[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Attackers Pounce on Critical Artifactory Bug Following Disclosure
Stronger Security Drives Ransomware Groups to Recruit From Within
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
AI Model Evaluator METR Hit by Credential Theft, Probing
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
Anthropic Users Hit by Infostealer Attacks, Session Thefts
Ars Technica
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Think twice before installing this device promising free movies
Inside Meta’s push to put robots to work in data centers
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Claude, Codex, and Hermes installed unowned code inside corporate networks
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
AI agents meant to replace Meta workers made “large-scale, disruptive actions”
Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
Waymo doubles spending on lobbying in robotaxi battle with Uber
Grok exfiltrates user data when malicious instructions are encrypted
CyberScoop
The FCC wants consumers to rate their telecom’s anti-robocall protections
Dogged Russia-based botnet dismantled after 23-year run
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Wyden seeks upgraded NSA security guidance on commercial VPN use
FBI raises alarm over deceptive phishing campaign targeting prominent people
Tina Peters, through attorney, backs off formal role in Shasta County elections
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
The Collective Cyber Defense letter wrote your next vendor questionnaire
McKesson copes with fallout from data theft extortion attack
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
InfoSecurity Magazine
Russian Man Extradited Over Malware Campaign Targeting Freelancers
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Attackers Steal METR API Key and Burn $600,000 in AI Credits
65% of Enterprises Have Seen AI Agents Act Out of Scope
White House Launches Pilot Program in Texas to Protect Water Infrastructure
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
Healthcare Giant McKesson Investigates Data Breach Incident
SecurityWeek
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
Exploit Published for Fresh Cleo Harmony Vulnerability
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards
Malicious Virtualizor Update Served via BGP Hijacking
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
Chrome and Firefox Updates Patch Dozens of Vulnerabilities
23-Year-Old Sality P2P Botnet Disrupted
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Palo Alto Networks Acquires AI Agent Platform Console
ZDNet
The Hacker News
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
How to Secure Enterprise AI: From Adoption to Incident Readiness
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
BleepingComputer
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
Ransomware protection for MSPs: A 6-point checklist for faster recovery
Dropbox accounts breached through Lenovo email verification flaw
Microsoft Defender flags legitimate Google search links as malicious
US charges Russian for infecting 80,000 freelancers with malware
Sality botnet infrastructure dismantled in joint global takedown
SonicWall warns of actively exploited SMA1000 zero-day flaws
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Aesto Health says data breach affects over 9.5 million patients
Critical Langflow flaw exploited to steal OpenAI and AWS keys
gbhackers
Threat Intelligence: Definition, Benefits, and Use Cases
Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers
255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover
Palo Alto Networks Acquires Console to Add Agentic AI Workflows to Cortex
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs
Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited in the Wild
Cybersecurity Dive
CISA scraps 6 free cybersecurity assessments for critical infrastructure operators
Security policies fail to keep up with a hybrid cloud world
Frontier AI helps exploit flaws in tests using key industrial devices
PaperCut issues emergency patches as threat actors target chained vulnerabilities
State-linked actor targets Cisco routers for espionage
Frontier AI tipping the scales toward cyber adversaries
CISA identifies security hurdles that led to very different results in two red-team engagements
Hundreds of agents went rogue in lead up to Hugging Face breach
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
Boston Scientific says cyberattack disrupted order processing, shipping
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
SonicWall's SMA1000 boxes under active attack again
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
UK cyber bill targets AI users, not the vendors building it
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
Another Artifactory CVE under attack by AI agents or humans
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
Anthropic pledges to try harder to keep models under control, asks partners to chip in
33-hour BGP hijack of Softaculous traffic prompts security scramble
Healthcare cyberattacks hit pacemakers and millions of patient records
VentureBeat
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.
Identity and permissions aren’t enough to govern AI agent behavior
AI agents need their own identity before they need a gateway
AI agents that pass authentication can still drift, expose data, or get memory-poisoned
The three layers of agentic AI security: A defense-in-depth architecture for autonomous agents
Visa ships a security AI that patches production code before any human reviews it
TechCrunch
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
Norway considers ban on camera-enabled wearable ‘pervert glasses’
X says attackers are targeting user accounts after the launch of X Money
AIR raises $50M to help companies vet the skills and add-ons AI agents use
Florida and Texas move to block Flock cameras over privacy concerns
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
How AI could make it harder for governments to use hacking tools
More Americans oppose police license plate cameras than support them: survey
ATF declares ‘major incident’ as ransomware gang claims hack
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
Network World Security
VMware by Broadcom: Product, service and support news
Palo Alto Networks buys Console to boost agentic security
Mainframe shops tap AI for system insights and recommendations
2026 network outage report and internet health check
China-linked hackers turn Cisco IOS XR routers into covert attack infrastructure
Nvidia unveils alternative high-bandwidth technology to bolster AI cards
Private AI cloud, agentic infrastructure dominate VMware Explore
Tailscale expands from VPN into a full connectivity platform
On-device translation: Why smaller, specialized AI models win
Kyndryl, Broadcom expand partnership to push private clouds for AI work
Help Net Security
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Download: The Agentic Software Development Guide
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
Attackers are going after prominent individuals through OAuth phishing, FBI warns
SonicWall SMA 1000 appliances under attack via zero-day flaws
A battery storage cyberattack would look exactly like a badly tuned controller
Global sinkhole operation ends Sality botnet’s 23-year run
Keepnet launches free SMS/Call Reporter for iOS
Visa enhances A2A Protect to stop fraud before money leaves the account
Edge Case launches Guardian, an AI platform for tracking risk across autonomous systems
SC Magazine
Ping YOUniverse: Restoring trust in both humans and AI agents
Breeze Comet threat actor targets Brazilian financial sector with sophisticated attacks
Leaked documents reveal Russian military cyber recruitment pipeline
NASCIO urges Congress to reauthorize grant program and address AI governance
New PackClient RAT sold on Telegram
65% of enterprises see AI agents acting outside of scope
Microsoft identifies ‘TerminalFix’ campaign spreading Python reverse tunnel
Preventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and Kai - Todd Sorrel, John Hurley, Galina Antova - BSW #463
Cronos network resumes activity after $74 million lending exploit
CrowdStrike launches AI agents for Project QuiltWorks
© 2026 RiskDiscovery | Sponsored by:
Deception Logic