darkreading
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month 3 weeks hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
2 weeks 5 days hence
MFA Won't Save You From OAuth Consent Abuse
7 hours 58 minutes ago
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
Vishnu Galata
AI Agent Breaches Spanish Organization, Modifies Personal Data
19 hours 13 minutes ago
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
Nate Nelson
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
1 day 4 hours ago
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
Jai Vijayan
China's FamousSparrow APT Spies on US Politics in Latin America
1 day 6 hours ago
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
Nate Nelson
AI Security Spending Jumps as Fear Outpaces Proof of Value
2 days 4 hours ago
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
Jai Vijayan
Fighting Your Dragons Through Tough Tech Times
2 days 8 hours ago
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
Dark Reading Editorial Team
BragJack Attack Can Turn a Browser's Agentic AI Against It
2 days 9 hours ago
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
Elizabeth Montalbano
Cyber Op Targets South Korean Media & Automotive Sectors
3 days 1 hour ago
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
Robert Lemos
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
3 days 5 hours ago
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
Rob Wright
Black Hat USA 2026 | OpenAI's Deep Dive Into Hugging Face Incident
3 days 6 hours ago
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards and cyber resilience.
Black Hat Staff
VectraRAT Can Hack Windows Enterprises for $250 per Month
3 days 9 hours ago
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
Elizabeth Montalbano
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
4 days 4 hours ago
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
Jai Vijayan
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
4 days 5 hours ago
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
Rob Wright
Anthropic CEO: Time to Shift From Improving to Controlling AI
4 days 9 hours ago
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
Elizabeth Montalbano
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
1 week ago
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
Nate Nelson
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
1 week ago
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
Arielle Waldman
SpiderSilk Hunts External Threats With AI-Based Scanner
1 week ago
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.
Agam Shah
Checked
7 hours 8 minutes ago
Public RSS feed
darkreading feed