[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
The Morning After We Pull a Root of Trust, Nobody Owns It
Interpol Leverages Global System to Curtail Fraud Payments
DROP Platform Lets Californians Reduce Digital Footprint
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
AI Harnesses Burst With Potential Exploit Opps
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
SE Asian Cybercriminal Syndicates Become a Global Power
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
Ars Technica
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
We now have a better understanding how OpenAI hacked into Hugging Face
Microsoft unveils AI security tools it says outperform competing platforms
TreeSize won't renew perpetual-license support unless users subscribe
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
Sheetz is quitting VMware, migrating 11,000 virtual machines
Windows 0-day drops the same day Microsoft releases record number of patches
CyberScoop
What the Hugging Face breach reveals about defense in the age of agentic AI
Anthropic says its AI accidentally hacked three companies during safety tests
Okta’s deal for Permiso aims to close gaps in identity threat detection
CISA issues recommendations to federal agencies on open-source software security
We know how to protect our troops from telecom attacks. We’re just not doing it.
Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims
A little-known npm package was North Korea’s warm-up act for the axios hack
Supply chain challenges loom large in quantum race, White House official says
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems
InfoSecurity Magazine
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AI and Automation Fall Short of Sysadmin Expectations
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Google Releases Patches for 370 Vulnerabilities in Chrome 151
NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
SecurityWeek
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
Critical Flaw Allowed to Azure Cosmos DB Pwnage
CareCloud Data Breach Impacts Over 350,000
Critical Code Execution Vulnerability Patched in TeamCity
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
Bank of America to Acquire Cybersecurity Firm MDSec
ZDNet
Did a OneDrive Photos app just appear on your PC? Here's what it does (and how to get rid of it)
Amazon is splitting its $600 million tariff refund with customers - here's who's eligible
How to keep your AI conversations as private as possible
Not just OpenAI - Anthropic says Claude's hacking spree 'falls short of ideal behavior'
How OpenAI's agent escaped: Sprung by humans in a series of preventable events
LinkedIn's new 'Seems like AI slop' button lets you report all those cringey posts
Looking for a new budget phone? This Motorola model is just $100, but only for a limited time
The best laptop cooling pads of 2026: Expert tested
Data Byte: This router's signal strength beat most competitors in our lab test
I installed these smart window shades in 10 minutes - now I want them all over my house
The Hacker News
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
BleepingComputer
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
CISA warns of cyberattacks disrupting U.S. water utilities
ESET tracks rise in malicious AI skills and adaptable malware
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
South Korea fines telco giant KT $39 million for customer data breach
JetBrains warns of critical TeamCity remote code execution flaw
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
VMware fixes three critical flaws allowing auth bypass, VM escapes
Google says AI helped Chrome fix 1,072 security bugs in two releases
gbhackers
Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins
Ransomware Killers Overwrite Security Process Memory Without Terminating Applications
Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution
Google Uses AI to Fix 1,072 Chrome Security Vulnerabilities
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
Critical Adobe Campaign Flaw Lets Attackers Execute Arbitrary Code
Critical SolarWinds Web Help Desk Flaw Lets Attackers Bypass SAML Authentication
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks
Cybersecurity Dive
Anthropic says human error let Claude AI models escape test environment and hack third parties
Hackers abuse Microsoft Teams in ransomware campaign through fake IT support
Shadow AI, leadership resistance make AI governance tough for worried CISOs
As data breaches grow costlier, ungoverned AI creates new risks
Authorities investigating a coordinated cyberattack against Minnesota water systems
Microsoft launches agentic security platform designed to combat AI-based attacks
Companies fear AI risks more than common cybersecurity threats
Coca-Cola restores most production capacity at dairy unit after ransomware attack
Tech industry giants say US must embrace openness, transparency in AI
In the Mythos era, security belongs at runtime
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
The most famous brand in physical security got pwned by ShinyHunters
Anthropic and OpenAI are competing to see whose agents can go rogue harder
Charities remain locked out of CAF Bank online accounts
Anthropic’s Claude escaped test sandbox to attack three organizations
Jailed Flock vandal wipes out three cameras, racks up thousands in damages
Russian spies take their half-click email attack from Zimbra to Outlook
Headteacher had the most guessable username-password combo you could imagine
Excuses like 'AI did it' don't exist in the eyes of the law
Closed models refuse to help researcher swat Linux bug
Word worm crawls into Copilot, spreads chaos
VentureBeat
Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
Mastercard spent decades training its fraud system to see bots as thieves. Now bots are the ones doing the buying.
Hush Security says the AI security problem has shifted from protecting models to governing identities as autonomous agents spread
The lineage behind 69% of open models was never verified. Cisco just fingerprinted almost 900 for free
NTT DATA AIVista and Snowflake: Identity alone won’t secure enterprise AI agents
Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
Snowflake launches Cortex AI Gateway to control AI agents and prevent runaway enterprise costs
TechCrunch
CareCloud begins to notify hundreds of thousands after hackers stole medical records
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
Okta buys AI security startup Permiso — source says for about $200M
In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap
US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
PSA: Your Claude shared chats and Artifacts may have ended up on Google
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
Network World Security
Groundcover raises $100M as observability pivots from monitoring to AI infrastructure
From dangling DNS records to reverse DNS gaps, attackers find new blind spots
Data center developer eyes disused newpaper printing plant
Broadcom patches vulnerabilities all over VMware
Microsoft doubles down on multi-model AI as it builds a Copilot super app
How Port Nelson overhauled its operations with private 5G
Most corporate IT is off premises. Data center costs, staffing remain difficult, Uptime reports
CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks
Dell, Nutanix combo expands virtualization, private cloud choices
IBM: AI-driven attacks increased 56% last year, and data breach costs are up 12%
Help Net Security
Cybercrime goes subscription: AI, malware and infrastructure on demand
Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
Anthropic’s Claude breached three companies during security tests
Traefik Labs introduces Distro Zero secure runtime for API and AI gateways
Horizon3.ai expands NodeZero with automated web application attack path testing
AttackIQ targets CTEM execution with AVA Agentic OS
Resecurity expands threat intelligence integration ecosystem with IBM QRadar
Aviation cyber risk sits on the ground, the blindness sits in the air
Companies push AI, sysadmins keep it on a short leash
AI agents are changing where cybersecurity seed funding lands
SC Magazine
Unspecified threat actors targeting US water systems, CISA warns
Non-human identity (NHI) programs stall on detection, not policy
What we learned about zero-trust from the OpenAI breach of HuggingFace
AiTM phishing overtakes credential theft as top threat to law firms
KT Corporation fined $39 million for 11-month data breach
Cryptomining campaign avoids root access to evade detection
Amazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire Sleet
Precision privilege containment: Eliminating local admin rights without disrupting productivity
Okta to acquire identity threat detection startup Permiso Security
UK Department for Education confirms data breach affecting over 600,000 records
© 2026 RiskDiscovery | Sponsored by:
Deception Logic