[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Angola's Largest Telco Breached Hours Before IPO
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
New Tool Traces AI Videos Back to Their Source
Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues
Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
Is There Really a Fix for CISO Fatigue?
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
Ars Technica
Claude published malicious code to the Internet and attacked 3 real companies
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
Sheetz is quitting VMware, migrating 11,000 virtual machines
CyberScoop
Open-source software’s archenemy TeamPCP goes back further than anyone thought
AI is getting better at election facts, but voters shouldn’t rely on it
National cyber director lays out White House plans to secure AI without writing new rules
AISI, OpenAI report more ‘unsanctioned’ model hacks
Massive supply-chain attack compromises 440 packages under four hours
Dem senators criticize Trump administration decisionmaking on AI security risks
Prolific ransomware group behind SonicWall zero-day attacks
Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming
Senate set to debate package of bills on privacy, AI and kids safety
How companies could share cyber risks without exposing their secrets
InfoSecurity Magazine
Fake Open VSX Extensions Harvest Private Repo and CI Data
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
Frontier Models Engage in Unsanctioned Behavior During Testing
Fake Bank of America Phishing Scam Installs Remote Access Malware
WhatsApp Scam Hijacks Accounts via Linked Devices Feature
Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions
Cloud and SaaS Environments Now Top Targets for Attackers
AI Accounts for Over Half of Cybercrime in Africa, Says Interpol
SecurityWeek
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
AI Agents Targeted Real People and Projects During Cybersecurity Tests
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
ZDNet
Hit by T-Mobile's outage? You can get up to $80 in credit - here's how
I ran a dumpstate analysis on my Android phone - 3 system diagnostics to check for free
Want a free Photoshop alternative on Linux? How to get Affinity today: 2 ways
You're charging your phone all wrong: 6 common myths, debunked
This free Windows 11 tool can rescue your PC when things go wrong - here's how
I've dictated over 120,000 words with my voice - these are my 3 favorite tools (and one is free)
Desktop Linux just cracked 10% market share - and Windows 11 is mostly to blame
The best 98-inch TVs of 2026: Expert tested
Need to run Windows or Android apps on Linux? This new release makes it easy
Marshall Stanmore IV vs. Sonos Era 300: I tested both to find the ultimate home speaker
The Hacker News
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
BleepingComputer
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
Google Blogger locks hundreds of blogs in malware false positive
How AI-powered phishing killed blocklists for good
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
New XCSSET variant targets macOS devs via compromised Xcode projects
77 Open VSX extensions found harvesting developer info
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Varonis Agent IBAC keeps AI agents within their intended boundaries
gbhackers
New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable
Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Microsoft Paid Record $20 Million in Bug Bounties to 562 Security Researchers Worldwide
OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Execute Code Remotely
Cybersecurity Dive
CISA is prioritizing work with critical infrastructure as it begins to recover from cuts
White House walks tightrope on securing AI without stifling tech innovation
Tech industry alliance proposes AI agent safety reporting program
AI widely used to exploit critical flaws, disrupt supply chains
AI makes costly spearphishing attacks easier, cyber insurer says
OT security coalition urges Congress, CISA to enact reforms amid water sector hacks
China-based hacker employs DeepSeek in autonomous threat campaign
How volunteer cyber experts are helping protect rural water systems
Anthropic says human error let Claude AI models escape test environment and hack third parties
US authorities see ‘significant escalation’ in attacks on water system devices
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
IBM's agentic AI platform is under active attack - patch now
London cops handed victim's new address and number to her stalker, watchdog says
UK charities count the cost of Beacon CRM cyberattack
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
Bypassing AI guardrails is so easy a script kiddie can do it
This one time, at Hacker Summer Camp …
Feds get 3 days to patch N-able God mode flaw under active exploit
AI helps Microsoft bug hunters chase a record $20M payday
Tennessee congressional hopeful accused of shooting license plate cameras
CAF Bank reopens online service but warns of further outages
VentureBeat
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
Mastercard spent decades training its fraud system to see bots as thieves. Now bots are the ones doing the buying.
Hush Security says the AI security problem has shifted from protecting models to governing identities as autonomous agents spread
The lineage behind 69% of open models was never verified. Cisco just fingerprinted almost 900 for free
NTT DATA AIVista and Snowflake: Identity alone won’t secure enterprise AI agents
Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
TechCrunch
PSA: Apple’s Private Relay can leak your real IP address
Android app developers may be unwittingly sharing their users’ location data with advertisers
Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress
Hackers steal over $130M by exploiting bug in offline hardware wallets
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
Apple challenges UK government’s latest demand for iCloud backdoor: report
Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate
Samsung bans smart TV apps that share users’ internet connections with strangers
CareCloud begins to notify hundreds of thousands after hackers stole medical records
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
Network World Security
Palo Alto Networks at Black Hat: How AI erased the 50-day patch window
2026 network outage report and internet health check
With FCC ban on new Chinese-made optical transceivers for DCs likely, it may be time to stock up
Nvidia moves to accelerate storage access, boost industry cooperation
Moo! LoRaWAN makes it easier to connect more things to the low power networking protocol—even cattle
Data center energy constraints and moratoriums are mounting. Expect to see stalled AI projects
Cisco exec testifies at US Senate panel on AI’s network impact
Nvidia’s next move? Financing AI
AMD unveils AI GPU to challenge Nvidia’s Rubin
Cato Networks launches agentic threat prevention
Help Net Security
Top product launches at Black Hat USA 2026
Stellar Cyber’s Auto-Triage AI matches human analysts 99.7% of the time
Tenable broadens AI visibility across major LLMs and AI tools
ArmorCode enhances attack path analysis with new AI agents and Context Risk Graph
Tuskira expands exposure management with Agentic Control Plane
Lumu launches live threat intelligence platform for real-time cyber defence
INTERPOL flags AI as the new engine of African cybercrime
AI agent deception moves from theory to reality in UK cyber tests
Code review used to be the only way to catch these bugs
15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
SC Magazine
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
Swiss Federal IT Agency FOITT compromised about 200 accounts due to SharePoint flaws
App SDKs may be sharing user location data with third parties by default
Cybercrime victims lose an average of $9,468, with global toll exceeding $1.24 trillion
77 malicious extensions found on Open VSX marketplace
TP-Link Omada ZTP systems vulnerable to fleet-wide compromise
CAF Bank online service restored after attempted fraud and login removal
Agentic AI and cybersecurity dominate discussions at Las Vegas Hacker Summer Camp
Apple restores Telegram after child abuse material ban; Gram token recovers
Senate committee to debate new online privacy and AI safety bills
© 2026 RiskDiscovery | Sponsored by:
Deception Logic