darkreading
Secure Your Spot at RSAC 2026 Conference
2 months hence
Risky Chinese Electric Buses Spark Aussie Gov't Review
3 hours 1 minute ago
Deployed across Australia and Europe, China's electric buses are vulnerable to cybercriminals and sport a virtual kill switch the Chinese state could activate.
Nate Nelson, Contributing Writer
Fortinet Firewalls Hit With Malicious Configuration Changes
3 hours 56 minutes ago
Automated infections of potentially fully patched FortiGate devices are allowing threat actors to steal firewall configuration files.
Rob Wright
From a Whisper to a Scream: Europe Frets About Overreliance on US Tech
7 hours 6 minutes ago
Concern is growing across Europe about relying on US cybersecurity companies, and Greenland takeover talk is eroding trust across the EU even further.
Rik Turner
Latin American Orgs Lack Confidence in Cyber Defenses, Skills
9 hours 9 minutes ago
Cybersecurity professionals in Latin America are least likely to have faith in their countries' preparedness for cyberattacks on critical infrastructure, the World Economic Forum says.
Robert Lemos, Contributing Writer
DPRK Actors Deploy VS Code Tunnels for Remote Hacking
11 hours 9 minutes ago
A spear-phishing campaign tied to the Democratic People's Republic of Korea (DPRK) uses trusted Microsoft infrastructure to avoid detection.
Elizabeth Montalbano, Contributing Writer
AI Agents Undermine Progress in Browser Security
1 day 2 hours ago
Web browser companies have put in substantial effort over the past three decades to strengthen the browser security stack against abuses. Agentic browsers are undoing all that work.
Robert Lemos, Contributing Writer
'Contagious Interview' Attack Now Delivers Backdoor Via VS Code
1 day 3 hours ago
Once trust is granted to the repository's author, a malicious app executes arbitrary commands on the victim's system with no other user interaction.
Jai Vijayan, Contributing Writer
Phishing Campaign Zeroes in on LastPass Customers
1 day 4 hours ago
The bait incudes plausible subject lines and credible messages, most likely thanks to attackers' use of large language models to craft them.
Alexander Culafi
Complex VoidLink Linux Malware Created by AI
1 day 10 hours ago
Researchers say the advanced framework was built almost entirely by agents, marking a significant evolution in the use of AI to develop wholly original malware.
Elizabeth Montalbano, Contributing Writer
'Damn Vulnerable' Training Apps Leave Vendors' Clouds Exposed
1 day 11 hours ago
Hackers are already leveraging these over-permissioned programs to access the IT systems of major security vendors.
Nate Nelson, Contributing Writer
'CrashFix' Scam Crashes Browsers, Delivers Malware
2 days 4 hours ago
The attack consists of a NexShield malicious browser extension, a social engineering technique to crash the browser, and a Python-based RAT.
Jai Vijayan, Contributing Writer
Mass Spam Attacks Leverage Zendesk Instances
2 days 4 hours ago
The CRM vendor advised ignoring or deleting suspicious emails and said the attacks were not tied to any breach or software vulnerability.
Alexander Culafi
Vulnerabilities Threaten to Break Chainlit AI Framework
2 days 7 hours ago
Familiar bugs in a popular open source framework for AI chatbots could give attackers dangerous powers in the cloud.
Nate Nelson, Contributing Writer
Google Gemini Flaw Turns Calendar Invites Into Attack Vector
2 days 9 hours ago
The indirect prompt injection vulnerability allows an attacker to weaponize invites to circumvent Google's privacy controls and access private data.
Elizabeth Montalbano, Contributing Writer
Microsoft & Anthropic MCP Servers at Risk of RCE, Cloud Takeovers
2 days 9 hours ago
Researchers found the popular model context protocol (MCP) servers, which are integral components of AI services, carry serious vulnerabilities.
Nate Nelson, Contributing Writer
ChatGPT Health Raises Big Security, Safety Concerns
3 days 7 hours ago
ChatGPT Health promises robust data protection, but elements of the rollout raise big questions regarding user security and safety.
Alexander Culafi
More Problems for Fortinet: Critical FortiSIEM Flaw Exploited
6 days 4 hours ago
CVE-2025-64155, a command injection vulnerability, was disclosed earlier this week and quickly came under attack from a variety of IP addresses.
Rob Wright
CISOs Rise to Prominence: Security Leaders Join the Executive Suite
6 days 9 hours ago
Security professionals are moving up the executive ranks as enterprises face rising regulatory and compliance standards.
Arielle Waldman
Checked
2 hours 13 minutes ago
Public RSS feed
darkreading feed