[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Critical Healthcare Systems Aren't Quantum-Ready
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Chinese Hackers Impersonate US Officials for AI Cyber Espionage
Need for Speed: AI-Driven Attacks Are Changing Security Strategies
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
Ars Technica
Hackers obtain counterfeit TLS certificates for Google and other large services
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
Licensing costs driving 90 percent of VMware users to explore options: Survey
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Apple changes full-disk access permissions to curb abuse from AI agents
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Memory executives expect RAM shortage to continue through 2028
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
CyberScoop
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
Wiretapping change sparks big privacy fight in the Golden State
Former NSA chief Nakasone says agency overhaul is ‘probably needed’
Here’s how experts think CISA should tell agencies to protect OT
Citrix discloses third actively exploited NetScaler zero-day in less than a week
The US needs a real plan to defend its water systems
The legal questions raised by agentic AI hacks
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
AI policy circles targeted in China-linked phishing operation
InfoSecurity Magazine
Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One
Danish CPR Breach Highlights Challenge of Supply Chain Risk
ClickFix Attack Hides VBScript Payload in Browser Cache
Nikkei Discloses Two Employee Cloud Account Compromises
Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities
Critical Medical Devices Unable to Support PQC Transition
ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise
Police Urge Passkey Use After Surge in Cybercrime Profits
Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
SecurityWeek
Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies
Android’s October 2026 Updates Patch 25 Vulnerabilities
Atlassian Patches Critical Vulnerability Affecting 8 Products
Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks
Cybersecurity M&A Roundup: 39 Deals Announced in September 2026
Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
ZDNet
Use Gemini for free? You’ll soon be limited to its weakest AI model
Office 2021 support ends this month – you have 5 options
Mistral’s new Le Chonk model brings AI cybersecurity to your business – and you control it
How I made a paid Mac app in 11 days with Claude – without writing a single line of code
iPhone 18 Pro Max can’t call or text on AT&T? Apple will replace it for free
This new ChatGPT scam tricks you into installing malware – how to spot the trap
Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
The Hacker News
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
BleepingComputer
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Atlassian warns of critical file-access flaw in Jira, Confluence
ASOS confirms data breach after “HACKED” in-app notifications
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
How to secure RMM software: 8 controls MSPs should test
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Engineer sentenced for locking over 3,000 devices on employer network
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
gbhackers
Partisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks
Best Just-in-Time (JIT) Access Tools Compared (2026): Features & Pricing
12 Best Fine-Grained Authorization Tools Compared (2026): Features & Pricing
12 Best Certificate Lifecycle Management (PKI) Tools Compared (2026): Features & Pricing
12 Best Machine Identity Management Solutions Compared (2026): Features & Pricing
Earth Sirrush Espionage Activity May Support Sandworm Operations Against Ukraine
Tencent Cloud-Linked AI Agent Fleet Bypasses Amap Anti-Bot Protections
Rockstar Games Attacks Expose MFA Fatigue, OAuth Token Theft and Dev Pipeline Security Failures
Fake ChatGPT, Claude and Gemini Ads Use Browser-in-the-Browser Phishing to Steal Accounts
ASOS Hacked as Attackers Abuse Customer Notification Platform to Threaten Data Leak
Cybersecurity Dive
IBM’s AI-powered vulnerability clearinghouse finds hundreds of Java flaws
US cyber resilience, oversight tested in series of attacks
Citrix issues patch for third exploited flaw in NetScaler
White House AI task force faces expertise, partnership challenges
Modernizing data security with DSPM, AI and fewer tools
Why permissions must be the foundation for next-gen identity security
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Fortinet warns that critical flaw in FortiMail is facing exploitation
SOC staffers generally pleased with AI’s impact, but worries remain
State-linked actor targets US AI policy experts in credential phishing campaigns
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
South Korean president calls for creation of tools that stop all cyber-attacks
Anthropic reconfigures its cool kids security program
Trump Mobile customers' data dumped - and some never even received their gold device
Microsoft extends the Outlook naughty step with two more file types
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
Asos app delivers a data leak threat instead of fast fashion
Denmark's ID register spills more people's details than the country has residents
Legacy sign-on service comes back to bite school software provider Bromcom
Atlassian warns of critical file access flaw in its datacenter products
Security researcher claims they found KVM guest-host escape flaw
VentureBeat
Microsoft's record Patch Tuesday shows why severity can't decide what gets patched first
Your vibe-coded apps are a ticking time bomb for your business. Here’s how to secure them.
AI agents need more than access control — they need identity at runtime
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
TechCrunch
LibreOffice says ‘no AI’ is now a software feature
Hackers steal 8 million citizens’ records from Danish government database
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Federal judge calls Flock ‘indiscriminate mass surveillance’
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
OpenAI cuts ties with 3 safety researchers, WSJ reports
California governor vetoes bill banning use of ‘pervert glasses’ to secretly record people
Network World Security
Cisco readies new control plane for quantum networks
Google overhauls cloud modernization portfolio with new AI agents
GTT bets that the network, not the log file, is where AI-era security gets won
Micro data center company launches stackable data center for edge and AI
AWS seeks to automate cloud optimization with new AI agent
IBM expands mainframe networking options as AI reshapes enterprise infrastructure
New memory player CXMT begins mass production of DRAM platform
From automated response to reasoning: Building confidence in AI-driven NetOps
Startup doxx.net hands the network controls to AI
IBM’s Bob wants to move in: Agent available for on-prem deployment
Help Net Security
ASOS confirms data breach after “hacked” app alert reaches shoppers
Anthropic loosens Claude’s cyber restrictions for verified defenders
AI Agent Gateway: Open-source tool keeps credentials out of agent configs
OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing
AI endpoint management: Visibility, compliance, and remediation
Even with OT network visibility, critical infrastructure operators struggle with legacy equipment
Automation, AI agents or people? Sorting out who handles each security finding
Check your X.Org server version because a dozen vulnerabilities have been patched
Anaconda combines agent swarms with autonomous security testing
Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia
SC Magazine
Building Quantum Safe Security as AI Safety and Governance Won't Save You - Vijay Viswanathan - BSW #468
A personnel file is a map: Why the FBI breach matters
Changing the game: How AI forces organizations to revisit assumptions about recovery and resilience
Typing, textGrain, NetScaler, Fortinet, Copilot, LibreOffice, Dots, Aaran Leyland - SWN #622
Critical Atlassian flaw exposes files across eight products
Financial phishing campaigns exploit fragmented hosting, AI tools
Phishing scam targets tourists applying for Schengen visas
MCP fixed secret handling. URL elicitation moved the phishing risk into the browser
Vermont embraces AI as a 'power tool' for state employees
AI model Mythos aids discovery of critical Rejetto HFS vulnerability
© 2026 RiskDiscovery | Sponsored by:
Deception Logic