darkreading
Please support the site operations by clicking ads.
[Virtual Event] Building a Secure AI Strategy for the Enterprise
3 weeks 3 days hence
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
1 day 23 hours ago
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
Nate Nelson
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
1 day 23 hours ago
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
Arielle Waldman
Why AI Is So Good at Scamming Humans
2 days ago
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
AI Governance Can't Wait
2 days 1 hour ago
Adversaries can manipulate AI defensive reasoning to silently compromise target networks.
Tony Anscombe
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
2 days 2 hours ago
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
Robert Lemos
Indonesia Hit by Android Banking App-Cloning Campaign
2 days 17 hours ago
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
Alexander Culafi
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
2 days 21 hours ago
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
Nate Nelson
Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
3 days 3 hours ago
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
Elizabeth Montalbano
EU Cyber Resilience Act to Enforce New Reporting Requirements
3 days 11 hours ago
Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.
Nate Nelson
Mythos Vulnerability Firehose Hits a Human Bottleneck
3 days 21 hours ago
An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.
Jai Vijayan
US Government Accuses Chinese AI Firms of Distilling Frontier Models
3 days 22 hours ago
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
Alexander Culafi
Identity-Based AI Attack Threatens Security of Enterprise Data
4 days 3 hours ago
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
Elizabeth Montalbano
Patch Tuesday Sets Another Record With 974 CVEs
4 days 21 hours ago
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
Jai Vijayan
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
4 days 21 hours ago
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Alexander Culafi
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
4 days 21 hours ago
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Nate Nelson
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
5 days 1 hour ago
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Elizabeth Montalbano
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
5 days 6 hours ago
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Robert Lemos
Companies Have 6 Months to Prepare for Automated Attacks
1 week 2 days ago
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.
Robert Lemos
Checked
8 hours 21 minutes ago
Public RSS feed
darkreading feed