darkreading
Please support the site operations by clicking ads.
[Virtual Event] Building a Secure AI Strategy for the Enterprise
4 weeks hence
Mythos Vulnerability Firehose Hits a Human Bottleneck
15 hours 19 minutes ago
An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.
Jai Vijayan
US Government Accuses Chinese AI Firms of Distilling Frontier Models
16 hours 51 minutes ago
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
Alexander Culafi
Identity-Based AI Attack Threatens Security of Enterprise Data
21 hours 59 minutes ago
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
Elizabeth Montalbano
Patch Tuesday Sets Another Record With 974 CVEs
1 day 15 hours ago
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
Jai Vijayan
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
1 day 15 hours ago
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Alexander Culafi
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
1 day 16 hours ago
Researchers and OpenAI disagree on whether the earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Nate Nelson
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
1 day 19 hours ago
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Elizabeth Montalbano
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
2 days ago
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Robert Lemos
Companies Have 6 Months to Prepare for Automated Attacks
5 days 20 hours ago
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
Robert Lemos
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
5 days 23 hours ago
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Alexander Culafi
Insurers Search for Answers to Rein in Rogue AI
6 days ago
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Robert Lemos
Large Enterprises Targeted in Fake Merger & Acquisition Scams
6 days 16 hours ago
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Nate Nelson
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
6 days 16 hours ago
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
Rob Wright, Alexander Culafi
What the AI Warning Letter Completely Missed
6 days 19 hours ago
The recent open letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
James Lyne
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
6 days 22 hours ago
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
Elizabeth Montalbano
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
1 week ago
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
Nate Nelson
AI's Vulnerability Surge May Be More Manageable Than First Feared
1 week ago
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Jai Vijayan
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
1 week ago
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Alexander Culafi
Checked
7 hours 34 minutes ago
Public RSS feed
darkreading feed