[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Identity-Based AI Attack Threatens Security of Enterprise Data
Patch Tuesday Sets Another Record With 974 CVEs
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
Companies Have 6 Months to Prepare for Automated Attacks
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
Ars Technica
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent
I rented a car, and within hours, my driver's license was for sale
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Think twice before installing this device promising free movies
Inside Meta’s push to put robots to work in data centers
CyberScoop
FBI cyber chief worries private sector not sharing enough cyber threat information
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Feds accuse China of ‘systematic’ distillation of U.S. AI models
Russian national extradited to US for alleged involvement in bank-account takeover scheme
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Why federal cyber defense demands an offense-driven mindset
In most cities, nobody owns the whole network
European parliament members call for slowdown of Serbia’s EU entry over spyware use
Why judgment is emerging as cybersecurity’s defining skill
InfoSecurity Magazine
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Gigabud Uses Android App Cloning to Evade Fraud Detection
ClickFix Moves into the Browser to Steal Cryptocurrency
NHIs Now the Number One Corporate Entry Point for Hackers
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
SAP Patches Maximum Severity “Overpass” Flaw
France Establishes New Government-Focused Cyber Incident Response Unit
Grindr Settles UK Data Privacy Claims for £26m
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
THost9 Android RAT Pairs Packed Loader With ADB Worm
SecurityWeek
AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
Android’s September 2026 Updates Patch 180 Vulnerabilities
Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Ivanti Patches Critical Flaws Across Enterprise Security Products
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
This Key Will Self-Destruct: An Open Standard for Revocable API Keys
ZDNet
The Hacker News
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
BleepingComputer
US says Chinese firms extracted billions of tokens from frontier AI models
Veradigm warns of patient data breach after ransomware gang claims attack
MFA's Weakest Link: Account Recovery Is the New Attack Path
Over 36,000 exposed Plex servers vulnerable to recent flaws
Man gets 15 years for extorting women with AI-generated porn videos
New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
Google warns of new Chrome zero-day bug exploited in attacks
Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
The EU CRA's Real Question: What Shipped, and When Did You Know?
gbhackers
Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs
Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root
Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks
GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems
ChatGPT Flaw Could Let Attackers Steal Gmail Data Across User Accounts
Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation
Cybersecurity Dive
CISOs are feeling the security burden of accelerated AI use
New FBI cyber strategy promises increase in adversary disruptions
N-able issues patch for zero-day flaw
Don’t let AI distract from cybersecurity basics, officials and executives warn
Essential AI agent security questions
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
OpenAI pledges $1B to provide resources, training for frontline cyber defenders
SonicWall urges immediate patching of chained vulnerabilities
Government, industry partner to shut down long-running Sality botnet
Government lacks ability to verify AI labs’ claims, experts say
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
WeChat worm could pwn a friend before they even answered the call
Microsoft breaks Patch Tuesday record with 974-CVE deluge
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Boston Scientific left nursing its bottom line after cyberattack
How to secure hybrid meeting rooms without sacrificing user experience
LG accused of 'egregious invasion of privacy' over TV data collection
BigBear phishing crew nets thousands of Microsoft 365 credentials
Extortion crews have their eyes on high-value AI data, Google warns
Britain reboots its space strategy with £7.8B already on the launchpad
Nightwing CEO has a Labor Day message for staff – and apparently The Register
VentureBeat
Agents identifying as OpenAI systems wrote 17,000 posts to a wiki no one was supposed to write to
Most security teams don't know how many AI agents they're running. Falcon Guardian found 18,000 at one company that had approved only 300.
MCP's new spec turns a planted prompt into a stolen credential
China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using
Google’s Gemini 3.8 Flash is built for agents, while its Cyber twin hunts vulnerabilities
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.
TechCrunch
‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
A hacker stole $340M in a crypto heist, then returned most of it
OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure
US military disabled ad tracking on troops’ devices following reports of targeted attacks
Abliteration.ai is making a business out of removing AI guardrails
It sure looks like hackers breached a major ID card verification service
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
Network World Security
Leap second proposal will keep software stacks in sync
Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
BackBox brings AI to network automation but keeps humans in control
2026 network outage report and internet health check
AI data boom fuels tape storage resurgence
Nvidia lets you build your own AI clusters locally with PAIR software
When analyst benchmarks miss the mark: Why Nvidia doesn’t fit Forrester’s data center matrix
HPE’s record Q3: AI infrastructure, networking demands drive growth, but supply constraints tap the brakes
VMware Cloud Foundation 9.1 adds transit gateway flexibility, segmentation, and native EVPN VXLAN support
Dell’s $95B AI backlog shows the infrastructure crunch is far from over
Help Net Security
Akeyless adds real-time enforcement for AI agents in production
Orchid Security targets AI agent risk with drift detection and kill switches
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
Zscaler Agentic SOC combines AI agents with zero trust telemetry
Chinese AI firms are siphoning capabilities from American models, CISA warns
Securin Platform helps security teams prove when attack paths are closed
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
AI-Infra-Guard: Open-source security scanner for AI systems
SC Magazine
BigBear 2.0 phishing campaign compromises MFA-protected Microsoft accounts
One report, many missions: A better way to coordinate America's cyber defense
Security Money: The Index Explodes, as the History of AI Teaches Us About Investments - John Willis - BSW #464
New Android RAT uses worm to target exposed ADB services
Center for Internet Security partners with OpenAI for AI cybersecurity pilot
Mars Security launches real-time threat intelligence to detection platform
MikroTik routers targeted by active SSH zero-day exploitation
Broadcom patches critical VMware Workstation and Fusion VM escape vulnerabilities
Madagascar strengthens digital identity program with new cybercrime laws
Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland - SWN #614
© 2026 RiskDiscovery | Sponsored by:
Deception Logic