darkreading
Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit
1 day 2 hours ago
TeamPCP is the likely cyber threat actor behind attacks on Trivy, Checkmarx's KICS and VS Code plug-ins, and the LiteLLM AI library — and all signs point to more attacks to come.
Jai Vijayan
How AI Coding Tools Crushed the Endpoint Security Fortress
1 day 2 hours ago
Security vendors have spent years building up defenses around the endpoint, but one researcher says AI coding tools have brought the walls down.
Rob Wright
GitHub 'OpenClaw Deployer' Repo Delivers Trojan Instead
1 day 8 hours ago
An AI-assisted campaign is spreading more than 300 poisoned packages for diverse assets ranging from developer tools to game cheats.
Elizabeth Montalbano
How a Large Bank Uses AI Digital Twins for Threat Hunting
1 day 10 hours ago
JPMorgan Chase uses digital fingerprints and digital twins to spot online attackers and malicious behaviors while also reducing pesky false alerts.
Bree Fowler
Microsoft Proposes Better Identity, Guardrails for AI Agents
1 day 11 hours ago
Companies need better controls to manage key threats rising from the growth of agentic AI. These new features provide a starting point.
Robert Lemos
AI in the SOC: What Could Go Wrong?
2 days 1 hour ago
Two cybersecurity leaders tested out AI in their respective SOCs for six months — and here's what they learned.
Becky Bracken
Trivy Supply Chain Attack Targets CI/CD Secrets
2 days 2 hours ago
A threat actor used the open source security tool to deploy an infostealer into CI/CD workflows and steal cloud credentials, SSH keys, tokens, and other sensitive secrets.
Jai Vijayan
Ransomware's New Era: Moving at AI Speed
2 days 2 hours ago
Threat actors bypass security tools and use AI to launch faster ransomware attacks that exploit valid credentials and target data.
Arielle Waldman
CISOs Debate Human Role in AI-Powered Security
2 days 3 hours ago
The idea of a "human in the loop" in AI deployment was challenged during a security executive panel at the RSAC 2026 Conference this week.
Alexander Culafi
Attackers Hide Infostealer in Copyright Infringement Notices
2 days 8 hours ago
A phishing campaign targeting healthcare, government, hospitality, and education sectors in various countries uses several evasion techniques to avoid detection.
Elizabeth Montalbano
Secure Your Spot at RSAC 2026 Conference
2 days 12 hours ago
AI Dominates RSAC Innovation Sandbox
3 days 12 hours ago
Ten finalists will each have three minutes to make their case for being the most innovative, promising young security company of the year.
Dark Reading Staff
Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw
5 days 4 hours ago
Attackers can execute arbitrary code without authentication if Oracle's Identity or Web Services Managers are exposed to the Web.
Nate Nelson
Cyber OpSec Fail: Beast Gang Exposes Ransomware Server
5 days 7 hours ago
Files on a central cloud server used by the ransomware group highlight a systematic, aggressive attack on network backups as a key TTP.
Robert Lemos
Interlock Ransomware Targets Cisco Enterprise Firewalls
5 days 10 hours ago
The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly disclosed.
Alexander Culafi
AI Conundrum: Why MCP Security Can't Be Patched Away
6 days 1 hour ago
RSAC Conference Preview: MCP introduces security risks into LLM environments that are architectural and not easily fixable, researcher says.
Jai Vijayan
With Government's Role Uncertain, Businesses Unite to Combat Fraud
6 days 3 hours ago
Major industry leaders agree to share information and collaborate to boost defenses in the wake of distressing online scams.
Arielle Waldman
Native Launches With Security Control Plane for Multicloud
6 days 3 hours ago
The cloud security startup's platform translates and enforces security policies across AWS, Azure, Google Cloud, and Oracle using provider-native controls.
Dark Reading Staff
Post-Quantum Web Could be Safer, Faster
6 days 5 hours ago
Major providers are testing a quantum-safe version of HTTPS that shrinks certificates to one-tenth their previous size, decreasing latency and adding transparency.
Robert Lemos
Checked
20 hours 48 minutes ago
Public RSS feed
darkreading feed