[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
AI-Generated Patches Fail Half the Time
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride
Researcher Claims Control of ChatGPT Secure Sandbox
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
AI Sends Global Crime Syndicates Into Fraud Nirvana
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
No Perfect Fix for AI Browser Prompt Injection Flaws
CSS: The Hidden Threat Lurking in Your Inbox
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Ars Technica
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Claude published malicious code to the Internet and attacked 3 real companies
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
CyberScoop
UK man tied to The Com sentenced for abusing 117 victims
Why transparent AI agents matter more than you think
More than half of AI-generated patches are broken
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
Ransom Cartel creator sentenced to 16 years in prison
The water sector just got it’s wake-up call. Again.
Snowflake hacker pleads guilty, faces up to 32 years in prison
Tom Cotton prods Treasury for tax code tweaks to modernize OT
InfoSecurity Magazine
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
WordPress Plugins Compromised Without a Single File Change
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
Go-Based macOS Malware Steals Crypto and Secrets
US Sanctions Iranian $6bn Crypto “Exchange” Shelbit
Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Google Links Redact Extortion Group to BlackFile Rebrand
Ransomware Surges in July After Q2 Lull
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
TeamPCP Traced Back to 2020 Cryptojacking Operation
SecurityWeek
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Metabase Patches Vulnerability Exploited as Zero-Day
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
Corporate Data Stolen in Levi Strauss Cyberattack
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
ZDNet
I tried a solar-powered AirTag alternative that lasts 2 years - and looks like my Apple Watch
This Mac dock gives me lag-free dual displays with no sketchy drivers - for $150
We lab-tested Ecovac's next-gen robot mop - here's where it shines (and struggles)
Claude's Record-a-Skill cut my research from hours to 30 minutes - but the magic has limits
Made by Google 2026: How to watch and what to expect from the Pixel 11 event
This 6-port USB-C charger replaced my ugly power brick - and powers my entire desk
I was loyal to T-Mobile for 10 years, but switching to Mint slashed my bill - by a lot
Samsung Galaxy Watch 9 review: Health data overload, but built for the future
This Bluetooth-only Marshall home speaker sounds so good, I can forgive the missing Wi-Fi
Your phone doesn't block SIM swapping attacks by default: Turn on these carrier settings now
The Hacker News
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
BleepingComputer
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
When Credentials Are No Longer Enough: Device Trust in the AI Era
Member of The Com sent to prison for blackmail, sextortion
LexisNexis shuts down services after suspicious activity on servers
Valve notifies Steam hardware customers of a data breach
Critical Progress LoadMaster flaw now actively exploited in attacks
Hackers breach TrueConf to trojanize client installers with backdoors
Metabase SQLi zero-day exploited in customer data-theft attacks
Unlimited Technology Systems breach impacts 3.8 million people
Levi Strauss & Co. says hackers stole corporate data in cyberattack
gbhackers
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware
HP ThinPro TPM Flaw Lets Attackers Bypass Full Disk Encryption and Steal LUKS Keys
Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
WordPress Supply Chain Attack Exploits BdThemes Plugins to Create Rogue Admin Accounts and Install Webshells
Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected
Apple Private Cloud Compute Path Traversal Flaw Lets Attackers Write Files as Root
Cybersecurity Dive
Civil-society initiative will pay cybersecurity vendors to protect rural water systems
Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’
Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Hackers grow more willing to destroy, not just disrupt, OT systems
OpenAI warns autonomous hacks are ‘watershed moment for computer security’
Western government leaders call for a focus on infrastructure resilience, not AI hype
CISA is prioritizing work with critical infrastructure as it begins to recover from cuts
White House walks tightrope on securing AI without stifling tech innovation
Tech industry alliance proposes AI agent safety reporting program
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Attackers pick Levi's pockets in social engineering attack
Wetherspoons bars smart glasses from filming customers
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
Framework loses customer data in Metabase zero-day attack
Claude Code puts auto mode in the driver's seat
Advertisers are trying to influence AI bots with secret ads
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
OpenAI pledges to add Astra security as Anthropic loosens Fable's leash
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
VentureBeat
AI agents are part of your team now. Here’s how to secure all of them.
The browser is where attacks land. Why is security still focused on the endpoint?
Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
Mastercard spent decades training its fraud system to see bots as thieves. Now bots are the ones doing the buying.
Hush Security says the AI security problem has shifted from protecting models to governing identities as autonomous agents spread
TechCrunch
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Signed up for Klaviyo? Dozens of advertisers may have seen your password
The AI safety test is becoming a safety risk
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you
Google’s top hacker hunter explains why hacking groups get codenames
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Computer maker Framework notifies ‘all customers’ of a data breach
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
Google says hackers are calling financial firm employees to hack and extort victims
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
Network World Security
Samsung offers future AI memory roadmap
Polish data center plans to send its waste heat to the neighbors
AMD to buy Taalas, maker of model-specific AI chips for enterprise inference
Agentic AI could force a rethink of enterprise AI server design, researchers say
NatJack exploits put NAT security assumptions to the test at Black Hat
Top network and data center events of 2026
AWS targets AI cost concerns with new Marketplace Insights tool
Arista hits first $3B quarter as AI networking demand continues and supply pressures show signs of improvement
Palo Alto Networks at Black Hat: How AI erased the 50-day patch window
2026 network outage report and internet health check
Help Net Security
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Metabase zero-day exploited to access Framework customer data
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
Anthropic to put AI in charge of reviewing Claude Code actions by default
OpenAI locks down Astra over potential critical cyber capabilities
GitHub Dependabot malware alerts now cover eight ecosystems
Chainloop: Open-source evidence store and policy engine for the software supply chain
Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
71% of CISOs spend 10+ hours on board reports
SC Magazine
Talk to the LLM: How AI exposes 'pig butchering' scams
Three interviews: system fragility, operational clarity, and Identity for AI agents - Robin Macfarlane, Kyle Sandy, Todd Thiemann - ESW #471
Black Hat: AI isn't the problem. We are
Bugcrowd's Braden Russell on launching Pathseeker
Forcepoint's Ronan Murphy on securing the data layer AI just set on fire
Fortra's Josh Davies on the evolving exploitation of trust
Keyfactor's Ellen Boehm on enterprise AI at scale
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605
Vishing group UNC6671 now focuses on extorting M&A firms
Researchers bypass Spectre v2 mitigations
© 2026 RiskDiscovery | Sponsored by:
Deception Logic