[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
Cisco Zero-Day Highlights API Endpoint Authentication Issues
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
MFA Won't Save You From OAuth Consent Abuse
AI Agent Breaches Spanish Organization, Modifies Personal Data
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
China's FamousSparrow APT Spies on US Politics in Latin America
AI Security Spending Jumps as Fear Outpaces Proof of Value
Fighting Your Dragons Through Tough Tech Times
Ars Technica
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
CyberScoop
Researchers use AI to find widespread software decoder flaw
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
Cisco alerts customers to second actively exploited zero-day in as many days
The AI hacking apocalypse is not inevitable
Authorities seize popular, long-running DDoS-for-hire service domains
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
Treasury’s Scott Bessent says no liability exemptions for AI labs
What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
InfoSecurity Magazine
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
CISA Upgrades Vulnerability Reporting Platform with More Automation
Manufacturing Accounts for 22% of all Ransomware Victims
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Cyber Essentials Has Record Year but Takeup Remains Low
Cisco Warns of Active Exploitation of Critical ISE Flaw
AI Agent Carries Out Multi-Stage Data Theft Attack
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
SecurityWeek
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
23 Million User Records Compromised in Gyazo Data Breach
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
NightmareStresser DDoS Service Disrupted in International Operation
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Critical Orkes Conductor Vulnerability Exploited in Attacks
MIND Secures $72 Million for AI-Powered DLP
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
ZDNet
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
Roku rolls out over 30 subscription bundles for up to 30% off, plus a new Labs feature
Claude Code’s revised projects adds AI orchestration, but local developers must wait
Bose returns with new open earbuds (and a refreshed favorite)
I recommend you don’t run these appliances on your power station – even if you can
Anthropic merges Claude chat and Cowork into one
How September’s Pixel Drop changes the way you call and message important contacts
I’ve used both iPhone 18 Pro models – here’s how my buying advice is changing in 2026
Windows 11 out-of-band update fixes audio glitch and other bugs – grab it now
The Hacker News
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
BleepingComputer
Gyazo server flaw exploited to steal 23.6 million user records
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft Teams will let admins block custom file extensions
Webinar: Which Google Workspace security controls actually matter?
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
New Check Point flaw lets hackers execute code with root privileges
Microsoft fixes broken copy and paste for Excel 2016 users
New RatHat Android malware uses AI to automate device control
OpenAI details more cases of AI agents taking unauthorized actions
gbhackers
PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
Cybersecurity Dive
Settra ransomware variant deployed in recent attacks
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
Manufacturers make patching progress, but identity management still major weakness
Hackers exploit zero-day flaw in Cisco email gateway
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
AI is now leading driver of new cybersecurity spending
Companies’ AI strategies don’t account for agentic tools
Security teams increasingly outflanked by AI agents
Malicious actors already using critical GitLab flaw, CISA and others warn
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
North Korea's fake job interviews infected 30,000 devices
FBI: Fake cop and government impersonation scams cost victims $1.6B
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
Researchers find way to listen in on headphones from afar
China's Salt Typhoon backdoors Latin American orgs with new snooping malware
London property manager breach may have exposed bank details and lockbox codes
Cisco drops another exploited zero-day, this time a perfect 10
Test environment let anyone access live customer data
VentureBeat
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
AI agents breached 395 organizations using credentials your IAM policy still treats as human
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
AI is changing the economics of software supply chain attacks
AI governance is moving to runtime — and regulated industries are getting there first
Why AI shouldn't be the one repairing your data pipelines
TechCrunch
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Researchers used Anthropic’s Claude to hack into OpenAI
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
US military says it has launched weapons into space
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
New Italian unicorn Exein rides the physical AI wave
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Revolut confirms customer data breach through fake government requests
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
Network World Security
Huawei aims to deliver faster AI chips, faster
Practical quantum computers are over a decade away, says NEC
Local AI is getting small enough to make every app multilingual
The amount of e-waste caused by AI is underestimated: we can’t only include the servers
Cisco patches max-severity ISE flaw, the second critical zero-day this week
Riverbed bolsters network performance monitoring with agentic AI
Axelera Europa targets enterprise data centers with far more efficient AI
European cloud watchdog slams Broadcom over VMware licensing practices, issues warnings about SAP
Critical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco brings Splunk AI on premises, expands agent observability, monitors token costs
Help Net Security
Bots with good manners are better at fooling people on social media
Arcjet brings security controls and audit trails to AI agents
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Android apps can now check security patches down to individual device components
Abandoned IoT apps keep sending sensitive data to broken servers
Hardcoded MCP credentials found in public GitHub files
98% of fraudulent hires have company credentials by the time they’re caught
Most WordPress pros still lack a breach recovery plan
New infosec products of the week: September 18, 2026
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
SC Magazine
Closing the AI control gap: From shadow AI to continuous protection
Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617
Congress pledges mental health support after Cyber Command suicides
AI reshapes exposure management around real-world risk, says Brinqa exec
How teams can patch faster when a bug gets added to CISA's KEV
Settra ransomware group uses MeshAgent RMM in recent attacks
From autonomous agent to trusted worker: Building identity and accountability for AI agents
AI hates CAPTCHAs - PSW #944
Cisco patches 10.0 ISE bug exploited in the wild
Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment - Rob Sadowski - BH26 #3
© 2026 RiskDiscovery | Sponsored by:
Deception Logic