[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Australian Gov't Weighs Mandatory AI Incident Reporting
Citizen Lab Slams Trump Administration, 'Techno-Fascist' Executives
Anthropic Gives Vetted Defenders Fewer Claude Guardrails
OpenAI Agent Escape Causes Wikimedia Service Outage
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Critical Healthcare Systems Aren't Quantum-Ready
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Ars Technica
Hackers obtain counterfeit TLS certificates for Google and other large services
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
Licensing costs driving 90 percent of VMware users to explore options: Survey
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Apple changes full-disk access permissions to curb abuse from AI agents
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Memory executives expect RAM shortage to continue through 2028
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
CyberScoop
Major rules for federal contractors handling sensitive data are nearing the finish line
FBI, French authorities seize deepfake CSAM-for-sale websites
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
Wiretapping change sparks big privacy fight in the Golden State
Former NSA chief Nakasone says agency overhaul is ‘probably needed’
Here’s how experts think CISA should tell agencies to protect OT
Citrix discloses third actively exploited NetScaler zero-day in less than a week
The US needs a real plan to defend its water systems
The legal questions raised by agentic AI hacks
InfoSecurity Magazine
Critical Flaw in Multiple Atlassian Products Exploited in the Wild
Europol and US GAO Sound the Alarm Over Quantum Threats
FBI and Secret Service Warn of FortiBleed Lockout Threat
OT Coalition Urges CISA to Mandate Federal OT Security
Attackers Hide AI Prompt Injections Inside Phishing Emails
Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One
Danish CPR Breach Highlights Challenge of Supply Chain Risk
ClickFix Attack Hides VBScript Payload in Browser Cache
SecurityWeek
TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
Oracle Health Data Breach Tally Climbs to Nearly 20 Million
FortiBleed Attackers Locking Victims Out of Fortinet Devices
Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform
Advantest Discloses Data Breach Months After Ransomware Attack
Chrome 155 Update Patches 247 Vulnerabilities
Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
ZDNet
Managers are using AI to write performance reviews – and it shows
Use Gemini for free? You’ll soon be limited to its weakest AI model
Office 2021 support ends this month – you have 5 options
Mistral’s new Le Chonk model brings AI cybersecurity to your business – and you control it
How I made a paid Mac app in 11 days with Claude – without writing a single line of code
iPhone 18 Pro Max can’t call or text on AT&T? Apple will replace it for free
This new ChatGPT scam tricks you into installing malware – how to spot the trap
Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
The Hacker News
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow
BleepingComputer
Owner of Empire cybercrime market gets 40 years in prison
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
Ransomware recovery CEO charged over secret ransom payments
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
Hackers hijack Google domains after breaching ccTLD registries
Microsoft Outlook to block MSIX attachments starting November
PoeLLM malware infects exposed AI servers in cryptomining attacks
Ransomware has a new target. Is your backup ready?
Hackers exploit critical Atlassian flaw after public PoC release
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
gbhackers
Critical Cisco Nexus Switch Vulnerabilities Allow Unauthenticated Attackers to Execute Code as Root
Financially Motivated Hacker Uses Agentic AI to Breach Multiple South Korean Finance Targets
PoC Exploit Released for Critical VMware Vulnerability Enabling Guest-to-Host Attacks
Hackers Target Hotels With Fake Guest Complaints to Deploy Blockchain-Based RAT Malware
Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands
ChainDrop and PolinRider Use Blockchain C2 to Steal Cloud and CI/CD Credentials
Attackers Hijack .gh, .sl, and .as Domains to Obtain Unauthorized SSL Certificates
12 Best ASPM Platforms Compared (2026): Features & Pricing
12 Best SCA Tools Compared (2026): Features & Pricing
Discord Security Bot Double Counter Hacked, Exposing Data of Millions of Users
Cybersecurity Dive
AI doesn’t change singular importance of phishing-resistant authentication, Okta says
FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users
IBM’s AI-powered vulnerability clearinghouse finds hundreds of Java flaws
US cyber resilience, oversight tested in series of attacks
Citrix issues patch for third exploited flaw in NetScaler
White House AI task force faces expertise, partnership challenges
Why permissions must be the foundation for next-gen identity security
Modernizing data security with DSPM, AI and fewer tools
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Fortinet warns that critical flaw in FortiMail is facing exploitation
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later
Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead
Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
US states sue popular kitmaker TP-Link over China risks
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
South Korean president calls for creation of tools that stop all cyber-attacks
Anthropic reconfigures its cool kids security program
Trump Mobile customers' data dumped - and some never even received their gold device
VentureBeat
Microsoft's record Patch Tuesday shows why severity can't decide what gets patched first
Your vibe-coded apps are a ticking time bomb for your business. Here’s how to secure them.
AI agents need more than access control — they need identity at runtime
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
TechCrunch
CIA officer admits to creating fake top secret government program to steal over $190M, including gold bars
LibreOffice says ‘no AI’ is now a software feature
Hackers steal 8 million citizens’ records from Danish government database
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Federal judge calls Flock ‘indiscriminate mass surveillance’
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
OpenAI cuts ties with 3 safety researchers, WSJ reports
Network World Security
SonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
Arista steps up its Ethernet challenge to Nvidia’s AI scale-up networking fabric
Dell gives AI agents a broader view of enterprise data
HPE supercharges ProLiant servers with AMD’s EPYC 9006 processors
AMD to ramp up CPU, GPU supply in 2027 as AI demand surges
Cisco readies new control plane for quantum networks
Google overhauls cloud modernization portfolio with new AI agents
GTT bets that the network, not the log file, is where AI-era security gets won
Micro data center company launches stackable data center for edge and AI
AWS seeks to automate cloud optimization with new AI agent
Help Net Security
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
GitHub adds AI to catch passwords before a code push
What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims
Pricing your bad days and how to build an economic model for security decisions
Who watches the AI watching your street?
How AI can fix cybersecurity compliance: From dashboards to continuous execution
The people who know passkeys best are still typing passwords
Java library vulnerabilities: IBM and Red Hat fix 400+ previously unknown flaws
Medical devices patients rely on most are least prepared for quantum attacks
SC Magazine
AI security is an architecture problem, not just a model problem
FortiBleed campaign still attacking Fortinet devices, US agencies warn
California updates wiretapping law, removing right to sue over internet surveillance
Lumen appoints Kim Keever as chief security officer
Atlassian warns of critical arbitrary file access vulnerability in self-hosted products
Attackers hijack top-level domains to mint counterfeit TLS certificates
Hadrian Security raises $40 million to expand AI-powered penetration testing
FortiBleed campaign targets Fortinet devices, leading to ransomware
Bromcom notifies customers of personal data breach affecting SSO technology
Don’t think of readiness as just an onboarding problem
© 2026 RiskDiscovery | Sponsored by:
Deception Logic