darkreading
CISOs vs. Boards: Myth or Misunderstanding?
2 days 6 hours ago
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
Arielle Waldman
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
2 days 7 hours ago
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
Robert Lemos
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
2 days 14 hours ago
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.
Nate Nelson
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
2 days 14 hours ago
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and cloud workloads.
Jeffrey Schwartz
Europe's Multilingual Reality Exposes AI Security Gaps
2 days 20 hours ago
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
Alexander Culafi
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
3 days 6 hours ago
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
Rob Wright
Agentic AI Challenges Progress in Confidential Computing
3 days 16 hours ago
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.
Agam Shah
Brazilian Banking Trojan Actively Spreading in Portugal
3 days 20 hours ago
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
Nate Nelson
Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain
4 days 2 hours ago
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.
Robert Lemos
Flaws in Passkey Implementation Show Old Attacks Still Work
4 days 3 hours ago
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.
Arielle Waldman
Attackers Are Learning to Live Off the AI Toolchain
4 days 6 hours ago
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
Jai Vijayan
Fake Bahrain Alert App Deploys Android Surveillance Malware
4 days 7 hours ago
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.
Alexander Culafi
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
4 days 11 hours ago
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
Elizabeth Montalbano
EU Financial Institutions Leak Data Through Cookie Trackers
4 days 16 hours ago
European and US banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.
Alexander Culafi
Ransomware Is Accelerating, but It's Not Because of AI
5 days 5 hours ago
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
Jai Vijayan
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
5 days 6 hours ago
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.
Robert Lemos
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
5 days 8 hours ago
A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
Elizabeth Montalbano
Choose Wisely: AI-Generated Coding Risk Varies, a Lot
5 days 14 hours ago
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
Alexander Culafi
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
6 days 5 hours ago
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
Jai Vijayan
Checked
21 hours 54 minutes ago
Public RSS feed
darkreading feed