[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Relays Are Masking Chinese Access to Frontier AI Models in the US
How the CISO-CMO Alliance Builds Trust Before Crisis Strikes
Microsoft Disrupts EvilTokens Device Code Phishing Service
Deception by Design: CISA's Guide to Tricking Cybercriminals
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Ars Technica
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
CyberScoop
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Pentagon cyber chief: The demand far exceeds supply
Ryuk ransomware operator sentenced to 2 years in prison
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
The president has called for AI leadership. Here’s the mission.
ShinyHunters claims attack on FBI exposes almost all agents
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Citing China, President Trump doubles down on hands-off approach to AI regulation
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
InfoSecurity Magazine
Hundreds of Leaked GitHub App Keys Still Authenticate
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
Ransomware Attacks Reach Record High for 2026
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds
Network Segmentation Failures Are Expanding the Corporate Attack Surface
AI Drives Surge in Bot and API Threats
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
SecurityWeek
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Adobe Patches Critical Flaws in Connect, AEM Forms
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Chrome 154 Patches 108 Vulnerabilities
A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
ZDNet
How to fix your Windows File History if the September update broke it
Nearly 70% of workers use AI regularly now – but many get no time to upskill
Claude Opus 5.5 delivers Fable 5.1 performance – and costs 40% less
Claim up to $95 today from Apple’s Siri AI settlement – here’s how
The AI models that cheat the most, according to new CAIS benchmark
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
Roku rolls out over 30 subscription bundles for up to 30% off, plus a new Labs feature
Claude Code’s revised projects adds AI orchestration, but local developers must wait
Bose returns with new open earbuds (and a refreshed favorite)
The Hacker News
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
BleepingComputer
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Hackers start exploiting critical WordPress flaw for code execution
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
InfraTrust report warns network management systems under attack
How One Kubernetes YAML Can Hand Over a GCP Organization
Arista patches actively exploited VeloCloud Orchestrator zero-day
Microsoft: September Windows updates break Always On VPN connections
Ryuk ransomware member sentenced to 24 months in prison
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
Rogue external MFA providers can steal passwords during logins
gbhackers
Fake Crypto Wallet App Delivers PamStealer Malware That Hijacks Mac Credentials
Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites
HPE Networking Analytics Engine Flaws Let Attackers Gain Root Access
Cybercriminals Abandon Domains but Keep the Hosting Networks Behind Malware Campaigns
SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts
Graphalgo Malware Uses Malicious Terraform Providers and Go Modules to Deploy RAT
NVIDIA Infrastructure Controller Hit by 14 Flaws Enabling Code Execution and Privilege Escalation
ManageEngine RCE Flaw Enables SYSTEM Code Execution From Windows Login Screen
Critical WordPress Flaw Lets Unauthenticated Attackers Execute Remote Code
Cybersecurity Dive
FBI probes cyberattack tied to third-party jobs portal
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries
Industrial leaders face cyber resilience gap as attacks shake confidence
Insurance sector begins to offer clarity on AI-related cyber claims
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Google AI models broke out of sandbox, hacked three companies
More CVEs than ever. The same old ones keep getting exploited.
Security’s 30-year habit: layering around the problem
Settra ransomware variant deployed in recent attacks
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Closing the observability gap for the AI-ready enterprise
British regulator takes a hard look at Pornhub's Apple-powered age checks
Why security belongs in the network
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
Z.ai says sorry for slurping up your code, open sources ZCode
Who signed off on that AI agent? Nobody? Thought so.
VentureBeat
AI has created a new identity problem. Agentic IAM is how we solve it.
Meta patched Muse’s zero-day, but security teams still lack visibility into what the agent can access
Companies are putting Jev in charge of AI agent decisions — and prompt injection can influence the verdict
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
AI agents breached 395 organizations using credentials your IAM policy still treats as human
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
TechCrunch
What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
LinkedIn adds new tools to fight fake profiles and bogus work histories
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
Stolen passwords are exposing America’s water providers to hackers
Google’s Gemini is the latest AI model to hack other companies
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Researchers used Anthropic’s Claude to hack into OpenAI
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
US military says it has launched weapons into space
Network World Security
Selector brings Git-based workflows and incident replay to network AI agents
80% of network pros are OK with giving AI an autonomous role in network operations
Inside Buffalo’s Highmark Stadium: How the Bills and Cisco built one network to run an entire venue, and what IT leaders can learn from it
9 career-boosting Wi-Fi certifications
Lenovo expands virtualization portfolio for AI
2026 network outage report and internet health check
California joins US states clamping down on data center gold rush
Huawei aims to deliver faster AI chips, faster
Practical quantum computers are over a decade away, says NEC
Local AI is getting small enough to make every app multilingual
Help Net Security
Cofense measures employee readiness against real-world phishing threats
80,000 relay servers help users in China slip past U.S. AI region bans
Portnox detects and removes unauthorized AI applications from managed devices
Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure
DarkMe RAT trades zero-days for plain phishing emails
Barracuda brings AI security and governance within reach of smaller organizations
Lookout targets smishing, voice cloning, and vishing with real-time mobile protection
Fake Claude Max giveaway tricks users into handing over their Google account credentials
Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
GPT-6 Sol and Luna arrive with 50% lower API prices
SC Magazine
The government must designate AI as critical infrastructure sooner rather than later
FBI probes ShinyHunters claims of massive agent data theft
First ‘autonomous AI C2 implant’ uses panel of models to vote on next task
Balancing AI Benefits and Risks as Your Next CISO Could be Artificial Intelligence - Evan McHenry - BSW #466
BigCommerce merchants impacted by third-party app data breach
VA criticizes Baylor Genetics for delayed notification after data breach
Amazon blocks Meta's Muse AI agent from its marketplace
TASK#STOMP campaign uses PowerShell backdoor for data theft
BYD Shark 6 remotely hacked, exposing vehicle controls and cabin audio
US jails adopt continuous biometric monitoring amid data privacy concerns
© 2026 RiskDiscovery | Sponsored by:
Deception Logic