anthropic found when it turned Mythos loose on encryption algorithms
Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
FBI sees Anthropic’s Mythos as a law enforcement challenge
AI-assisted security tools are finding more bugs, but the threat level has not changed
Microsoft debuts AI cybersecurity offerings as competition heats up
Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms
Google’s solution to hacker name confusion? Yet another naming system
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
Despite multiple takedowns, botnets continue to grow
InfoSecurity Magazine
Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
NCSC Publishes Guidance to Aid Incident Response and Recovery
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
SecurityWeek
Spur Raises $200 Million for IP Intelligence Platform
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
ShinyHunters Claims Ernst & Young Hack
Cyera Acquiring Oasis Security in $1 Billion Deal
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
OT Security Startup Frenos Raises $1.52 Million
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
Act Security Emerges from Stealth to Fight the Patch Problem
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
ZDNet
Get Apple Music's student discount plus Apple TV for just $6 a month - here's how
I tested the Ultrahuman Ring Pro: Rich in features, but still a hard sell
5 ways I speed up my Android phone beyond clearing system cache - all for free
12 keychain gadgets worth carrying every day (and why they're worth it)
You can lease an iPhone through Klarna now - but should you? I did the math
How much storage does your phone really need in 2026? Probably less than you think
Microsoft's new AI model beats Mythos on security benchmark
How to remap the Copilot key on your keyboard to something more helpful
Is your smart TV a secret proxy? LG to suspend rogue apps, Samsung sets impacted too
Did ransomware attacks really decline? Here are your business' 4 best defenses
The Hacker News
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
BleepingComputer
CubePilot drone software dev hit by DNS hijacking to intercept traffic
OpenAI models used Artifactory zero-days to escape to the internet
CISA shares advice on isolating vital systems during cyberattacks
vBulletin fixes critical pre-auth RCE flaw with public exploit
Is Your SSO Protected Against Modern Credential Attacks?
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Data breach at medical billing firm MCBS affects 1.26 million people
Hackers target US firms in FastJson RCE zero-day attacks
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
New Dysphoria DDoS botnet spreads to 200k devices worldwide
gbhackers
Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Critical WordPress Plugin Backdoor Exposes 20,000 Sites to Full Administrator Takeover
Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection
Bank of Baroda Confirms Data Breach After Employee Email Account Compromised
JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox
Attackers Split RAT Components Across npm Packages to Evade Isolated Code Reviews
Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools
OpenAI Open-Sources Codex Security CLI to Find, Validate, and Fix Code Vulnerabilities
Autonomous AI Agent Escapes Sandbox and Breaches Hugging Face Production Systems
Cybersecurity Dive
Authorities investigating a coordinated cyberattack against Minnesota water systems
Microsoft launches agentic security platform designed to combat AI-based attacks
Companies fear AI risks more than common cybersecurity threats
Coca-Cola restores most production capacity at dairy unit after ransomware attack
Tech industry giants say US must embrace openness, transparency in AI
What the Trojan horse gets right (and wrong) about AI security
In the Mythos era, security belongs at runtime
Zero-day flaw in Check Point SmartConsole is under exploitation
The most vulnerable AI products are also some of the most commonly exposed online
Russia-backed threat actor targets Western organizations in phishing campaign
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
America bans imported robots due to supply chain and security risks
MCP gets an enterprise makeover
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face
Microsoft and Wiz mind-meld agents catch more than 90% of bugs
DEF CON bans Meta-style 'pervert glasses'
AI-found bugs aren't proving any easier to exploit despite the hype
Bank for charities pulls online services over security fears
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Microsoft's solution to AI security: more AI and more acronyms
VentureBeat
Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
Snowflake launches Cortex AI Gateway to control AI agents and prevent runaway enterprise costs
Fiduciary AI: Agents need to prove trustworthiness, not just ability
Microsoft launches AI cybersecurity model, agentic defense platform to cut enterprise security costs
New ransomware targets AI model weights and can't even collect the ransom
Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
An AI now judges every move Rubrik's agents make, its AI chief said at VB Transform 2026 — but no one's measured if the judge is right
TechCrunch
Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
PSA: Your Claude shared chats and Artifacts may have ended up on Google
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
The hacker who humiliated spyware makers and was never caught
US accuses American of allegedly wiping his phone using a ‘duress’ password during border search
How AI guardrails are impeding the work of offensive cybersecurity researchers
AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
US government says Iran-linked hackers are disrupting American water and energy providers
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
Network World Security
A 13-year-old flaw is exposing tens of thousands of data center management systems
Arista patches maximum severity vulnerability that is already being exploited
Fortinet’s new FortiGate platform converges firewall, SASE technologies
2026 network outage report and internet health check
Netscout doubles DDoS defense capacity to counter AI-driven botnets
Up to 50% of data center capacity slated for 2026 could be delayed
Network jobs watch: Hiring, skills and certification trends
Cisco, AMD bring enterprise-level security, visibility to Ryzen AI Halo systems
Cloudflare Internal DNS puts public and private DNS on one policy engine
Atos launches sovereign cloud service to power comeback
Help Net Security
Accuris uses AI to improve BOM decisions and supply chain resilience
FortiGate 1200G brings FortiSASE Outpost to customer-controlled environments
Stolen Meta and Google ad accounts are worth more than the money they hold
1Password targets standing privileges with new access management capabilities
WhatsApp brings end-to-end encrypted voice and video calls to the web
Torq makes AI SOC investigations continuously self-learning
Root Evidence puts real-world evidence at the center of vulnerability prioritization
Abnormal AI extends behavioral security to identities, AI systems, and insider threats
Mend.io enhances application security with AI runtime protection and faster zero-day response
Realm Security adds Detection Integrity and Data Haven Search to cut SIEM costs
SC Magazine
Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458
Proof-of-concept exploit released for Certighost Windows AD CS vulnerability
Arista patches critical command injection flaw in VeloCloud Orchestrator exploited in attacks
Operation Cronos dismantled LockBit ransomware group by undermining affiliate trust
Hackers exploit FastJson vulnerability for remote code execution
German government report details Windows Hello for Business biometric security limitations
Italian organizations targeted by 148 ransomware attacks in first half of 2026
Malicious Steam workshop map delivered malware to MECCHA CHAMELEON players
Google introduces new cybercrime naming taxonomy, diverging from Microsoft's initiative
Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet and More - SWN #602
© 2026 RiskDiscovery | Sponsored by:
Deception Logic