darkreading
Interpol Arrests Over 1K Cybercriminals in 'Operation Serengeti 2.0'
12 hours 10 minutes ago
The operation disrupted countless scams, and authorities seized a significant amount of evidence and recovered nearly $100 million in lost funds.
Kristina Beek
Apple Patches Zero-Day Flaw Used in 'Sophisticated' Attack
15 hours 5 minutes ago
CVE-2025-43300 is the latest zero-day bug used in cyberattacks against "targeted individuals," which could signify spyware or nation-state hacking.
Rob Wright
The Growing Challenge of AI Agent and NHI Management
15 hours 13 minutes ago
The growing ecosystem of agents, chatbots, and machine credentials that outnumber human users by an order of magnitude is creating a poorly understood but potentially major security issue.
Michael Morgenstern
Insurers May Limit Payments in Cases of Unpatched CVEs
15 hours 43 minutes ago
Some insurers look to limit payouts to companies that don't remediate serious vulnerabilities in a timely manner. Unsurprisingly, most companies don't like those restrictions.
Robert Lemos, Contributing Writer
Do Claude Code Security Reviews Pass the Vibe Check?
16 hours 8 minutes ago
AI-assisted security reviews from Anthropic and others could help level up enterprise application security in the era of vibe coding.
Ericka Chickowski, Contributing Writer
Personal Liability, Security Becomes Bigger Issues for CISOs
17 hours 14 minutes ago
While the furor from CISO prosecutions has died down, worries continue over a lack of liability protections and potential targeting by cybercriminals and hackers for their privileged roles.
Robert Lemos, Contributing Writer
System Shocks? EV Smart Charging Tech Poses Cyber-Risks
1 day 8 hours ago
Trend Micro's Salvatore Gariuolo talks with the Black Hat USA 2025 News Desk about how the new ISO 15118 standard for electric vehicle smart charging and vehicle-to-grid communications can be weaponized by threat actors.
Rob Wright
Scattered Spider Member Sentenced to a Decade in Prison
1 day 8 hours ago
Noah Michael Urban, 20, was one of several members of the Scattered Spider collective who were arrested and charged in 2024 in connection with high-profile cyberattacks.
Kristina Beek
Easy ChatGPT Downgrade Attack Undermines GPT-5 Security
1 day 8 hours ago
By using brief, plain clues in their prompts that are likely to influence the app to query older models, a user can downgrade ChatGPT for malicious ends.
Nate Nelson, Contributing Writer
Why Video Game Anti-Cheat Systems Are a Cybersecurity Goldmine
1 day 8 hours ago
Sam Collins and Marius Muench of the University of Birmingham, UK, join the Black Hat USA 2025 News Desk to explain how anti-cheat systems in video games provide valuable lessons on defending against threat actors' techniques and strategies.
Rob Wright
How Architectural Controls Help Can Fill the AI Security Gap
1 day 10 hours ago
NCC Group's David Brauchler III shares how foundational controls and threat modeling strategies can help secure agentic AI tools in ways traditional guardrails can't.
Alexander Culafi
Hackers Abuse VPS Infrastructure for Stealth, Speed
1 day 11 hours ago
New research highlights how threat actors abuse legitimate virtual private server offerings in order to spin up infrastructure cheaply, quietly, and fast.
Alexander Culafi
K-12 School Incident Response Plans Fall Short
1 day 12 hours ago
Quick recovery relies on three security measures.
Arielle Waldman
Tree of AST: A Bug-Hunting Framework Powered by LLMs
1 day 12 hours ago
Teenaged security researchers Sasha Zyuzin and Ruikai Peng discuss how their new vulnerability discovery framework leverages LLMs to address limitations of the past.
Alexander Culafi
Prepping the Front Line for MFA Social Engineering Attacks
1 day 15 hours ago
Attackers will continue to evolve, and the help desk will always be a target. But with the right mix of training, support, and trust, frontline agents can become your biggest security assets.
Paul Underwood
Tailing Hackers, Columbia University Uses Logging to Improve Security
1 day 15 hours ago
Logging netflows provided valuable insight about attacker tactics during a breach by state-sponsored hackers targeting Columbia's research labs.
Mercedes Cardona
DARPA: Closing the Open Source Security Gap With AI
1 day 16 hours ago
DARPA's Kathleen Fisher discusses the AI Cyber Challenge at DEF CON 33, and the results that proved how automation can help patch vulnerabilities at scale.
Alexander Culafi
Hacktivist Tied to Multiple Cyber Groups Sentenced to Jail
1 day 23 hours ago
At one point, Al-Tahery Al-Mashriky was hacking thousands of websites within the span of three months while stealing personal data and sensitive information.
Kristina Beek
DPRK, China Suspected in South Korean Embassy Attacks
2 days 4 hours ago
Detailed spear-phishing emails sent to European government entities in Seoul are being tied to North Korea, China, or both.
Nate Nelson, Contributing Writer
Checked
9 hours 13 minutes ago
Public RSS feed
darkreading feed