[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
EU Cyber Resilience Act to Enforce New Reporting Requirements
Mythos Vulnerability Firehose Hits a Human Bottleneck
US Government Accuses Chinese AI Firms of Distilling Frontier Models
Identity-Based AI Attack Threatens Security of Enterprise Data
Patch Tuesday Sets Another Record With 974 CVEs
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Ars Technica
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent
I rented a car, and within hours, my driver's license was for sale
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Think twice before installing this device promising free movies
CyberScoop
Conti ransomware crew member sentenced to four years in prison
Hawley probes OpenAI over Hugging Face breach
AI lets small actors run state-level hacking campaigns, Anthropic report finds
Governments ‘buying time’ in race between innovation, security, national cyber director says
Chinese espionage groups swarm to exploit triple-link chain of zero-days
FTC rescinds policy requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
FBI cyber chief worries private sector not sharing enough cyber threat information
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
InfoSecurity Magazine
CISA Updates Insider Threat Guide With New Mitigation Advice
MantaxOtax Android Malware Combines Ransomware With Spyware
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
Anthropic Reveals Yet Another Cybersecurity Incident
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Gigabud Uses Android App Cloning to Evade Fraud Detection
ClickFix Moves into the Browser to Steal Cryptocurrency
NHIs Now the Number One Corporate Entry Point for Hackers
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
SecurityWeek
Mandiant Founder Kevin Mandia Joins Amazon Board
Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
Anthropic Researcher Resigns With Warning About the Dangers of AI Development
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation
Critical NetScaler Vulnerability Exploited in Attacks
Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
4.1 Million Impacted by AdaptHealth Data Breach
Organizations Warned of Cisco Secure FMC Exploitation
ZDNet
The Hacker News
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
BleepingComputer
New Android malware encrypts files, steals data, and harasses victims
September Windows Server updates break Remote Desktop Services
Surfshark VPN says hackers breached internal testing, proxy servers
Microsoft Excel KB5002914 update breaks copy and paste for some users
AI-powered attack exploited PaperCut flaws to hack 395 organizations
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
IDScan confirms breach tied to 153 million stolen driver’s licenses
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
Microsoft says September updates fix mouse settings reset issues
gbhackers
OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
OpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits
Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
Cybersecurity Dive
Threat groups enhance cyberattack capabilities with AI
CISA is on the verge of filling hundreds of critical vacancies
White House sees water cybersecurity partnership in Texas as national blueprint
How AI anxieties dominated the summer’s big cybersecurity conference
CISOs are feeling the security burden of accelerated AI use
New FBI cyber strategy promises increase in adversary disruptions
N-able issues patch for zero-day flaw
Don’t let AI distract from cybersecurity basics, officials and executives warn
Essential AI agent security questions
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
ShinyHunters expose 6.4M in attack on medical supplier McKesson
Dental contractor set up secret account with access to 4,000 patient records then left the company
Anthropic reveals fourth likely crime committed by its AI
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Serial Microsoft 0-day hunter drops yet another Defender exploit
WeChat worm could pwn a friend before they even answered the call
Microsoft breaks Patch Tuesday record with 974-CVE deluge
VentureBeat
Anthropic's safety monitor missed a live cyberattack because Mythos 5's reasoning said everything was fine
Agents identifying as OpenAI systems wrote 17,000 posts to a wiki no one was supposed to write to
Most security teams don't know how many AI agents they're running. Falcon Guardian found 18,000 at one company that had approved only 300.
MCP's new spec turns a planted prompt into a stolen credential
China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using
Google’s Gemini 3.8 Flash is built for agents, while its Cyber twin hunts vulnerabilities
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
TechCrunch
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
A hacker stole $340M in a crypto heist, then returned most of it
OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure
US military disabled ad tracking on troops’ devices following reports of targeted attacks
Abliteration.ai is making a business out of removing AI guardrails
It sure looks like hackers breached a major ID card verification service
Network World Security
Nvidia invests $3.5B in MediaTek to extend its grip on AI
MikroTik patches flaws currently being exploited to take over routers
Leap second proposal will keep software stacks in sync
Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
BackBox brings AI to network automation but keeps humans in control
2026 network outage report and internet health check
AI data boom fuels tape storage resurgence
Nvidia lets you build your own AI clusters locally with PAIR software
When analyst benchmarks miss the mark: Why Nvidia doesn’t fit Forrester’s data center matrix
HPE’s record Q3: AI infrastructure, networking demands drive growth, but supply constraints tap the brakes
Help Net Security
Your passkeys can now move between password managers on Android
Attackers call employees’ personal phones to break into Microsoft 365 accounts
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
Scytale expands vendor risk management with AI-powered TPRM tools
WordPress adds automated security checks to block risky plugin releases
Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Apple is building photo verification for the people who need it most
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Cybercriminals are building phishing pages that exist only inside victims’ browsers
AI adoption brings new security headaches for already stretched CISOs
SC Magazine
It's More Secure When It's Disabled - PSW #943
When English becomes exploit code: The hidden risk inside MCP servers
CISA: WatchGuard Firebox bug exploited in ransomware campaigns
A security framework for coding agents and their harnesses
What CIO-CISO alignment looks like when it's working
A credo for the AI era: Trust, but Decompile
PaperCut MF/NG flaws attacked with hundreds of AI agents
Skullcandy Dime 3 earbuds vulnerable to Bluetooth hijacking
Gigabud banking trojan uses app cloning to evade fraud detection
Over 36,000 Plex media servers remain unpatched against security vulnerabilities
© 2026 RiskDiscovery | Sponsored by:
Deception Logic