darkreading
2 Separate Campaigns Probe Corporate LLMs for Secrets
2 weeks 2 days ago
A total of 91,403 sessions targeted public LLM endpoints to find leaks in organizations' use of AI and map an expanding attack surface.
Elizabeth Montalbano, Contributing Writer
Deepfake Fraud Tools Are Lagging Behind Expectations
2 weeks 5 days ago
Deepfakes are becoming more realistic and more popular. Luckily, defenders are still ahead in the arms race.
Nate Nelson, Contributing Writer
Illicit Crypto Economy Surges Amid Increased Nation-State Activity
2 weeks 5 days ago
Cybercriminal cryptocurrency transactions totaled billions in 2025, with activity from sanctioned countries like Russia and Iran causing the largest jump.
Robert Lemos, Contributing Writer
Russia’s Fancy Bear APT Doubles Down on Global Secrets Theft
2 weeks 5 days ago
The notorious state-sponsored group relies on basic techniques that are highly effective, often delivering greater ROI than more complex malware-heavy operations.
Nate Nelson, Contributing Writer
CrowdStrike to Buy SGNL to Expand Identity Security Capabilities
2 weeks 6 days ago
The CrowdStrike-SGNL deal underscores how identity security has become a critical component of enterprise cybersecurity as companies add cloud services and deploy AI-driven tools.
Fahmida Y. Rashid
Maximum Severity HPE OneView Flaw Exploited in the Wild
2 weeks 6 days ago
Exploitation of CVE-2025-37164 can enable remote code execution on HPE's IT infrastructure management platform, leading to devastating consequences.
Rob Wright
Fake AI Chrome Extensions Steal 900K Users' Data
2 weeks 6 days ago
Threat actors ripped off a legitimate AI-powered Chrome extension in order to harvest ChatGPT and DeepSeek data before sending it to a C2 server.
Alexander Culafi
ChatGPT's Memory Feature Supercharges Prompt Injection
2 weeks 6 days ago
The "ZombieAgent" exploit makes use of ChatGPT's long-term memory and advanced capabilities.
Nate Nelson, Contributing Writer
Here's What Cloud Security's Future Holds for the Year Ahead
2 weeks 6 days ago
Here are the top cloud security trends I'm seeing in my crystal ball for the New Year — particularly arming us for AI adoption.
Melinda Marks
Attackers Exploit Zero-Day in End-of-Life D-Link Routers
3 weeks ago
Hackers are attacking a critical zero-day flaw in unsupported D-Link DSL routers to run arbitrary commands.
Jai Vijayan, Contributing Writer
Phishers Exploit Office 365 Users Who Let Their Guard Down
3 weeks ago
Microsoft said that Office 365 tenants with weak configurations and who don't have strict anti-spoofing protection enabled are especially vulnerable.
Alexander Culafi
Cyberattacks Likely Part of Military Operation in Venezuela
3 weeks ago
Cyber's role in the US raid on Venezuela remains a question, though President Trump alluded to "certain expertise" in shutting down the power grid in Caracas.
Robert Lemos, Contributing Writer
DDoSia Powers Affiliate-Driven Hacktivist Attacks
3 weeks ago
Pro-Russian group NoName057(16) uses a custom denial-of-service tool to mobilize volunteers and disrupt government, media, and institutional sites tied to Ukraine and the West.
Jai Vijayan, Contributing Writer
Lack of MFA Is Common Thread in Vast Cloud Credential Heist
3 weeks ago
An emerging threat actor that goes by "Zestix" used an assortment of infostealers to obtain credentials and breach file-sharing instances of approximately 50 enterprises.
Elizabeth Montalbano, Contributing Writer
Scattered Lapsus$ Hunters Snared in Cyber Researcher Honeypot
3 weeks 1 day ago
Scattered Lapsus$ Hunters, also known as ShinyHunters, were drawn in using a realistic, yet mostly fake, dataset.
Alexander Culafi
ClickFix Campaign Serves Up Fake Blue Screen of Death
3 weeks 1 day ago
Threat actors are using the social engineering technique and a legitimate Microsoft tool to deploy the DCRat remote access Trojan against targets in the hospitality sector.
Elizabeth Montalbano, Contributing Writer
Startup Trends Shaking Up Browsers, SOC Automation, AppSec
3 weeks 2 days ago
These startups reimagined browser security, pioneered application security for AI-generated code, and are building consensus on agentic vs. human costs.
Paul Shomo
Advisor360 Gets a Handle on Shadow AI via Automation
3 weeks 2 days ago
With employees looking for the benefits of artificial intelligence, a fintech company stepped up controls with automation.
Mercedes Cardona
CISOs Face a Tighter Insurance Market in 2026
3 weeks 2 days ago
Insured entities are becoming more sophisticated in their views on how cyber policies fit into their broader risk management plans.
Ericka Chickowski, Contributing Writer
Checked
5 hours 4 minutes ago
Public RSS feed
darkreading feed