darkreading
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
21 hours 5 minutes ago
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
Jai Vijayan
AI Harnesses Burst With Potential Exploit Opps
22 hours 41 minutes ago
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
Robert Lemos
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
1 day 2 hours ago
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
Alexander Culafi
SE Asian Cybercriminal Syndicates Become a Global Power
1 day 17 hours ago
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
Robert Lemos
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
1 day 17 hours ago
A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.
Nate Nelson
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
1 day 22 hours ago
OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.
Alexander Culafi
Red Agents vs. Blue Agents: How to Make AI Better at Defense
1 day 22 hours ago
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
Rob Wright
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
2 days ago
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
Fahmida Y. Rashid
Hugging Face Hack: Lessons for Cyber Defenders
2 days ago
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
Dark Reading Editorial Team
When AppSec Scanners Become a Supply Chain Attack Vector
2 days 1 hour ago
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
Ericka Chickowski
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
2 days 3 hours ago
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
Elizabeth Montalbano
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
2 days 20 hours ago
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.
Jeffrey Schwartz
Thousands of Data Center Controllers Open to Takeover
2 days 21 hours ago
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
Jai Vijayan
When AI Agents Escape Sandboxes, Old Security Rules Apply
2 days 21 hours ago
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
Alexander Culafi
Stronger AI Safety Requires Peeking Inside the 'Black Box'
2 days 22 hours ago
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
Robert Lemos
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
3 days 1 hour ago
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
Elizabeth Montalbano
Former Citigroup CISO Blauner on What Makes A Great Security Leader
3 days 5 hours ago
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
Kristina Beek
AI Agent Drives Espionage Attack on Thai Ministry of Finance
3 days 17 hours ago
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
Alexander Culafi
Agentic Browsers Rewind Web Security by 20 Years
3 days 20 hours ago
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.
Ericka Chickowski
Checked
18 hours 30 minutes ago
Public RSS feed
darkreading feed