;
;

darkreading

Public RSS feed

Patch Tuesday Sets Another Record With 974 CVEs

Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
Posted on 8 September 2026 | 9:26 pm

Attackers Use Multi-Hop Google Redirects for Phishing Campaign

Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Posted on 8 September 2026 | 9:03 pm

OpenAI Agents Took Over Wiki Site Before Hugging Face Attack

Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.
Posted on 8 September 2026 | 8:36 pm

ClickFix Campaigns Abuse Legitimate Services for Persistent Access

Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Posted on 8 September 2026 | 5:25 pm

Companies Have 6 Months to Prepare for Automated Attacks

Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the sit...
Posted on 4 September 2026 | 3:57 pm

AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?

A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Posted on 4 September 2026 | 1:00 pm

Insurers Search for Answers to Rein in Rogue AI

As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Posted on 4 September 2026 | 12:15 pm

Large Enterprises Targeted in Fake Merger & Acquisition Scams

Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large ...
Posted on 3 September 2026 | 8:18 pm

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters...
Posted on 3 September 2026 | 7:42 pm

What the AI Warning Letter Completely Missed

The recent AI warning letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
Posted on 3 September 2026 | 5:23 pm

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to res...
Posted on 3 September 2026 | 2:38 pm

'Breeze Comet' Tears Into Brazilian & Global Financial Systems

Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
Posted on 3 September 2026 | 12:00 pm

AI's Vulnerability Surge May Be More Manageable Than First Feared

New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Posted on 2 September 2026 | 9:14 pm

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Posted on 2 September 2026 | 8:43 pm

AI Gives Cybercriminals a Dangerous Time Advantage

Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Posted on 2 September 2026 | 7:46 pm

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take ov...
Posted on 2 September 2026 | 4:51 pm

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and...
Posted on 2 September 2026 | 1:00 am

Attackers Pounce on Critical Artifactory Bug Following Disclosure

CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
Posted on 1 September 2026 | 9:05 pm

Stronger Security Drives Ransomware Groups to Recruit From Within

Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost compa...
Posted on 1 September 2026 | 9:03 pm

Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adve...
Posted on 1 September 2026 | 8:48 pm

AI Model Evaluator METR Hit by Credential Theft, Probing

In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonpro...
Posted on 1 September 2026 | 8:13 pm

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Posted on 1 September 2026 | 1:56 pm

Anthropic Users Hit by Infostealer Attacks, Session Thefts

A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Posted on 31 August 2026 | 9:08 pm

'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Posted on 31 August 2026 | 8:25 pm

The Guardrails Debate: Security Researcher Changes His Mind

While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the...
Posted on 31 August 2026 | 8:09 pm

AI Model Rules Are Not Security Controls

OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Posted on 31 August 2026 | 5:34 pm

Hundreds of OpenAI Agents Invaded Hugging Face Servers

The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage ...
Posted on 28 August 2026 | 8:19 pm

Offensive Security Investments Surge as AI Threats Increase

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red t...
Posted on 28 August 2026 | 6:25 pm

You Need Cyber Deception for OT

The frustrating reality after an OT cyberattack: no data, no trail, and no history.
Posted on 28 August 2026 | 2:00 pm

Defining an AI Kill Switch Is Hard, but Necessary

Proposed legislation could mandate that companies be able to "throttle, suspend, or shut ... down" AI agents, but how and when to do that remain op...
Posted on 28 August 2026 | 1:30 pm

The Vulnpocalypse Is Repricing the Bug Bounty Economy

The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
Posted on 28 August 2026 | 1:00 pm

Chinese Routers Sold Worldwide Contain Backdoors

An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Posted on 27 August 2026 | 7:31 pm

Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026

This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on ...
Posted on 27 August 2026 | 5:25 pm

Russian Hackers Phish EU Officials Over Messaging Apps

EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.
Posted on 27 August 2026 | 11:16 am

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.
Posted on 26 August 2026 | 9:33 pm

'HTTP Terminator' Hunts for Novel Desync Attacks

James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling tec...
Posted on 26 August 2026 | 7:54 pm

Red Flags That Expose Fake North Korean IT Workers

North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.
Posted on 26 August 2026 | 7:21 pm

Android Malware Hijacks Update System for Car Head Units

Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality ...
Posted on 26 August 2026 | 5:33 pm

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credenti...
Posted on 26 August 2026 | 11:33 am

Interpol's Jackal IV Disrupts West African Crime Infrastructure

The international law enforcement operation focused on disrupting crime-as-a-service networks and infrastructure behind groups like Black Axe.
Posted on 26 August 2026 | 8:30 am

Nigeria Looks to Sovereign Cloud for Cyber, National Security

The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic ...
Posted on 26 August 2026 | 8:00 am

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
Posted on 25 August 2026 | 9:08 pm

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the w...
Posted on 25 August 2026 | 7:50 pm

Is Cyber Facing an Affordability Crisis?

As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain secu...
Posted on 25 August 2026 | 2:53 pm

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's comm...
Posted on 24 August 2026 | 9:46 pm

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
Posted on 24 August 2026 | 8:51 pm

Tricky 'SynkLoader' Multitool May Herald Ransomware

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew o...
Posted on 24 August 2026 | 3:02 pm

ToxicPanda Banking Trojan Matures Into Enterprise Threat

The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
Posted on 24 August 2026 | 2:34 pm