darkreading
Please support the site operations by clicking ads.
[Virtual Event] Building a Secure AI Strategy for the Enterprise
3 weeks hence
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
1 day 17 hours ago
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
Jai Vijayan
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
1 day 19 hours ago
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
Rob Wright
Anthropic CEO: Time to Shift From Improving to Controlling AI
1 day 22 hours ago
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
Elizabeth Montalbano
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
4 days 20 hours ago
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
Nate Nelson
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
4 days 20 hours ago
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
Arielle Waldman
SpiderSilk Hunts External Threats With AI-Based Scanner
4 days 20 hours ago
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.
Agam Shah
Why AI Is So Good at Scamming Humans
4 days 21 hours ago
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
AI Governance Can't Wait
4 days 22 hours ago
Adversaries can manipulate AI defensive reasoning to silently compromise target networks.
Tony Anscombe
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
4 days 23 hours ago
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
Robert Lemos
Indonesia Hit by Android Banking App-Cloning Campaign
5 days 14 hours ago
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
Alexander Culafi
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
5 days 18 hours ago
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
Nate Nelson
Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
5 days 23 hours ago
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
Elizabeth Montalbano
EU Cyber Resilience Act to Enforce New Reporting Requirements
6 days 8 hours ago
Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.
Nate Nelson
Mythos Vulnerability Firehose Hits a Human Bottleneck
6 days 18 hours ago
An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.
Jai Vijayan
US Government Accuses Chinese AI Firms of Distilling Frontier Models
6 days 19 hours ago
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
Alexander Culafi
Identity-Based AI Attack Threatens Security of Enterprise Data
1 week ago
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
Elizabeth Montalbano
Patch Tuesday Sets Another Record With 974 CVEs
1 week ago
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
Jai Vijayan
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
1 week ago
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Alexander Culafi
Checked
1 day 1 hour ago
Public RSS feed
darkreading feed