darkreading
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month 2 weeks hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
1 week 6 days hence
EDR Evasion Stack Helps Process Injection Slip Past Defenses
1 day 6 hours ago
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
Alexander Culafi
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
1 day 6 hours ago
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
Rob Wright
UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
1 day 11 hours ago
The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
Robert Lemos
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
1 day 12 hours ago
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
Elizabeth Montalbano
Relays Are Masking Chinese Access to Frontier AI Models in the US
2 days 5 hours ago
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
Jai Vijayan
How the CISO-CMO Alliance Builds Trust Before Crisis Strikes
2 days 6 hours ago
Cybersecurity and brand reputation are inextricably linked. Security and marketing leaders who establish regular touchpoints, develop joint crisis communications plans, and translate security risks into their brand impact position their organizations to significantly outperform those treating security as an operational IT concern.
George V. Hulme, Contributing Writer
Microsoft Disrupts EvilTokens Device Code Phishing Service
2 days 7 hours ago
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Alexander Culafi
Deception by Design: CISA's Guide to Tricking Cybercriminals
2 days 7 hours ago
The Cybersecurity and Infrastructure Security Agency (CISA) is going old school to help organizations with limited resources set traps for hackers.
Arielle Waldman
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
2 days 9 hours ago
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
Robert Lemos
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
2 days 15 hours ago
Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
2 days 16 hours ago
Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
Elizabeth Montalbano
How AI Agents Can Trigger Runaway Costs for Enterprises
3 days 5 hours ago
Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
Jai Vijayan
ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?
3 days 6 hours ago
ShinyHunters defaced Cl0p's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
Alexander Culafi
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
3 days 7 hours ago
Victims have been identified in Africa, including in Kenya and Uganda.
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
3 days 12 hours ago
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.
Elizabeth Montalbano
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
6 days 6 hours ago
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.
Cisco Zero-Day Highlights API Endpoint Authentication Issues
6 days 7 hours ago
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
Rob Wright
Checked
23 hours 2 minutes ago
Public RSS feed
darkreading feed