darkreading
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
6 hours 12 minutes ago
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
Jai Vijayan
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
7 hours 23 minutes ago
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions.
Rob Wright
CISOs Feel the Heat Over AI Risk
8 hours 43 minutes ago
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
Robert Lemos
Attackers Combo Up Evasion Tactics for BEC Phishing
9 hours 20 minutes ago
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
Elizabeth Montalbano
Cybersecurity Keeps Events 'Uneventful'
13 hours 50 minutes ago
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.
Olga Polishchuk
Inc Ransomware Exploits SonicWall SMA Zero-Days
3 days 7 hours ago
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.
Nate Nelson
The Real AI Threat Is Blind Trust
3 days 11 hours ago
AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.
R. Justin Martin
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
3 days 14 hours ago
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.
Alexander Culafi
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
3 days 16 hours ago
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks.
Jeffrey Schwartz
Agentic AI: Taming the Unpredictable
4 days 6 hours ago
Agentic artificial intelligence is creating enough risks for organizations to demand a security reframe.
Arielle Waldman
1M+ Emails Use Hidden Text to Dupe AI Security Filters
4 days 8 hours ago
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
Nate Nelson
Police Disrupt a €140M Cyber Fraud Ring in Spain
4 days 20 hours ago
Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.
Nate Nelson
Forgotten Bootloaders Expose Secure Boot Blind Spot
5 days 6 hours ago
Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.
Jai Vijayan
Identity Attacks Overtake Exploits as Top Ransomware Cause
5 days 7 hours ago
Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
Alexander Culafi
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
5 days 9 hours ago
We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity intelligence beyond North America.
Tara Seals
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
5 days 10 hours ago
The US government's restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant cyber implications.
Rob Wright
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
5 days 12 hours ago
When combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system.
Elizabeth Montalbano
2-Click Cursor Exploit Enables Dev Environment Takeover
5 days 14 hours ago
Simple age-old bugs give bad actors access to developers' secrets and source code-rich environments.
Nate Nelson
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
5 days 19 hours ago
The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.
Robert Lemos
Checked
5 hours 47 minutes ago
Public RSS feed
darkreading feed