[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Critical Healthcare Systems Aren't Quantum-Ready
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Chinese Hackers Impersonate US Officials for AI Cyber Espionage
Need for Speed: AI-Driven Attacks Are Changing Security Strategies
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
Ars Technica
Hackers obtain counterfeit TLS certificates for Google and other large services
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
Licensing costs driving 90 percent of VMware users to explore options: Survey
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Apple changes full-disk access permissions to curb abuse from AI agents
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Memory executives expect RAM shortage to continue through 2028
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
CyberScoop
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
Wiretapping change sparks big privacy fight in the Golden State
Former NSA chief Nakasone says agency overhaul is ‘probably needed’
Here’s how experts think CISA should tell agencies to protect OT
Citrix discloses third actively exploited NetScaler zero-day in less than a week
The US needs a real plan to defend its water systems
The legal questions raised by agentic AI hacks
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
InfoSecurity Magazine
OT Coalition Urges CISA to Mandate Federal OT Security
Attackers Hide AI Prompt Injections Inside Phishing Emails
Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One
Danish CPR Breach Highlights Challenge of Supply Chain Risk
ClickFix Attack Hides VBScript Payload in Browser Cache
Nikkei Discloses Two Employee Cloud Account Compromises
Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities
Critical Medical Devices Unable to Support PQC Transition
SecurityWeek
Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform
Advantest Discloses Data Breach Months After Ransomware Attack
Chrome 155 Update Patches 247 Vulnerabilities
Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
ASOS Confirms Cyberattack, Data Breach
Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies
Android’s October 2026 Updates Patch 25 Vulnerabilities
Atlassian Patches Critical Vulnerability Affecting 8 Products
ZDNet
Use Gemini for free? You’ll soon be limited to its weakest AI model
Office 2021 support ends this month – you have 5 options
Mistral’s new Le Chonk model brings AI cybersecurity to your business – and you control it
How I made a paid Mac app in 11 days with Claude – without writing a single line of code
iPhone 18 Pro Max can’t call or text on AT&T? Apple will replace it for free
This new ChatGPT scam tricks you into installing malware – how to spot the trap
Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
The Hacker News
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
What Is Agentic Pentesting? What It Proves, and Where It Stops.
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
BleepingComputer
PoeLLM malware infects exposed AI servers in cryptomining attacks
Ransomware has a new target. Is your backup ready?
Hackers exploit critical Atlassian flaw after public PoC release
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
Musician sent to prison for $10 million streaming fraud using AI bots
Advantest confirms personal information stolen in ransomware attack
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Atlassian warns of critical file-access flaw in Jira, Confluence
ASOS confirms data breach after “HACKED” in-app notifications
gbhackers
EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Tax and Financial Data
Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands
Russian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure
FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials
Hackers Use ERP Web Shell and IDOR Flaws to Breach Major South Korean Churches
OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack
LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension
Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
Critical Veeam Backup & Replication Flaw Allows Low-Privileged Users to Execute Remote Code
Partisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks
Cybersecurity Dive
AI doesn’t change singular importance of phishing-resistant authentication, Okta says
FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users
IBM’s AI-powered vulnerability clearinghouse finds hundreds of Java flaws
US cyber resilience, oversight tested in series of attacks
Citrix issues patch for third exploited flaw in NetScaler
White House AI task force faces expertise, partnership challenges
Why permissions must be the foundation for next-gen identity security
Modernizing data security with DSPM, AI and fewer tools
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Fortinet warns that critical flaw in FortiMail is facing exploitation
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
South Korean president calls for creation of tools that stop all cyber-attacks
Anthropic reconfigures its cool kids security program
Trump Mobile customers' data dumped - and some never even received their gold device
Microsoft extends the Outlook naughty step with two more file types
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
Asos app delivers a data leak threat instead of fast fashion
Denmark's ID register spills more people's details than the country has residents
Legacy sign-on service comes back to bite school software provider Bromcom
Atlassian warns of critical file access flaw in its datacenter products
VentureBeat
Microsoft's record Patch Tuesday shows why severity can't decide what gets patched first
Your vibe-coded apps are a ticking time bomb for your business. Here’s how to secure them.
AI agents need more than access control — they need identity at runtime
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
TechCrunch
LibreOffice says ‘no AI’ is now a software feature
Hackers steal 8 million citizens’ records from Danish government database
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Federal judge calls Flock ‘indiscriminate mass surveillance’
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
OpenAI cuts ties with 3 safety researchers, WSJ reports
California governor vetoes bill banning use of ‘pervert glasses’ to secretly record people
Network World Security
AMD to ramp up CPU, GPU supply in 2027 as AI demand surges
Cisco readies new control plane for quantum networks
Google overhauls cloud modernization portfolio with new AI agents
GTT bets that the network, not the log file, is where AI-era security gets won
Micro data center company launches stackable data center for edge and AI
AWS seeks to automate cloud optimization with new AI agent
IBM expands mainframe networking options as AI reshapes enterprise infrastructure
New memory player CXMT begins mass production of DRAM platform
From automated response to reasoning: Building confidence in AI-driven NetOps
Startup doxx.net hands the network controls to AI
Help Net Security
Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
Gremlin Foresight AI finds system weaknesses and verifies the fixes
Imply Lumi connects SIEM tools and AI agents to more security data
FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
Vijil DART tests AI agents for security flaws and policy violations
Edgescan Atomic validates attack paths with controlled AI testing
Trustero automates vendor document reviews with human approval
Hoxhunt expands Respond to automate phishing investigations and email removal
Tanium adds endpoint behavior detection and AI-assisted threat hunting
Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
SC Magazine
Atlassian warns of critical arbitrary file access vulnerability in self-hosted products
Attackers hijack top-level domains to mint counterfeit TLS certificates
Hadrian Security raises $40 million to expand AI-powered penetration testing
FortiBleed campaign targets Fortinet devices, leading to ransomware
Bromcom notifies customers of personal data breach affecting SSO technology
Don’t think of readiness as just an onboarding problem
Former engineer sentenced for ransomware-style attack on employer
Former NSA director discusses agency reorganization amid evolving cyber threats
Cisco Talos warns of ClickFix attacks using trusted services
LibreOffice will not integrate AI features in the foreseeable future
© 2026 RiskDiscovery | Sponsored by:
Deception Logic