darkreading
Please support the site operations by clicking ads.
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
1 month 2 weeks ago
A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
Nate Nelson
The Morning After We Pull a Root of Trust, Nobody Owns It
1 month 2 weeks ago
The most valuable move any security team can make is building a certificate and key inventory.
Rajeev Mohindra
Interpol Leverages Global System to Curtail Fraud Payments
1 month 2 weeks ago
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
Robert Lemos
DROP Platform Lets Californians Reduce Digital Footprint
1 month 2 weeks ago
Hundreds of thousands of California residents have already registered for the Delete Request and Opt-out Platform (DROP), which launches Aug. 1. Other states could follow if the process goes smoothly.
Arielle Waldman
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
1 month 2 weeks ago
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.
Alexander Culafi
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
1 month 2 weeks ago
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
Jai Vijayan
AI Harnesses Burst With Potential Exploit Opps
1 month 2 weeks ago
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
Robert Lemos
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
1 month 2 weeks ago
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
Alexander Culafi
SE Asian Cybercriminal Syndicates Become a Global Power
1 month 2 weeks ago
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
Robert Lemos
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
1 month 2 weeks ago
A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.
Nate Nelson
Cybersecurity, Then & Now
1 month 2 weeks ago
Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.
Kelly Jackson Higgins
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
1 month 2 weeks ago
OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.
Alexander Culafi
Red Agents vs. Blue Agents: How to Make AI Better at Defense
1 month 2 weeks ago
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
Rob Wright
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
1 month 2 weeks ago
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
Fahmida Y. Rashid
Hugging Face Hack: Lessons for Cyber Defenders
1 month 2 weeks ago
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
Dark Reading Editorial Team
When AppSec Scanners Become a Supply Chain Attack Vector
1 month 2 weeks ago
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
Ericka Chickowski
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
1 month 2 weeks ago
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
Elizabeth Montalbano
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
1 month 2 weeks ago
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.
Jeffrey Schwartz
Thousands of Data Center Controllers Open to Takeover
1 month 2 weeks ago
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
Jai Vijayan
Checked
22 minutes 47 seconds ago
Public RSS feed
darkreading feed