[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Trump, Tech Giants Strike Voluntary AI Safety Accord
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
'NeedyMantis' Provides Long-Term Access to Compromised Networks
Ars Technica
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
There's a new way to break RSA that's faster than anything we've seen before
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
CyberScoop
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
WaterISAC reckons with range of threats after summer of cyberattacks
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Alleged ShinyHunters leader arrested in the Netherlands
Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities
Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
As AI world debates security, NVIDIA releases open source tools for agents
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
InfoSecurity Magazine
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
MI5 Warns Over 100 Academics Helped China's Espionage Plans
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord
AI Boosts SOC Analyst Capacity but Limits Skill Development
Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware
Apple Patches CoreGraphics Zero Day Exploited in Attacks
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials
SecurityWeek
AI Has Changed Attack Speed, Not Security Fundamentals
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
500,000 Active Credentials Left Exposed on GitHub
Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
ZDNet
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
Pearson’s Workera deal targets a big workplace problem: No time to AI upskill
LLMjacking can run up your business’ AI bill fast – how to stop it
Is ChatGPT your new Google Workspace alternative? Meet Space, Pages, and slides
Get Kindle Unlimited free for 3 months with this early Prime Day deal
iOS 27.0.1 released: Apple fixes annoying iPhone 18 Pro restart and freezing issues
Bose’s new wired earbuds aim for the same great sound and ANC – no charging needed
Your Bose headphones are getting a major Bluetooth upgrade – what to expect
The Hacker News
How Financial Services Companies Can Modernize Their Software Supply Chain
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
BleepingComputer
Microsoft enables Windows settings backup by default for orgs
Hackers stole Pentagon personnel records of over 3 million people
Metamask discloses security incident affecting its infrastructure
Russian state hackers use new RedFlick technique to push malware
DIVD says Zammad zero-days enabled AI-driven network breach
Over 543,000 valid credentials exposed in public GitHub repositories
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
Cisco warns of new SD-WAN zero-day exploited in attacks
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Microsoft to block Entra ID script injection attacks starting October
gbhackers
TerminalFix Attacks Deploy Lorem Ipsum Loader to Create Covert Tunnels Into Corporate Networks
Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content
Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation
CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight
Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos
SC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence
HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
Cybersecurity Dive
Mass exploitation of Citrix NetScaler: What we currently know
National cyber director defends private-sector hacking program, urges focus on security basics
Citrix NetScaler exploitation began days before public notification
Dotted Line: How construction is dealing with cybersecurity in the age of AI
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations
Kiteworks lifts advisory after precautionary warning for customers to shut down systems
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security testing has to keep pace with AI-driven attackers
Context matters when it comes to cybersecurity’s agentic operating model
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
England's schools are getting better at mopping up cyber incidents
UK privacy watchdog starts over with new board and Manchester HQ
Fewer women than ever in UK's 'old boys' club' cyber industry
Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
More than half of UK businesses lack confidence in basic cyber skills
UK rail cops' £320K face-scanning spree nets zero matches
Spectre bug is back, this time to haunt JIT engines
Add one more AI worry to the nightmare scenario: self-replicating prompt injections
FBI to ShinyHunters: 'We know how to find you'
VentureBeat
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
AI agents are exposing a security gap between the data they read and the systems they can change
AI agents have routed around access blocks. Only 9% of companies in VentureBeat's August survey isolate high-risk agents
Monorepos make coding agents more useful — but compromised accounts are harder to contain
TechCrunch
Hackers stole millions of US military personnel records during months-long data breach
Meta disputes claim that Muse read a user’s private messages without permission
Dutch police arrest ShinyHunters hacker accused of planning two murders
Still running iOS 26? Update your iPhones, iPads, and Macs for this urgent security fix
OpenAI apologizes to Australia after its AI agents breached government sites
Reco raises $55M as AI agent security startups crowd the market
Protego Ventures closes debut $125M fund for Israeli defense tech
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
Some Supabase customers are publicly exposing reams of people’s data to the web
Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
Network World Security
LiquidStack unveils liquid-cooling platform targeting AI data centers
If Apple returns to enterprise server game (with help from Nvidia), what market could it target?
OpenStack Hibiscus adds DNS security features and confidential computing to the open-source cloud platform
2026 network outage report and internet health check
AMD agrees to buy World Labs to fill out its AI stack
Why a network digital twin is the missing piece for AI-era operations
NetScaler admins told to patch critical zero-days in ADC and Gateway now
Tackling the three hidden mistakes when planning a GCC
Rewiring global capability centers for the AI era
Google’s first prototype satellite is going up, kicking off its space-based data center project
Help Net Security
Sophos uses agentic AI to show businesses which security fixes deserve funding
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
Legit Security extends automated fixes to vulnerable open-source dependencies
Pentagon breach exposes personal data of more than 3 million people
Armadin raises $255.5 million to expand AI offensive security platform
New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
Some car apps are slipping owners’ data to big tech companies
Sentinel Envelope Plus adds software protection without source code changes
BlackFog adds prompt protection and governance for agentic AI
Many expect AI in the SOC to make entry jobs harder to get
SC Magazine
Fake Zoom installer delivers new CloudSyncD macOS backdoor
Zero Trust ends at the browser
Okta: The Blueprint Alliance AI-agent framework isn't ours, but everybody's
South African air traffic control firm investigates ransomware-linked malware in OT network
High-severity OpenSSL flaw can leak memory or crash programs
AI coding agents expose sensitive data through public screenshots
Russia proposes new rules to curb SIM card fraud
UK employers plan tech team expansion, prioritizing security and AI skills
Microsoft Entra ID to enhance security against script injection attacks
New security flaws discovered in Android and Apple devices
© 2026 RiskDiscovery | Sponsored by:
Deception Logic