[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
CISOs Break Their Silence in 'Declassified' Docuseries
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
Video Call Exploit Chains Two Flaws in Unisoc Modems
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
Hugging Face Breach Raises Big Questions About AI Security Controls
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
Mission-Driven Security: Inside a Global Bank's Defense
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
Ars Technica
Microsoft Copilot reveals secret input that allowed it to be hacked
Nvidia discloses $21B stake in SpaceX
Vulnerability giving attackers full control of Macs is under active exploitation
PBS station fears losing 50TB of data after being ghosted by cloud storage provider
OpenAI and Anthropic in price war as Chinese AI rivals gain ground
Private security firms will soon be allowed to hack overseas cybercriminals
Terabytes of credentials leaked in massive supply-chain attack
DEF CON crowd suspected in fake-hotspot attack on Delta flight
Chrome adopts what may be the best protection yet against account takeovers
New Pass-ta-key attack reveals all the things we didn't know about passkeys
CyberScoop
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
Details emerge on BlackFile’s recent attacks on financial companies
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
AI’s ‘middle class’ has gotten dramatically better at hacking
Trump turns to private sector in offensive hacking operations memo
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Kimwolf botnet rebuilt to survive takedowns, researchers say
InfoSecurity Magazine
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities
NASA Ground Control Software Flaw Enables Unauthenticated Commands
Cyber Incident Disrupts Student Services at UT San Antonio
Three-quarters of Ransomware Attacks Target Mid-Market Firms
UK Legal Regulator Raises AI Misuse Concerns
UNISOC Modem Flaw Enables Remote Code Execution via Video Calls
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act
SafePal Data Breach Hits Tens of Thousands of Customers
SecurityWeek
Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
Xpander Raises $7.5 Million for AI Management and Governance
Fortinet Acquires AI Security Company Virtue AI
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
GitLab Patches Critical Code Injection Vulnerability
Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
680,000 Impacted by French Tax Authority Data Breach
ZDNet
I tested GNOME's glassy new look - and it's simply spectacular
Add photos to your iMessages with one tap - how to skip that annoying iOS menu
One of our favorite Bluetooth tracker cards is under $35 with this exclusive deal
Can you guess Apple's next move? Last chance to win big in ZDNET's Big Guessing Game
I tested Omarchy Quattro, one of the first Linux distros to go all in on AI - and I didn't hate it
Ubuntu on Windows outgrowing native installs? Not according to Canonical's Jon Seager
T-Mobile will cover your first month of 5G home internet and give you up to $200 back - here's how
Google's AI can see your business data by default in Workspace - unless you disable it
Microsoft reveals customizable context menu for Windows users - how to try it out
Apple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it
The Hacker News
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
BleepingComputer
Comcast turns your Xfinity WiFi into a home motion detector
Clop created custom web shell for Windchill data theft attacks
Your Controls Block Known Attacks. What About the Behavior?
Microsoft tests faster Windows File Explorer, new context menu
CISA: Windows Task Host flaw now exploited by ransomware gangs
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft starts removing WMIC tool used by cybercriminals
Hacker claims 3.6 million Azure account records stolen from major companies
Pokémon Center data breach exposes customer info, cancels some orders
Microsoft confirms GitHub is down worldwide
gbhackers
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Critical MLflow SSRF Flaw Exploited in the Wild
OpenAI Warns Organizations to Automate Cybersecurity as AI-Powered Attacks Accelerate
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
French Tax Authority Cyberattack Exposes Tax Data of 678,000 Individuals and Businesses
Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS
Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver
AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
Cybersecurity Dive
GitLab issues emergency patch for critical code-injection flaw
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
Critical flaw in SAP Commerce Cloud faces initial exploitation attempts
Major genetic-testing firm says hack compromised sensitive patient data
Why more security data has blurred companies’ view of risk
Researchers confirm breach claims by data-extortion group
Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks
Researchers find AI-powered hacking tools for sale in underground forums
US government will let private companies hack criminal gangs
Hackers abuse AI models to find new entry paths
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Expired credit cards revived by researchers to make unauthorized payments
CISA gives feds 3 days to fix actively exploited Ray RCE bug
Apple plugs image-processing hole ripe for spyware abuse
Copilot tricked into telling reseachers how to hack itself
Crook hawks millions of records allegedly plundered from corporate Azure tenants
Code fixers have fired up the AI warp drive. Strange new worlds await
Black Hat and DEF CON are AI conferences now, too
Microsoft blames AI for delayed Exchange update, can’t say when it will arrive
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI
Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do
VentureBeat
Three Claude agents given conflicting orders sabotaged each other on a shared server — then didn't tell users what they'd done
Four of five enterprises that secured AI agent identities still can't contain one that goes rogue
OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks
AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push
AI agents are part of your team now. Here’s how to secure all of them.
The browser is where attacks land. Why is security still focused on the endpoint?
Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know
TechCrunch
OpenAI institutes new safeguards after Hugging Face breach
Comcast adds motion sensing to millions of its newer routers, with a privacy catch
Bluesky says its recent outage was caused by another DDoS attack
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
How to tell if your AI platforms’ accounts have been hacked
What we know about the alleged Iranian hacks on US water utilities
US courts will start publishing how often the government uses spyware
Flock says its new tool will help identify police abuse, but hasn’t explained how it works
If Apple sends you a push notification alerting you to a spyware attack, take it seriously
Network World Security
Reports: Google partnering with AMD for next-gen hybrid TPU
Why 6 GHz Wi-Fi will make or break the modern enterprise
Is your networking built for AI’s traffic patterns and data volumes?
IBM partners with OpenAI to drive enterprise AI deployment
It’s final! Judge says HPE’s Juniper acquisition is complete
Google, Microsoft and Nvidia back 800V DC standard for AI data centers
Five takeaways from Cisco’s Q4 and what they mean for IT pros
Cisco rides ‘networking supercycle’ for strong Q4
North American data center vacancy holds at just 1%
2026 network outage report and internet health check
Help Net Security
NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation
Download: 2026 Credential Risk Report
Google’s $10,000 refund test shows why AI agents need zero trust
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
OpenAI tightens defenses after AI agents breach research environment
Hacker claims millions of records stolen from corporate Azure tenants
Synthesized builds Test Data Agent to validate AI agents with production-like data
Google’s open-source HEIR lets AI work with data it can’t see
A hollowed out data layer is making CISOs fly blind into AI attacks
Attackers turn to AI for help identifying files worth stealing
SC Magazine
Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608
How to Build a Security Architecture Operating Model
What Cloud Security Actually Controls
Cloud Governance and Assurance: Evidencing Control Effectiveness Across Providers
Control Plane Gaps Create Invisible Cloud Risk
How to Build an IAM Program: Strategy, Phasing, and What Goes Wrong
CISA confirms 2025 Windows Task Host flaw exploited by ransomware groups
What the Iran cyberattacks can teach boards about cyber warfare
Wiz agent finds Snowflake repo flaw in code co-authored by GitHub Copilot Autofix
Augmenting Threat Intel Analysis with Agents - Sai Kiran Uppu, Chris Wallis, Ramin Farassat - ASW #396
© 2026 RiskDiscovery | Sponsored by:
Deception Logic