darkreading
'Djinn' Stealer Targets Cloud, AI Credentials
13 hours 55 minutes ago
The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.
Jai Vijayan
Vulnerabilities Expose Private Data in Indian Government Systems
14 hours 18 minutes ago
One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal.
Nate Nelson
Can Clothes Make You Invisible to Facial Recognition?
15 hours 46 minutes ago
Does life feel Orwellian sometimes? One researcher has a solution for you: graphic tees that confuse the neural networks in surveillance cameras.
Nate Nelson
Iran, Russia, China Target Water Systems for Sabotage
16 hours 12 minutes ago
Nation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation — not sophisticated malware.
Alexander Culafi
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
23 hours 39 minutes ago
Adversaries could plant a malicious repository that can execute arbitrary code and steal cloud credentials by exploiting the vulnerability, which showcases growing MCP risk.
Elizabeth Montalbano
Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk
2 days 23 hours ago
Rising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks.
Bree Fowler
AI Decline? Confidence in Autonomous Penetration Testing Falls
3 days 16 hours ago
Companies are still experimenting with automated AI systems to find security weaknesses, but fewer are relying on the technology.
Robert Lemos
Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions
3 days 17 hours ago
Cisco joins a growing list of security platform providers that are betting that securing the agentic workforce means turning identity into the primary control plane.
Jeffrey Schwartz
New Initiative Tackles Security for End-of-Life Open Source Software
3 days 18 hours ago
The Open Source Sustainability Initiative's goal is to help enterprises manage and secure aging open source projects while maintaining regulatory compliance.
Arielle Waldman
AI Won't Wipe-Out Entry-Level Cybersecurity Jobs
3 days 19 hours ago
Instead of eliminating jobs for early-career cyber pros, AI is creating new opportunities for candidates with strong human decision-making skills.
Jon France
Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex
3 days 21 hours ago
Getting accurate visibility into IT and OT systems will be compounded by multivendor environments, misaligned update life cycles, and interoperability gaps.
Alexander Culafi
Thanks for Crushing the Submissions Inbox. We're Trying to Keep Up
3 days 22 hours ago
It might be taking a bit longer than usual to respond to your submissions — here's why.
Becky Bracken
Name That Toon Contest
4 days ago
Robinhood Cuts Access Approval Time to Support High-Velocity Development
4 days 12 hours ago
The fintech company's engineering-first application security team reengineered the process for granting system access, making it easier and more secure for developers working on their projects. Here are the lessons learned from Robinhood's experience.
Ericka Chickowski
In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
4 days 13 hours ago
The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments.
Jai Vijayan
Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
4 days 14 hours ago
The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers.
Nate Nelson
EdTech Attackers Shift From Schools to Their Software Suppliers
4 days 14 hours ago
Educational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters' Notebook video series.
Arielle Waldman
Local Police Collusion Hampers Crackdown on Asian Scam Centers
4 days 16 hours ago
With tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement efforts.
Robert Lemos
Europe Evolves Into Ransomware's Favorite Region
5 days 1 hour ago
After a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers.
Nate Nelson
Checked
6 hours 19 minutes ago
Public RSS feed
darkreading feed