[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Choose Wisely: AI-Generated Coding Risk Varies, a Lot
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
CISOs Feel the Heat Over AI Risk
Attackers Combo Up Evasion Tactics for BEC Phishing
Cybersecurity Keeps Events 'Uneventful'
Inc Ransomware Exploits SonicWall SMA Zero-Days
The Real AI Threat Is Blind Trust
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
Ars Technica
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
Sheetz is quitting VMware, migrating 11,000 virtual machines
Windows 0-day drops the same day Microsoft releases record number of patches
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
The US government warns that Russia state hackers are coming after your router
Now, defenders are embracing the prompt injection, too
Patch for Windows Defender 0-day could allow attackers to fill hard disk
CyberScoop
House intel bill includes provisions on state and local threat intelligence, election security, AI
North Korea’s IT worker scheme funds Russia’s war effort
What the World Cup can teach us about cybersecurity resilience
Director of Commerce AI standards office out after three months
Why blocking AI models won’t stop the cyber threats they create
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
Leading members of Scattered Spider sentenced in UK to 66 months in jail
Program to rotate cyber personnel through federal agencies saw little use
Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime
Security researchers find stalkers abusing Chrome’s sync feature
InfoSecurity Magazine
Russian Hacker Turns Jailbroken Claude Into Pentest Platform
A New Ransomware Threat Actor Emerges Every Week, Warns Report
FBI Warns of Deepfake Videos Impersonating IC3 Leadership
US Hospital Finance Software Provider Craneware Reports Data Theft
Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros
Cruciferra Crypter Uses Process Ghosting to Evade Detection
JadePuffer Returns With Ransomware Designed to Wipe AI Models
Researchers Build WordPress Exploit Using OpenAI's GPT
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
SecurityWeek
Empirical Security Raises $25 Million in Series A Funding
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
Clover Health Investments Discloses Data Breach
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
Zimbra Update Patches Critical Vulnerabilities
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
ZDNet
How spatial audio works on headphones and speakers - and the best way to experience it
Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next
90,000 Flock cameras have quietly gone up in the US: What they track and how to check your city
Light's new $299 flip phone has no apps and T9 texting, but aims to connect people
This Android 17 setting logs suspicious activity on your phone for troubleshooting - turn it on ASAP
Android backups count toward your 15GB Google storage limit now - how to check your settings
AT&T's new business plan includes 'unlimited' hotspot data - and starts at $75 per line
I tested iOS 26 Siri against iOS 27 Siri AI in my car - and it wasn't even close
Best tablets for note-taking 2026: Expert tested and reviewed
T-Mobile will pay for your first month of 5G home internet, and give you up to $200 back - here's how
The Hacker News
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
N-day is Becoming N-Hour. Patching Faster Won't Save You.
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
BleepingComputer
Critical wp2shell WordPress flaws exploited to install webshells
Closing the Identity Gaps in Critical Infrastructure Security
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Microsoft shares manual fix for WSUS sync delays and timeouts
Windows LegacyHive zero-day flaw gets free, unofficial patches
Estée Lauder discloses data breach via Oracle E-Business flaw
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
gbhackers
Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers
New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI
Craneware Cyberattack Exposes Employee and US Healthcare Customer Data
2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
Cybersecurity Dive
Ransomware victims fail to fix flaws that exposed them
Researchers trace SonicWall SMA1000 exploitation to late June
Hackers steal customer data from major hospital software vendor
Your attack surface is bigger than you think
The secret problem in AI infrastructure: Why MCP security starts with secrets
Abbott discloses cyberattack on cancer diagnostics business
Ransomware attack forces Coca-Cola to suspend US production at dairy unit
Gaps in network security, oversight strategy hamper US’s aviation cybersecurity regulators
Iran-nexus actors using AI to enhance cyber playbook
CISA warns that multiple vulnerabilities in SharePoint are under exploitation
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Kratos phishing-as-a-service kit loses its battle with international law enforcement
AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert
Intel fortifies Foundry with an actual customer: Fortinet
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy
Attackers pummel critical WordPress vuln to create all sorts of mischief
Scammers impersonate FBI on social media, prey on crime victims
Malicious cloud customers can bring down the power grid
Frontier LLMs couldn't help Hugging Face fight off evil agents
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Connecting AI agents to outside services explodes the risk radius
VentureBeat
Safety guardrails blocked Hugging Face's defenders, not the attacker, when an AI agent breached its systems
AI confidence just dropped 17 points in six months. That’s actually great news.
Capital One releases VulnHunter, an open-source AI tool that finds software flaws before hackers do
Zero trust must now move at agent speed
1Password moves into AI cost management, betting that token spend is the next enterprise budget crisis
Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools
Shared API keys expose AI agents at 69% of enterprises, new VentureBeat research finds
TechCrunch
AI music generator Suno breach affects 55M users, per Have I Been Pwned
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
The Zoom hack that says, ‘Don’t record me’
FBI arrests man accused of using Steam games to drain victims’ crypto wallets
Amazon fixing bug that billed some AWS customers billions of dollars
Coca-Cola suspended production at its Fairlife dairy after a ransomware attack
UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group
Network World Security
2026 network outage report and internet health check
Helios marks AMD’s biggest AI infrastructure push yet
Sheetz replaces VMware at more than 830 stores
AI workloads shake up observability market
New York State just hit pause on the AI data center boom
Huawei eying possible DRAM market entry
IBM targets AI edge with Power server, software upgrades
Network jobs watch: Hiring, skills and certification trends
Google Cloud configuration update disrupts VMware Engine stretched clusters
Fortinet adds AI protections to endpoint security platform
Help Net Security
AI agents tricked into recommending malicious GitHub repositories
Teleport enhances Identity Security platform with new AI agent behavior controls
JadePuffer returns with ransomware built to target AI models and infrastructure
Druva brings backup, recovery and governance to AI workloads
Cisco’s open-weight Antares models make vulnerability localization cheaper
Shufti simplifies cross-border compliance with the Glocal Platform
SonicWall SMA zero-days were exploited weeks before disclosure
Fake FBI agents target people who already got scammed
AWS wants GuardDuty to automate the first steps of threat investigations
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
SC Magazine
Ostium trading platform loses $23.75 million in off-chain exploit
Estée Lauder customer data compromised in Oracle E-Business Suite breach
Sophisticated crypter service Cruciferra evades detection with advanced techniques
Mithra AI launches to verify data before AI models produce answers
FBI warns of scammers impersonating agency online
7 mistakes companies make deploying AI agents
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Bridging the divide: The convergence of AI and infosec
Guide helps organizations evaluate AI in security operations centers
LG monitors criticized for silently installing McAfee ads via Windows Update
© 2026 RiskDiscovery | Sponsored by:
Deception Logic