[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
25 Years After Code Red: What the Worm Era Can Teach Us About AI Security
CISOs Feel the Heat Over AI Risk
Attackers Combo Up Evasion Tactics for BEC Phishing
Cybersecurity Keeps Events 'Uneventful'
Inc Ransomware Exploits SonicWall SMA Zero-Days
The Real AI Threat Is Blind Trust
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
Ars Technica
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
Now, even Russia's most elite hackers are using Clickfix to infect devices
Energy IPOs surge as investors hunt for ways to play AI boom
Sheetz is quitting VMware, migrating 11,000 virtual machines
Windows 0-day drops the same day Microsoft releases record number of patches
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
The US government warns that Russia state hackers are coming after your router
Now, defenders are embracing the prompt injection, too
Patch for Windows Defender 0-day could allow attackers to fill hard disk
Allstate accuses Broadcom of auditing it because it quit VMware, CA
CyberScoop
What the World Cup can teach us about cybersecurity resilience
Director of Commerce AI standards office out after three months
Why blocking AI models won’t stop the cyber threats they create
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
Leading members of Scattered Spider sentenced in UK to 66 months in jail
Program to rotate cyber personnel through federal agencies saw little use
Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime
Security researchers find stalkers abusing Chrome’s sync feature
SonicWall customers under threat as attackers exploit 2 zero-days
Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
InfoSecurity Magazine
FBI Warns of Deepfake Videos Impersonating IC3 Leadership
US Hospital Finance Software Provider Craneware Reports Data Theft
Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros
Cruciferra Crypter Uses Process Ghosting to Evade Detection
JadePuffer Returns With Ransomware Designed to Wipe AI Models
Researchers Build WordPress Exploit Using OpenAI's GPT
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
Government Agencies Falling Victim to Ransomware Daily, Warns Study
23andMe Faces New Security Mandates in $18m Data Breach Settlement
SecurityWeek
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
Clover Health Investments Discloses Data Breach
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
Zimbra Update Patches Critical Vulnerabilities
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
ZDNet
I tested iOS 26 Siri against iOS 27 Siri AI in my car - and it wasn't even close
Best tablets for note-taking 2026: Expert tested and reviewed
T-Mobile will pay for your first month of 5G home internet, and give you up to $200 back - here's how
Fedora Xfce or Xubuntu: Which is the best Linux desktop?
I wore Meta's $499 prescription Ray-Bans for 6 weeks: They're stylish but not for me
Want to add Android Auto to your old car? Here are two ways - including one that's under $20
I tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this much security
The best rugged phones in 2026: Expert tested
An AI agent breached Hugging Face before an AI defender caught it: What users should do next
Why I still recommend Synology's DS225+ NAS - even if it can't replace your cloud storage
The Hacker News
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
N-day is Becoming N-Hour. Patching Faster Won't Save You.
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
BleepingComputer
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Microsoft shares manual fix for WSUS sync delays and timeouts
Windows LegacyHive zero-day flaw gets free, unofficial patches
Estée Lauder discloses data breach via Oracle E-Business flaw
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
JadePuffer agentic attacks now target AI model data with ransomware
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
gbhackers
2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Abbott Confirms Cyberattack After Unauthorized Access to Cancer Diagnostics Systems
Cybersecurity Dive
Researchers trace SonicWall SMA1000 exploitation to late June
Hackers steal customer data from major hospital software vendor
The secret problem in AI infrastructure: Why MCP security starts with secrets
How agentic endpoint security shuts down IDE-based supply chain attacks
Your attack surface is bigger than you think
Abbott discloses cyberattack on cancer diagnostics business
Ransomware attack forces Coca-Cola to suspend US production at dairy unit
Gaps in network security, oversight strategy hamper US’s aviation cybersecurity regulators
Iran-nexus actors using AI to enhance cyber playbook
CISA warns that multiple vulnerabilities in SharePoint are under exploitation
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy
Attackers pummel critical WordPress vuln to create all sorts of mischief
Scammers impersonate FBI on social media, prey on crime victims
Malicious cloud customers can bring down the power grid
Frontier LLMs couldn't help Hugging Face fight off evil agents
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Connecting AI agents to outside services explodes the risk radius
AI spam filters are getting suckered by old-school text salting
Attackers target critical FortiSandbox flaws as CISA issues patch order
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN
VentureBeat
Safety guardrails blocked Hugging Face's defenders, not the attacker, when an AI agent breached its systems
AI confidence just dropped 17 points in six months. That’s actually great news.
Capital One releases VulnHunter, an open-source AI tool that finds software flaws before hackers do
Zero trust must now move at agent speed
1Password moves into AI cost management, betting that token spend is the next enterprise budget crisis
Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools
Shared API keys expose AI agents at 69% of enterprises, new VentureBeat research finds
TechCrunch
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
The Zoom hack that says, ‘Don’t record me’
FBI arrests man accused of using Steam games to drain victims’ crypto wallets
Amazon fixing bug that billed some AWS customers billions of dollars
Coca-Cola suspended production at its Fairlife dairy after a ransomware attack
UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group
Period tracker Stardust shares users’ health data with analytics firm, says Mozilla research
Network World Security
Helios marks AMD’s biggest AI infrastructure push yet
Sheetz replaces VMware at more than 830 stores
AI workloads shake up observability market
New York State just hit pause on the AI data center boom
Huawei eying possible DRAM market entry
IBM targets AI edge with Power server, software upgrades
Network jobs watch: Hiring, skills and certification trends
Google Cloud configuration update disrupts VMware Engine stretched clusters
Fortinet adds AI protections to endpoint security platform
How data centers cope with heat waves
Help Net Security
Shufti simplifies cross-border compliance with the Glocal Platform
SonicWall SMA zero-days were exploited weeks before disclosure
Fake FBI agents target people who already got scammed
AWS wants GuardDuty to automate the first steps of threat investigations
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Open-source maintainers still work underfunded as sponsorship crosses $100 million
The air gap is a myth and other OT security truths
Nobody was checking the drives that encrypt your laptop
PR3TACK preemptive framework maps threats before attackers use them
AI agents are still logging in as humans
SC Magazine
7 mistakes companies make deploying AI agents
Bridging the divide: The convergence of AI and infosec
Guide helps organizations evaluate AI in security operations centers
LG monitors criticized for silently installing McAfee ads via Windows Update
Hugging Face uses GLM 5.2 to investigate AI agent-driven cyberattack
South Korea proposes new rules for seizing self-custody crypto wallets
HollowGraph malware uses Microsoft 365 calendar for command and control
Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts
Craneware confirms customer and employee data exposed in security incident
F5 fixes critical nginx vulnerability CVE-2026-42533
© 2026 RiskDiscovery | Sponsored by:
Deception Logic