darkreading
The Ransomware Holiday Bind: Burnout or Be Vulnerable
4 months 2 weeks ago
Ransomware groups target enterprises during off-hours, weekends, and holidays when security teams are stretched thin and response times lag.
Arielle Waldman
AI Bolsters Python Variant of Brazilian WhatsApp Attacks
4 months 2 weeks ago
Water Saci has upgraded its self-propagating malware to compromise banks and cryptocurrency exchanges by targeting enterprise users of the popular chat app.
Elizabeth Montalbano, Contributing Writer
China Researches Ways to Disrupt Satellite Internet
4 months 2 weeks ago
While satellite constellations — such as Starlink — are resilient, 2,000 drones could cut communications to a region the size of Taiwan, researchers find.
Robert Lemos, Contributing Writer
While ECH Adoption Is Low, Risks Remain for Enterprises, End Users
4 months 2 weeks ago
Is the new privacy protocol helping malicious actors more than Internet users?
Colm Healy
Iran's 'MuddyWater' Levels Up With MuddyViper Backdoor
4 months 2 weeks ago
New Fooder loader and memory-only tactics suggest MuddyWater has evolved from its usual noisy ops to more stealthy espionage operations.
Jai Vijayan, Contributing Writer
Researchers Use Poetry to Jailbreak AI Models
4 months 2 weeks ago
When prompts were presented in poetic rather than prose form, attack success rates increased from 8% to 43%, on average — a fivefold increase.
Alexander Culafi
New Raptor Framework Uses Agentic Workflows to Create Patches
4 months 2 weeks ago
Researchers used prompts and large language models to develop an open source AI framework capable of generating both vulnerability exploits and patches.
Arielle Waldman
DPRK's 'Contagious Interview' Spawns Malicious Npm Package Factory
4 months 2 weeks ago
North Korean attackers have delivered more than 197 malicious packages with 31K-plus downloads since Oct. 10, as part of ongoing state-sponsored activity to compromise software developers.
Elizabeth Montalbano, Contributing Writer
Tomiris Unleashes 'Havoc' With New Tools, Tactics
4 months 2 weeks ago
The Russian-speaking group is targeting government and diplomatic entities in CIS member states and Central Asia in its latest cyber-espionage campaign.
Jai Vijayan, Contributing Writer
CodeRED Emergency Alert Platform Shut Down Following Cyberattack
4 months 2 weeks ago
The Inc ransomware gang took responsibility for the attack earlier this month and claimed it stole sensitive subscriber data.
Rob Wright
Police Disrupt 'Cryptomixer,' Seize Millions in Crypto
4 months 2 weeks ago
Multiple European law enforcement agencies recently disrupted Cryptomixer, a service allegedly used by cybercriminals to launder ill-gotten gains from ransomware and other cyber activities.
Alexander Culafi
Shai-hulud 2.0 Variant Threatens Cloud Ecosystem
4 months 2 weeks ago
The latest attack from the self-replicating npm-package poisoning worm can also steal credentials and secrets from AWS, Google Cloud Platform, and Azure.
Elizabeth Montalbano, Contributing Writer
Digital Fraud at Industrial Scale: 2025 Wasn't Great
4 months 2 weeks ago
Advanced fraud attacks surged 180% in 2025 as cyber scammers used generative AI to churn out flawless IDs, deepfakes, and autonomous bots at levels never before seen.
Jai Vijayan, Contributing Writer
'Dark LLMs' Aid Petty Criminals, But Underwhelm Technically
4 months 2 weeks ago
As in the wider world, AI is not quite living up to the hype in the cyber underground. But it's definitely helping low-level cybercriminals do competent work.
Nate Nelson, Contributing Writer
Prompt Injections Loom Large Over ChatGPT's Atlas Browser
4 months 2 weeks ago
It's the law of unintended consequences: equipping browsers with agentic AI opens the door to an exponential volume of prompt injections.
Alexander Culafi
How Malware Authors Are Incorporating LLMs to Evade Detection
4 months 2 weeks ago
Cyberattackers are integrating large language models (LLMs) into malware, running prompts at runtime to evade detection and augment their code on demand.
Robert Lemos, Contributing Writer
Enterprises Aren't Confident They Can Secure Non-Human Identities (NHIs)
4 months 2 weeks ago
More than half of organizations surveyed aren't sure they can secure non-human identities (NHIs), underscoring the lag between the rollout of these identities and the tools to protect them.
Don Tait
Iran Exploits Cyber Domain to Aid Kinetic Strikes
4 months 3 weeks ago
The country deploys "cyber-enabled kinetic targeting" prior to — and following — real-world missile attacks against ships and land-based targets.
Robert Lemos, Contributing Writer
Advanced Security Isn't Stopping Ancient Phishing Tactics
4 months 3 weeks ago
New research reveals that sophisticated phishing attacks consistently bypass traditional enterprise security measures.
Kristina Beek
Checked
1 hour 35 minutes ago
Public RSS feed
darkreading feed