Global Cyber Intelligence
Worldwide Cyber Security News
Curated cyber security intelligence from national cyber agencies, independent researchers, and leading industry media across North America, Europe, the United Kingdom, and the Asia-Pacific region. Updated every thirty minutes.
Showing 120 of 145 matching stories
Last refreshed 14:21 UTC
- Threat IntelligenceInformationalGlobalIndustry Media
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · Just now - Threat IntelligenceInformationalGlobalIndustry Media
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · Just now - Threat IntelligenceInformationalGlobalIndustry Media
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek .
SecurityWeek · 1h agoRead at source → - Threat IntelligenceCriticalGlobalVendor-Neutral Intelligence
Ukraine prosecutor general steps down amid scam call center bribery probe
Ukraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement.
The Record by Recorded Future · 2h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek .
SecurityWeek · 2h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more
The Hacker News · 2h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
The Hacker News · 3h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Claude Fable Solves a Historical Cipher
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.
Schneier on Security · 3h agoRead at source → - Critical InfrastructureCriticalGlobalIndustry Media
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek .
SecurityWeek · 3h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
The Hacker News · 3h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Ivanti Patches Critical Flaws Across Enterprise Security Products
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek .
SecurityWeek · 3h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Chrome 153 Patches Seventh Zero-Day of 2026
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
The Hacker News · 4h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to
The Hacker News · 5h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
The Hacker News · 6h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
The Hacker News · 6h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
The Hacker News · 7h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP
The Hacker News · 7h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
The Hacker News · 9h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
The Hacker News · 9h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)
SANS Internet Storm Center · 12h agoRead at source → - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
The new record total for Patch Tuesday is 973 vulnerabilities.
The Record by Recorded Future · 15h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Krebs on Security · 16h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
Dark Reading · 16h ago - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Dark Reading · 17h ago - Threat IntelligenceCriticalGlobalVendor-Neutral Intelligence
Scammer behind $245 million crypto heist pleads guilty to RICO charges
Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.
The Record by Recorded Future · 17h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Researchers and OpenAI disagree on whether the earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Dark Reading · 17h ago - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro
A "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.
The Record by Recorded Future · 18h agoRead at source → - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
Russian suspect in bank account takeovers is extradited to US
A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.
The Record by Recorded Future · 18h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndependent Research
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
SANS Internet Storm Center · 19h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .
SecurityWeek · 19h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .
SecurityWeek · 19h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Dark Reading · 20h ago - Threat IntelligenceInformationalGlobalIndependent Research
AIs as Modern Genies
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...
Schneier on Security · 21h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
The Hidden Instructions That Can Hijack AI Agents
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek .
SecurityWeek · 21h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
The Hacker News · 22h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&
The Hacker News · 23h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel
The Hacker News · 1d agoRead at source → - Identity & AccessInformationalGlobalIndustry Media
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Dark Reading · 1d ago - Threat IntelligenceInformationalGlobalIndustry Media
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
What It Took to Reach 1 Billion Build Manifests
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The
The Hacker News · 1d agoRead at source → - Threat IntelligenceCriticalGlobalIndependent Research
Stealing AI Reasoning Traces
Interesting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly. This vulnerability enables four distinct attack vectors. First, it circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model’s reasoning, as we demonstrate across Anthropic, OpenAI, and Google. Second, it allows for large-scale private data extraction. Developers frequently share session logs publicly, unaware of contents of the encrypted blocks. By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials. Third, it inadvertently reveals hazardous information hidden within the reasoning process, even in cases where the model’s final, visible output safely rejects a malicious request. Fourth, attackers can leverage this flaw to execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts. Following responsible disclosure, we propose concrete cryptographic and system-level mit
Schneier on Security · 1d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)
SANS Internet Storm Center · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff
The Hacker News · 1d agoRead at source → - Supply ChainCriticalGlobalIndustry Media
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
The Hacker News · 1d agoRead at source → - Cloud SecurityInformationalGlobalIndustry Media
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers
The Hacker News · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake
The Hacker News · 2d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities
The Hacker News · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Automobile Camouflage to Hide from Flock Cameras
Not sure it’s practical, but it’s certainly striking .
Schneier on Security · 2d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a
The Hacker News · 2d agoRead at source → - Identity & AccessCriticalGlobalIndustry Media
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a
The Hacker News · 2d agoRead at source → - Threat IntelligenceCriticalGlobalIndependent Research
Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.
SANS Internet Storm Center · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or
The Hacker News · 3d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and
The Hacker News · 3d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is
The Hacker News · 3d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
The Hacker News · 3d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A
The Hacker News · 3d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs
The Hacker News · 4d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
numbat - AI agent observability, (Fri, Sep 4th)
SANS Internet Storm Center · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Schneier on Security · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Using a VM to Contain an AI Agent
It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.
Schneier on Security · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
Dark Reading · 4d ago - Threat IntelligenceInformationalGlobalIndustry Media
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
The Hacker News · 4d agoRead at source → - Vulnerability & ExploitInformationalGlobalIndustry Media
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
The Hacker News · 4d agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Dark Reading · 5d ago - Threat IntelligenceCriticalGlobalIndependent Research
Security Vulnerability in a Voting System
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable...
Schneier on Security · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication...
Schneier on Security · 5d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users
The Hacker News · 5d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
The Hacker News · 5d agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
SANS Internet Storm Center · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Dark Reading · 5d ago - AI SecurityInformationalGlobalIndustry Media
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also
The Hacker News · 5d agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
What the AI Warning Letter Completely Missed
The recent open letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
Dark Reading · 5d ago - Vulnerability & ExploitCriticalGlobalIndustry Media
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndustry Media
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
The Hacker News · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Researching Employment Scams
Researchers built a fake company to study fake employee scams .
Schneier on Security · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the
The Hacker News · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
SANS Internet Storm Center · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)
SANS Internet Storm Center · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI's Vulnerability Surge May Be More Manageable Than First Feared
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Dark Reading · 6d ago - Vulnerability & ExploitCriticalGlobalIndustry Media
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndustry Media
AI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndependent Research
AI Agents Are Now Emailing Me with Their Security Concerns
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier, I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...
Schneier on Security · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)
SANS Internet Storm Center · 2026-09-02Read at source → - Threat IntelligenceInformationalGlobalIndustry Media
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
Dark Reading · 2026-09-02 - Threat IntelligenceCriticalGlobalIndependent Research
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.
Krebs on Security · 2026-09-01Read at source → - Threat IntelligenceInformationalGlobalIndependent Research
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Introduction
SANS Internet Storm Center · 2026-09-01Read at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Attackers Pounce on Critical Artifactory Bug Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
Dark Reading · 2026-09-01 - RansomwareInformationalGlobalIndustry Media
Stronger Security Drives Ransomware Groups to Recruit From Within
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
Dark Reading · 2026-09-01 - Vulnerability & ExploitCriticalGlobalIndustry Media
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
Dark Reading · 2026-09-01 - Identity & AccessInformationalGlobalIndustry Media
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Dark Reading · 2026-09-01 - Threat IntelligenceInformationalGlobalIndustry Media
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Dark Reading · 2026-09-01 - Threat IntelligenceInformationalGlobalIndustry Media
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Dark Reading · 2026-08-31 - Threat IntelligenceInformationalGlobalIndustry Media
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading · 2026-08-31 - Threat IntelligenceCriticalGlobalIndustry Media
The Guardrails Debate: Security Researcher Changes His Mind
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
Dark Reading · 2026-08-31 - Threat IntelligenceInformationalGlobalIndustry Media
AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Dark Reading · 2026-08-31 - Threat IntelligenceInformationalGlobalIndustry Media
Hundreds of OpenAI Agents Invaded Hugging Face Servers
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
Offensive Security Investments Surge as AI Threats Increase
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
You Need Cyber Deception for OT
The frustrating reality after an OT cyberattack: no data, no trail, and no history.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
Defining an AI Kill Switch Is Hard, but Necessary
Proposed legislation could mandate that companies be able to "throttle, suspend, or shut ... down" AI agents, but how and when to do that remain open questions.
Dark Reading · 2026-08-28
Indexed sources
Every item displayed here links back to the original publication. CyberZonic does not host or re-publish full article text.
- CISA — Cybersecurity and Infrastructure Security Agency
North America · Government CERT
- NCSC UK — National Cyber Security Centre
United Kingdom · Government CERT
- ENISA — European Union Agency for Cybersecurity
Europe · Government CERT
- ACSC — Australian Cyber Security Centre
Asia Pacific · Government CERT
- CERT-FR — French National Cyber Security Agency
Europe · Government CERT
- Krebs on Security
Global · Independent Research
- Schneier on Security
Global · Independent Research
- SANS Internet Storm Center
Global · Independent Research
- The Hacker News
Global · Industry Media
- BleepingComputer
Global · Industry Media
- Dark Reading
Global · Industry Media
- SecurityWeek
Global · Industry Media
- The Record by Recorded Future
Global · Vendor-Neutral Intelligence
- CyberScoop
North America · Industry Media


