darkreading
[Virtual Event] Building a Secure AI Strategy for the Enterprise
1 month hence
Companies Have 6 Months to Prepare for Automated Attacks
1 day 13 hours ago
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
Robert Lemos
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
1 day 16 hours ago
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Alexander Culafi
Insurers Search for Answers to Rein in Rogue AI
1 day 17 hours ago
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Robert Lemos
Large Enterprises Targeted in Fake Merger & Acquisition Scams
2 days 9 hours ago
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Nate Nelson
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
2 days 9 hours ago
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
Rob Wright
What the AI Warning Letter Completely Missed
2 days 11 hours ago
The recent AI warning letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
James Lyne
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
2 days 14 hours ago
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
Elizabeth Montalbano
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
2 days 17 hours ago
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
Nate Nelson
AI's Vulnerability Surge May Be More Manageable Than First Feared
3 days 8 hours ago
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Jai Vijayan
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
3 days 8 hours ago
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Alexander Culafi
AI Gives Cybercriminals a Dangerous Time Advantage
3 days 9 hours ago
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Kristina Beek
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
3 days 12 hours ago
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Elizabeth Montalbano
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
4 days 4 hours ago
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
Robert Lemos
Attackers Pounce on Critical Artifactory Bug Following Disclosure
4 days 8 hours ago
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
Jai Vijayan
Stronger Security Drives Ransomware Groups to Recruit From Within
4 days 8 hours ago
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
Arielle Waldman
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
4 days 8 hours ago
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
Rob Wright
AI Model Evaluator METR Hit by Credential Theft, Probing
4 days 9 hours ago
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Alexander Culafi
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
4 days 15 hours ago
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Elizabeth Montalbano
Checked
15 hours 10 minutes ago
Public RSS feed
darkreading feed