darkreading
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month 1 week hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
5 days 21 hours hence
Alleged KillSec Ransomware Mastermind a 16-Year-Old
19 hours 48 minutes ago
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
Jai Vijayan
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
1 day 4 hours ago
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
Nate Nelson
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
1 day 20 hours ago
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
Alexander Culafi
Trump, Tech Giants Strike Voluntary AI Safety Accord
1 day 20 hours ago
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.
Jai Vijayan
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
1 day 22 hours ago
New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
2 days 2 hours ago
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
Elizabeth Montalbano
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
2 days 10 hours ago
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
Robert Lemos
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
2 days 19 hours ago
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
Jai Vijayan
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
2 days 20 hours ago
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
Alexander Culafi
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
3 days ago
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
'NeedyMantis' Provides Long-Term Access to Compromised Networks
3 days 2 hours ago
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
Elizabeth Montalbano
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
3 days 3 hours ago
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
Rob Wright
Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities
3 days 19 hours ago
The Open Agent Safety Platform relies on hardware and software components to monitor agent activities and quarantine unruly agents before they can cause harm.
Agam Shah
One Packet Can Crash OT Servers in Industrial Sectors
3 days 20 hours ago
A high-severity vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments, and orgs should patch right away.
Jai Vijayan
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
3 days 21 hours ago
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
Alexander Culafi
AI Agents Are Privileged Users; Who Is Auditing Their Access?
3 days 22 hours ago
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.
Ravi Sharma
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
4 days ago
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.
Nate Nelson
Checked
8 hours 21 minutes ago
Public RSS feed
darkreading feed