darkreading
Secure Your Spot at RSAC 2026 Conference
1 month 2 weeks hence
Ransomware Gang Goes Full 'Godfather' With Cartel
7 hours 45 minutes ago
Since its launch in 2023, DragonForce has pushed a cartel model, emphasizing cooperation and coordination among ransomware gangs.
Jai Vijayan, Contributing Writer
CISA Makes Unpublicized Ransomware Updates to KEV Catalog
8 hours 11 minutes ago
A third of the "flipped" CVEs affected network edge devices, leading one researcher to conclude, "Ransomware operators are building playbooks around your perimeter."
Rob Wright
Attackers Use Windows Screensavers to Drop Malware, RMM Tools
8 hours 53 minutes ago
By tapping the unusual .scr file type, attackers leverage "executables that don't always receive executable-level controls," one researcher noted.
Alexander Culafi
Extra Extra! Announcing DR Global Latin America
16 hours 30 minutes ago
Dark Reading has something new hitting the newsstand: a content section purpose-built for Latin American readers, featuring news, analysis, features, and multimedia.
Tara Seals
Big Breach or Smooth Sailing? Mexican Gov't Faces Leak Allegations
17 hours ago
A hacktivist group claims a 2.3-terabyte data breach exposes the information of 36 million Mexicans, but no sensitive accounts are at risk, says government.
Robert Lemos, Contributing Writer
Google Looker Bugs Allow Cross-Tenant RCE, Data Exfil
19 hours ago
Attackers could even have used one vulnerable Lookout user to gain access to other GCP tenants' environments.
Nate Nelson, Contributing Writer
Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days
1 day 8 hours ago
APT28's attacks rely on specially crafted Microsoft Rich Text Format (RTF) documents to kick off a multistage infection chain to deliver malicious payloads.
Jai Vijayan, Contributing Writer
GlassWorm Malware Returns to Shatter Developer Ecosystems
1 day 9 hours ago
The self-replicating malware has poisoned a fresh set of Open VSX software components, leaving potential downstream victims with infostealer infections.
Alexander Culafi
AI May Supplant Pen Testers, But Oversight & Trust Are Not There Yet
1 day 11 hours ago
Crowdsourced bug bounties and pen-testing firms see AI agents stealing the low-hanging vulnerabilities from their human counterparts. Oversight remains key.
Robert Lemos, Contributing Writer
8-Minute Access: AI Accelerates Breach of AWS Environment
1 day 13 hours ago
The AI-assisted attack, which started with exposed credentials from public S3 buckets, rapidly achieved administrative privilges.
Elizabeth Montalbano, Contributing Writer
Dark Patterns Undermine Security, One Click at a Time
1 day 13 hours ago
People trust organizations to do the right thing, but some websites and apps have user interfaces that ultimately lead to inadequate security.
Arielle Waldman
Attackers Harvest Dropbox Logins Via Fake PDF Lures
2 days 7 hours ago
A malware-free phishing campaign targets corporate inboxes and asks employees to view "request orders," ultimately leading to Dropbox credential theft.
Alexander Culafi
County Pays $600K to Wrongfully Jailed Pen Testers
2 days 8 hours ago
Iowa police arrested two penetration testers in 2019 for doing their jobs, highlighting the risk to security professionals in red teaming exercises.
Nate Nelson, Contributing Writer
Chinese Hackers Hijack Notepad++ Updates for 6 Months
2 days 10 hours ago
State-sponsored threat actors compromised the popular code editor's hosting provider to redirect targeted users to malicious downloads.
Jai Vijayan, Contributing Writer
ShinyHunters Expands Scope of SaaS Extortion Attacks
2 days 13 hours ago
Following their attacks on Salesforce instances last year, members of the cybercrime group have broadened their targeting and gotten more aggressive with extortion tactics.
Elizabeth Montalbano, Contributing Writer
Torq Moves SOCs Beyond SOAR With AI-Powered Hyper Automation
5 days 7 hours ago
Investors poured $140 million into Torq's Series D Round, raising the startup's valuation to $1.2 billion, to bring AI-based "hyper automation" to SOCs.
Jeffrey Schwartz
2026: The Year Agentic AI Becomes the Attack-Surface Poster Child
5 days 8 hours ago
Dark Reading asked readers whether agentic AI attacks, advanced deepfake threats, board recognition of cyber as a top priority, or password-less technology adoption would be most likely to become a trending reality for 2026.
Tara Seals
Out-of-the-Box Expectations for 2026 Reveal a Grab Bag of Risk
5 days 8 hours ago
Security teams need to be thinking about this list of emerging cybersecurity realities to avoid rolling the dice on enterprise security risks (and opportunities).
Tara Seals
Checked
3 hours 58 minutes ago
Public RSS feed
darkreading feed