[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
Why the CISO-CFO Relationship Is a Key to Cybersecurity Success
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
What We Missed: Google Gemini Joins the AI Escape Party
Stopping IT Worker Scams Requires Revamped HR Process
Russia's Hybrid Cyber-Physical War in Europe Heats Up
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
SectopRAT Returns, Hiding Inside a Legitimate Application
3 Cyber Threats That Defined the Summer of 2026
Ars Technica
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
There's a new way to break RSA that's faster than anything we've seen before
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
CyberScoop
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
New bill would create federal investigative body for AI-driven hacks
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
How tax policy can stop threat actors from breaching US water systems
CISA outlines improvement plan for CVE program
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
InfoSecurity Magazine
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach
NVIDIA Launches Open Platform to Secure Autonomous AI Agents
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns
MCP Is Creating Major Governance Gaps, Researchers Warn
Citrix Patches Critical Zero Days Under Active Exploitation
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
CISA Unveils Election Security Plan Ahead of 2026 Midterms
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
Researchers Identify AliExpress Phishing Domains Before Registration
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
SecurityWeek
Call for Presentations Open for 2026 CISO Forum Virtual Summit
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
DC Health Agency Exposes 400,000 Beneficiary Records
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
ZDNet
Bose’s new wired earbuds aim for the same great sound and ANC – no charging needed
Your Bose headphones are getting a major Bluetooth upgrade – what to expect
This one WatchOS 27 feature just solved my biggest issue with Apple Watch
Your LG TV is constantly collecting your data – here’s how to stop it
Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’
Google Wallet got a lot of new tricks in 2026 – these 5 are my favorites
Microsoft’s Surface Mouse is back, now with haptic feedback – and I need it
AI agent kill switch urged by Okta-led alliance – how businesses could make it work
Is your Apple Watch 12 or Ultra 4 randomly restarting? Here’s the fix
How to fix your Windows File History if the September update broke it
The Hacker News
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Zero Trust for AI Agents Starts With Fixing Zero Visibility
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
BleepingComputer
JadePuffer agentic AI attacks target Azure, destroy cloud resources
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
CISA orders feds to patch exploited Citrix flaws by Wednesday
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
gbhackers
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI Agents
Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
670 Jev Domains Registered After Launch as Fake AI Marketplaces Target Users
Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords
Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
12 Best Cloud Encryption Solutions Compared (2026): Features & Pricing
Cybersecurity Dive
Kiteworks lifts advisory after precautionary warning for customers to shut down systems
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
Niche AI tools pose major cybersecurity risk to infrastructure operators
Your attack surface is bigger than you think… and hackers know that
Security testing has to keep pace with AI-driven attackers
Context matters when it comes to cybersecurity’s agentic operating model
Businesses expand AI’s cybersecurity uses as comfort with technology grows
Threat groups ramp up social-engineering attacks against healthcare sector
Wiz uses AI to find vulnerabilities in critical infrastructure
Rogue OpenAI agent targeted Australian government site
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Ex-soldier's telecom hacking spree earns him 70 months
Certainties in life: Death, taxes, and critical Citrix vulns under attack
OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought
Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
Crooks use fake desktop apps to fool HR staff into giving them remote access
Bitget blames North Korea for $387.5M crypto wallet raid
Which copy of that file is the real one? Dinner, off the record, in Midtown
Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
VentureBeat
AI agents are exposing a security gap between the data they read and the systems they can change
AI agents have routed around access blocks. Only 9% of companies in VentureBeat's August survey isolate high-risk agents
Monorepos make coding agents more useful — but compromised accounts are harder to contain
AI coding tools are accelerating dependency sprawl and expanding malware risk with it
AI has created a new identity problem. Agentic IAM is how we solve it.
Meta patched Muse’s zero-day, but security teams still lack visibility into what the agent can access
Companies are putting Jev in charge of AI agent decisions — and prompt injection can influence the verdict
TechCrunch
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
Some Supabase customers are publicly exposing reams of people’s data to the web
Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
North Korean hackers suspected in $351M crypto theft, the largest so far this year
Australia to investigate if OpenAI hack of government health website broke the law
What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
LinkedIn adds new tools to fight fake profiles and bogus work histories
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
Stolen passwords are exposing America’s water providers to hackers
Google’s Gemini is the latest AI model to hack other companies
Network World Security
NetScaler admins told to patch critical zero-days in ADC and Gateway now
Tackling the three hidden mistakes when planning a GCC
Rewiring global capability centers for the AI era
Google’s first prototype satellite is going up, kicking off its space-based data center project
Can Nvidia’s GeForce gaming GPU really be repurposed for AI computing?
Meta floats project to lay first petabit submarine fiberoptic cable
IP Fabric 8.1 adds application-aware mapping and cloud-native data model
On-prem VeloCloud Orchestrator under attack, only some versions patched
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Selector brings Git-based workflows and incident replay to network AI agents
Help Net Security
FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data
Other users can watch your browsing and time your keystrokes through OS file notifications
NVIDIA wants AI agent safety enforced in silicon, not left to the agent
“Drunk” AI is terrible at keeping secrets
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts
LinkedIn tests a way for connections to verify your work history
If you do one security check this quarter, make it agent memory
Authorizer: Open-source authentication and authorization for your apps
SC Magazine
Multi-factor authentication: implementation, gaps, and abuse resistance
How cross-account trust creates exploitable privilege boundaries
Passwordless authentication: passkeys, FIDO2, and WebAuthn
What Security Leaders Need to Know About the New Ransomware Economics
Why XACML Still Matters: The Fine-Grained Authorization Problem Most IAM Programs Haven't Solved
Companies have to rethink how they budget security
How to build a non-human identity governance program
SPIFFE and SPIRE: workload identity for cloud-native environments
SAML assertion forgery: how the attack works and how to stop it
Why identity, not the network, has to be the perimeter
© 2026 RiskDiscovery | Sponsored by:
Deception Logic