[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Microsoft's Patch Tuesday Deluge Continues With August Updates
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
Multistate Water System Attacks Widen, Iran Suspected
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
Coruna, DarkSword iOS Exploits Proliferate Globally
Outdated Cybercrime Laws Put Security Researchers at Risk
Sherlock Holmes Was the 'OG' Social Engineer
AI-Generated Patches Fail Half the Time
Ars Technica
Chrome adopts what may be the best protection yet against account takeovers
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Claude published malicious code to the Internet and attacked 3 real companies
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
CyberScoop
Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas
NIST wants to overhaul its vulnerability database for the AI age
The FTC wants to regulate AI for ideological bias
OpenAI says Daybreak will expand to offer specialized cyber services
NATO and an AI startup can now name and track software vulnerabilities
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
UK man tied to The Com sentenced for abusing 117 victims
Why transparent AI agents matter more than you think
More than half of AI-generated patches are broken
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
InfoSecurity Magazine
Six npm Packages Read C2 Addresses From Ethereum Wallet
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
OpenAI Pauses Some Development of Astra Model on Security Concerns
Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
WordPress Plugins Compromised Without a Single File Change
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
SecurityWeek
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
Zoom Patches Zero-Click Code Execution Vulnerability
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Corma Raises $60 Million for Defensive Cybersecurity AI Model
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
ZDNet
Why software factories are back - and how they work in the age of AI
How to create flyers with AI that people won't hate: 8 tips (and prompts) that really work
A developer got Word 1.1a from 1990 to run on Windows 11 - try it yourself
Linux desktop use surged to 22% on one workday, Cloudflare data shows
I tried Opera's new vertical tabs - and it might be the best implementation yet
Nvidia's open Nemotron 3.5 Lightning model is all about specialized, local agentic AI
This $50 power bank is safer than my lithium-ion battery - and it's coming on my next flight
Best robot mowers of 2026: Expert tested
7 simple gadgets that can make your home smarter for under $100
I tried Google Wallet's new allowance feature, and my kid already ditched their debit card
The Hacker News
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
BleepingComputer
DeadLock ransomware uses blockchain to resist infrastructure takedown
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Windows 11 KB5121003 & KB5120240 cumulative updates released
Wesco confirms security incident after ExfilSquad claims data theft
Mozilla updates GPG signing key for Firefox releases after exposure
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
gbhackers
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Plug & Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks
Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
GhostJacking Attacks Let Hackers Hijack AI Agents and Steal Cloud Credentials
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
Hackers Pivot Through Private APN to Sabotage Siemens PLCs at Polish Power Plant
CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files
Cybersecurity Dive
Former BlackFile affiliates linked to extortion campaign targeting private equity
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
Civil-society initiative will pay cybersecurity vendors to protect rural water systems
Secure development can help turn the tables as AI alters cyber landscape
Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’
Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Hackers grow more willing to destroy, not just disrupt, OT systems
OpenAI warns autonomous hacks are ‘watershed moment for computer security’
Western government leaders call for a focus on infrastructure resilience, not AI hype
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Signal adds an extra layer of security to make sure you're actually chatting with the right person
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
Two wars and a World Cup lead to epic DDoS attacks on publishers
Deepfake hiccup unmasks suspected digital certificate fraudster
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
DEF CON hackers add new muscle to water utility protection
North Korean spies are running local LLMs to cause AI mischief
Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list
VentureBeat
OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks
AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push
AI agents are part of your team now. Here’s how to secure all of them.
The browser is where attacks land. Why is security still focused on the endpoint?
Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
TechCrunch
FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures
Delta investigating after someone set up fake Wi-Fi network mid-flight
North Korean remote IT staffer worked for US government agency, says FBI
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Signed up for Klaviyo? Dozens of advertisers may have seen your password
The AI safety test is becoming a safety risk
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you
Google’s top hacker hunter explains why hacking groups get code names
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Computer maker Framework notifies ‘all customers’ of a data breach
Network World Security
IBM, Together AI team to offer open-source AI inference in the cloud
Server prices to rise by up to 87% at OVHcloud
IT infrastructure shortages are real and lasting. Here’s how to cope
Tor still runs on altruism, but cheap hosting is pulling it off course
Out of band, out of mind: DEF CON research calls IPMI a ‘sanctioned backdoor’ into enterprise networks
Samsung offers future AI memory roadmap
Polish data center plans to send its waste heat to the neighbors
AMD to buy Taalas, maker of model-specific AI chips for enterprise inference
Agentic AI could force a rethink of enterprise AI server design, researchers say
NatJack exploits put NAT security assumptions to the test at Black Hat
Help Net Security
Arctera enhances Unified Platform for evidence-driven compliance workflows
Citrix expands Platform Flex with observability and secure developer services
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Ransomware gangs don’t need control system access to disrupt industrial production
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
GPT-5.6-Cyber refuses security researchers’ requests far less often
Who will be the Stanislav Petrov in your organization?
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Previously unseen entry vector used to breach Polish energy plant
Your security vendor gets the frontier cyber model, you get the findings
SC Magazine
Microsoft SharePoint Server bug exploited in ransomware attacks
Squirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606
What AI Agent Incident Response Actually Controls
How to Build an AI Security Program
What AI Control Points Actually Govern
US cyber officials warn AI is giving attackers an edge
Stop bracing for the AI monster – fix the boring stuff first
AI agent exploits gym booking system vulnerability
Mozilla issues new GPG key after accidental exposure
‘GhostJacking’ attack turns error logs into indirect prompt injections
© 2026 RiskDiscovery | Sponsored by:
Deception Logic