[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Thanks for Crushing the Submissions Inbox. We're Trying to Keep Up
In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
EdTech Attackers Shift From Schools to Their Software Suppliers
Local Police Collusion Hampers Crackdown on Asian Scam Centers
Europe Evolves Into Ransomware's Favorite Region
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
2026 FIFA World Cup Faces Surge in Cyber Threats
Do CISOs Need a Code of Ethics?
More Malicious OpenClaw Skills Threaten AI Supply Chain
Ars Technica
Notion killing Skiff-influenced email app since most users use AI agents instead
One-two punch delivered in global operation disrupts cybercrime "assembly line"
White House drastically shortens deadline for dropping quantum-vulnerable crypto
Oracle’s 21,000 layoffs help drive its debt-fueled AI investments
Following user outcry, AMD reinstates memory encryption in consumer CPUs
Microsoft discovers new lightweight backdoor that steals cryptocurrency
Apple patches high-severity eavesdropping vulnerability in Beats Studio Buds
Before SpaceX IPO, investors in China secretly acquired stakes
Massive breach spills credentials for thousands of sensitive networks
Tesco moving 40,000 server workloads off VMware amid Broadcom's “abusive conduct”
CyberScoop
FCC passes new cybersecurity rules for emergency systems, undersea cables
Federal court rules Trump election-focused executive order illegal
Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract
Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack
Why patch directives only go so far
Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
In a first, a court takedown goes after two cybercrime tools at once
Open-source security is posing challenges governments can’t easily solve
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
Algerian man charged with running two cybercrime marketplaces
InfoSecurity Magazine
China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor
CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach
Cisco Vulnerability Exploited Months Before Disclosure, Google Warns
Twenty Million US IP Connections Used by Proxy Services
Trust in Automated AI Vulnerability Scanning Collapses to 9%, New Study Finds
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
macOS Flaw Lets Standard Users Disable EDR and MDM
Major Increase in Ransomware Attacks Targeting Europe, Warns New Report
Researchers Trick AI Browsers Into Leaking Credentials
Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers
SecurityWeek
Nebulock Raises $25 Million for AI-Native Contextual Security
Linux Foundation Unveils New Open Source Security Project Akrites
$3 Million Reportedly Stolen in Polymarket Hack
Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
New Enterprise-Ready MCP Specification Brings New Security Challenges
Philip Martin Joins Uber as Chief Information Security Officer
Runlayer Raises $30 Million in Series A Funding
Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack
Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
ZDNet
The best Prime Day tech deals under $100 that I'd actually buy
How to get free Windows 10 security patches until October 2027 - and avoid the $30 fee
Your last chance to get a MacBook Neo at $590 is here - Apple just raised its price
Windows 10 just very quietly got another year of free support - but why?
5 tech products that seriously impressed our experts - and are up to 50% off
5 weird Prime Day gadgets we've tested that you can buy right now
After years of using Android Auto, these are the 8 phone cooling tips I swear by
These 15+ award-winning gadgets are on sale for Prime Day - but we'd pay full price
I recommend this Sonos smart speaker to everyone I know - get it while it's $40 off for Prime Day
5 gadgets that helped declutter my desk (and why they're worth every penny)
The Hacker News
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
Guardian Agents: The Next Layer of Identity Governance
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
BleepingComputer
Anthropic is testing desktop-like Claude Cowork for mobile
Poland busts SIM-swapping gang tied to millions in crypto theft
Order-tracking app Shop abused to push callback phishing attacks
Microsoft quietly extends free Windows 10 ESU support to October 2027
New macOS malware embeds fake errors to confuse AI analysis tools
PirloTV sports piracy network disrupted as 44 domains seized
Bluekit phishing kit adopts browser-in-the-middle for login theft
The Four Elevations of Effective Fraud Prevention
Webinar: Why account takeovers remain one of the hardest threats to stop
Google releases new privacy controls for activity history, personalization
gbhackers
Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks
FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE
Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader
Scammers Abuse Shopify to Send Fake Invoices and Steal Credentials via Fake Support Calls
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone
KuinaExtractor Stealer Targets Browser Data, Crypto Wallets, Roblox, Steam, and Discord
WhatsApp Adds Security Warning Before Users Start Chat With Unknown Numbers
Chinese-Speaking Hackers Deploy TinyRCT Backdoor Against Critical Energy Infrastructure
ChatGPT 5.6 Release Reportedly Delayed Following Trump Administration Security Request
Cybersecurity Dive
NIST offers security guidance for water utilities using remote-access tools
As cyber risk continues to evolve, the insurance industry tightens its guardrails
Microsoft, Europol lead global takedown of infostealer malware
Ransomware attacks grew in 2025 as traditional data breaches fell
White House’s state infrastructure cybersecurity initiative stalled
Trump sets new deadlines for agencies and contractors to adopt post-quantum cryptography
Klue investigating supply chain attack that targeted Salesforce integrations
Looming AI-fueled threats require urgent cybersecurity improvements, Five Eyes members say
Interpol, Europol renew agreement to combat hackers and other criminals
CISA urges device hardening after thousands of Fortinet credentials compromised
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Security boss thought MFA would be too much security
Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
UK school’s network left wide open for invasion, student found
Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’
The hits keep on coming for Cisco vulnerabilities
Microsoft uses AI to link two malware operations in racketeering suit
London cops bring live facial recognition to West End
VentureBeat
Visa will offer an inside look at Project Glasswing and how the most powerful agentic models are changing enterprise security at VB Transform 2026
7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes
Copilot searched your mailbox. LiteLLM handed out admin keys. Run this 5-check audit before your stack is next
85% of IT teams claim every AI agent is under control. Only 42% actually know who owns them.
Attackers scale deception with AI. Defenders need truth at machine speed.
NanoClaw and JFrog launch 'immune system' to block AI agents from downloading malicious code
Meta's AI support agent bound recovery emails for anyone who asked. Your SOC never saw an alert.
TechCrunch
Polymarket says hackers stole users’ funds
Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats
Cellebrite said it cut off Russia, but Russia used its tools anyway
New website names and shames companies that still don’t offer passkeys to users
Klue says hackers stole credential from 2022 that led to customer data breaches
Password manager maker LastPass says hackers stole customer support case data during Klue breach
Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach
A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak
Anthropic says Claude may want to see your ID
Klue hack results in data breach at several cybersecurity firms
Network World Security
Researchers cast new doubt on Microsoft’s quantum computing advance
IBM unveils sub-1 nanometer chip with nearly 100 billion transistors
Qualcomm’s $3.9 billion purchase of Modular aims to change the data center dynamic
IBM, Red Hat, Palo Alto team to secure open-source software
Break legacy lock-in: Strategic options for enterprises facing the vSphere 8 deadline
Attackers exploit Cisco Unified CM flaw weeks after patch release
Upscale AI readies Skyhammer scale-up networking tech, raises new funding
Rami Rahim’s message for network pros: Legacy networks can’t withstand rigors of AI
2026 network outage report and internet health check
China’s LineShine dethrones El Capitan as the world’s fastest supercomputer
Help Net Security
Proof’s x401 establishes an open protocol for AI agent identity and authorization
Critical open-source projects get a new security framework
Synology issues critical fix for MailPlus Server vulnerabilities
Ransomware gangs find Europe’s weakest link in third-party suppliers
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Mystery hackers use novel SharkLoader dropper against governments, software devs
SIM-swapping gang busted in international police operation
ZeroTier Quantum RC2 brings post-quantum security closer to general availability
ThreatModeler introduces Nexus to automate threat modeling with AI governance
Microsoft gives Windows 10 users an unexpected extra year of free security updates
SC Magazine
How to stop treating OEM software like a security liability
New ‘Blacksite’ phishing kit bundles AiTM with scanner evasion
Microsoft extends free Windows 10 security updates for consumers
Model Context Protocol overhaul introduces new security challenges for developers
Cloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #932
Sports piracy ring linked to PirloTV disrupted in 44-domain takedown
BreachRx launches AI incident command center to handle multiple simultaneous attacks
Russia reportedly hacked dissident's phone with Cellebrite tools after company cut ties
Incode acquires Identiq, invests $100 million in privacy-preserving identity infrastructure
China's 360 Security Technology unveils AI models for vulnerability discovery
© 2026 RiskDiscovery | Sponsored by:
Deception Logic