[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
AI-Generated Patches Fail Half the Time
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride
Researcher Claims Control of ChatGPT Secure Sandbox
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
AI Sends Global Crime Syndicates Into Fraud Nirvana
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
No Perfect Fix for AI Browser Prompt Injection Flaws
CSS: The Hidden Threat Lurking in Your Inbox
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Ars Technica
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Claude published malicious code to the Internet and attacked 3 real companies
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
CyberScoop
More than half of AI-generated patches are broken
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
Ransom Cartel creator sentenced to 16 years in prison
The water sector just got it’s wake-up call. Again.
Snowflake hacker pleads guilty, faces up to 32 years in prison
Tom Cotton prods Treasury for tax code tweaks to modernize OT
Open-source software’s archenemy TeamPCP goes back further than anyone thought
AI is getting better at election facts, but voters shouldn’t rely on it
InfoSecurity Magazine
Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Google Links Redact Extortion Group to BlackFile Rebrand
Ransomware Surges in July After Q2 Lull
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
TeamPCP Traced Back to 2020 Cryptojacking Operation
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
Violent Physical Crypto Thefts Surge to $30m in Losses
Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing
Fake Open VSX Extensions Harvest Private Repo and CI Data
SecurityWeek
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)
Microsoft, Apple Release Fresh Security Updates
3.8 Million Impacted by Unlimited Technology Systems Data Breach
Critical Vulnerabilities Patched With Chrome 151 Update
Snowflake Hacker Pleads Guilty in US Court
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway
ZDNet
This 6-port USB-C charger replaced my ugly power brick - and powers my entire desk
I was loyal to T-Mobile for 10 years, but switching to Mint slashed my bill - by a lot
Samsung Galaxy Watch 9 review: Health data overload, but built for the future
This Bluetooth-only Marshall home speaker sounds so good, I can forgive the missing Wi-Fi
Your phone doesn't block SIM swapping attacks by default: Turn on these carrier settings now
Samsung Galaxy Z Fold 8 review: The compact foldable I've wanted all along
I read Microsoft's Windows 11 'quality' progress report - and the subtext says it all
I compared Google's pricier Pixel 11 series to Samsung's Galaxy lineup - here's the better value now
Apple rushes out emergency fix for screen sharing flaw on Macs - update ASAP
I'm a diehard OnePlus user: Here's my plan now that the company is leaving North America
The Hacker News
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Growing Up The Hard Way
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
BleepingComputer
Unlimited Technology Systems breach impacts 3.8 million people
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Real emails, hijacked payments: Two H1 2026 attack chains
North Carolina Ports confirms cyberattack disrupting operations
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
ClickFix attack pushes macOS infostealer for crypto theft attacks
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
Swiss government SharePoint breach compromised 200 accounts
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Meta AI model hacked a company during misconfigured cyber test
gbhackers
Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts
New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses
Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Claude Code RCE Flaw Lets Malicious Pull Requests Execute Code on Developer Systems
Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz
What Is Cyber Security Risk Assessment? A Complete Guide (2026)
Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts
1000 Best Google Dorks List (Google Hacking Guide) – 2026
Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
Cybersecurity Dive
Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Hackers grow more willing to destroy, not just disrupt, OT systems
OpenAI warns autonomous hacks are ‘watershed moment for computer security’
Western government leaders call for a focus on infrastructure resilience, not AI hype
CISA is prioritizing work with critical infrastructure as it begins to recover from cuts
White House walks tightrope on securing AI without stifling tech innovation
Tech industry alliance proposes AI agent safety reporting program
AI widely used to exploit critical flaws, disrupt supply chains
AI makes costly spearphishing attacks easier, cyber insurer says
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Ransomware attacks spike as world distracted by AI
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder
Attacker phished way into US defense supplier's Microsoft 365 account
'Asimov was right' about rules for robots, says ex-US Cyber Director
China launches mysterious probe into security of Palo Alto Networks' products
How the famed USENIX Security conf is managing a flood of papers in the AI era
AI struggles to patch vulns without adult supervision
Humans in the loop miss a third of dangerous AI coding agent requests
VentureBeat
AI agents are part of your team now. Here’s how to secure all of them.
The browser is where attacks land. Why is security still focused on the endpoint?
Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
Mastercard spent decades training its fraud system to see bots as thieves. Now bots are the ones doing the buying.
Hush Security says the AI security problem has shifted from protecting models to governing identities as autonomous agents spread
TechCrunch
Computer maker Framework notifies ‘all customers’ of a data breach
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
Google says hackers are calling financial firm employees to hack and extort victims
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
Hacker pleads guilty to stealing data from more than 165 Snowflake customers
PSA: Apple’s Private Relay can leak your real IP address
Android app developers may be unwittingly sharing their users’ location data with advertisers
Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress
Hackers steal over $130M by exploiting bug in offline hardware wallets
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
Network World Security
Samsung offers future AI memory roadmap
Polish data center plans to send its waste heat to the neighbors
AMD to buy Taalas, maker of model-specific AI chips for enterprise inference
Agentic AI could force a rethink of enterprise AI server design, researchers say
NatJack exploits put NAT security assumptions to the test at Black Hat
Top network and data center events of 2026
AWS targets AI cost concerns with new Marketplace Insights tool
Arista hits first $3B quarter as AI networking demand continues and supply pressures show signs of improvement
Palo Alto Networks at Black Hat: How AI erased the 50-day patch window
2026 network outage report and internet health check
Help Net Security
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens
Keepit AI Truth Cloud protects the data behind enterprise AI
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
What the first year of EU AI Act transparency enforcement could look like
US fuel gauge exposure fell by more than half in three months
ShieldFont fights AI scraping by handing crawlers the wrong words
Gut feeling does nothing against AI spear phishing texts
Photos: Black Hat USA 2026, part two
Novel-reading apps used users’ phones to generate fake ad traffic
SC Magazine
Vishing group UNC6671 now focuses on extorting M&A firms
Researchers bypass Spectre v2 mitigations
Zbtlink denies backdoor claims amid firmware download pause
Walmart faces lawsuit over alleged secret voiceprint collection in Illinois
AI coding tools vulnerable to malicious GitHub issues
Crypto thieves increasingly using physical attacks for virtual currency theft
OpenAI disrupts major ChatGPT-driven scam campaign in Cambodia
China reviews Palo Alto Networks products, citing security concerns
Chinese-linked LightSpy spyware expands to over a dozen countries
How we can apply lessons from The Odyssey to the AI challenge
© 2026 RiskDiscovery | Sponsored by:
Deception Logic