[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
Cisco Zero-Day Highlights API Endpoint Authentication Issues
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
MFA Won't Save You From OAuth Consent Abuse
AI Agent Breaches Spanish Organization, Modifies Personal Data
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
China's FamousSparrow APT Spies on US Politics in Latin America
AI Security Spending Jumps as Fear Outpaces Proof of Value
Fighting Your Dragons Through Tough Tech Times
Ars Technica
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
CyberScoop
Early Scattered Spider member pleads guilty to cybercrime spree
Researchers use AI to find widespread software decoder flaw
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
Cisco alerts customers to second actively exploited zero-day in as many days
The AI hacking apocalypse is not inevitable
Authorities seize popular, long-running DDoS-for-hire service domains
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
Treasury’s Scott Bessent says no liability exemptions for AI labs
InfoSecurity Magazine
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
CISA Upgrades Vulnerability Reporting Platform with More Automation
Manufacturing Accounts for 22% of all Ransomware Victims
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Cyber Essentials Has Record Year but Takeup Remains Low
Cisco Warns of Active Exploitation of Critical ISE Flaw
AI Agent Carries Out Multi-Stage Data Theft Attack
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
SecurityWeek
TigerByte Cyber Emerges From Stealth With $3 Million in Funding
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
23 Million User Records Compromised in Gyazo Data Breach
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
NightmareStresser DDoS Service Disrupted in International Operation
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Critical Orkes Conductor Vulnerability Exploited in Attacks
MIND Secures $72 Million for AI-Powered DLP
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
ZDNet
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
Roku rolls out over 30 subscription bundles for up to 30% off, plus a new Labs feature
Claude Code’s revised projects adds AI orchestration, but local developers must wait
Bose returns with new open earbuds (and a refreshed favorite)
I recommend you don’t run these appliances on your power station – even if you can
Anthropic merges Claude chat and Cowork into one
How September’s Pixel Drop changes the way you call and message important contacts
I’ve used both iPhone 18 Pro models – here’s how my buying advice is changing in 2026
Windows 11 out-of-band update fixes audio glitch and other bugs – grab it now
The Hacker News
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
Identity Visibility in 2026: The Foundation of Identity Security
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
BleepingComputer
BragJack attacks hijack AI browser agents through malicious extensions
North Korean WaterPlum hackers infected 30,000 devices worldwide
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Viral AI actress' hotline face-scans every caller, watches their mood
Gyazo server flaw exploited to steal 23.6 million user records
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft Teams will let admins block custom file extensions
Webinar: Which Google Workspace security controls actually matter?
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
gbhackers
Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet
North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes
PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner
PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Cybersecurity Dive
Settra ransomware variant deployed in recent attacks
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
Manufacturers make patching progress, but identity management still major weakness
Hackers exploit zero-day flaw in Cisco email gateway
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
AI is now leading driver of new cybersecurity spending
Companies’ AI strategies don’t account for agentic tools
Security teams increasingly outflanked by AI agents
Malicious actors already using critical GitLab flaw, CISA and others warn
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Agentic security is the billion-dollar challenge for some clever startup to solve
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
North Korea's fake job interviews infected 30,000 devices
FBI: Fake cop and government impersonation scams cost victims $1.6B
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
Researchers find way to listen in on headphones from afar
China's Salt Typhoon backdoors Latin American orgs with new snooping malware
London property manager breach may have exposed bank details and lockbox codes
Cisco drops another exploited zero-day, this time a perfect 10
VentureBeat
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
AI agents breached 395 organizations using credentials your IAM policy still treats as human
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
AI is changing the economics of software supply chain attacks
AI governance is moving to runtime — and regulated industries are getting there first
Why AI shouldn't be the one repairing your data pipelines
TechCrunch
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Researchers used Anthropic’s Claude to hack into OpenAI
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
US military says it has launched weapons into space
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
New Italian unicorn Exein rides the physical AI wave
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Revolut confirms customer data breach through fake government requests
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
Network World Security
Huawei aims to deliver faster AI chips, faster
Practical quantum computers are over a decade away, says NEC
Local AI is getting small enough to make every app multilingual
The amount of e-waste caused by AI is underestimated: we can’t only include the servers
Cisco patches max-severity ISE flaw, the second critical zero-day this week
Riverbed bolsters network performance monitoring with agentic AI
Axelera Europa targets enterprise data centers with far more efficient AI
European cloud watchdog slams Broadcom over VMware licensing practices, issues warnings about SAP
Critical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco brings Splunk AI on premises, expands agent observability, monitors token costs
Help Net Security
Bots with good manners are better at fooling people on social media
Arcjet brings security controls and audit trails to AI agents
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Android apps can now check security patches down to individual device components
Abandoned IoT apps keep sending sensitive data to broken servers
Hardcoded MCP credentials found in public GitHub files
98% of fraudulent hires have company credentials by the time they’re caught
Most WordPress pros still lack a breach recovery plan
New infosec products of the week: September 18, 2026
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
SC Magazine
What model access failure costs the business
Spear Phishing: How the attack works and how to stop it
How to build an OT security operating model
What OT Resilience Actually Controls
The AI Security Control Problem: Why AI Requires a Different Security Discipline
New CISA-hosted VINCE-NT system revealed for coordinated vulnerability disclosure
Closing the AI control gap: From shadow AI to continuous protection
Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617
Congress pledges mental health support after Cyber Command suicides
AI reshapes exposure management around real-world risk, says Brinqa exec
© 2026 RiskDiscovery | Sponsored by:
Deception Logic