darkreading
Secure Your Spot at RSAC 2026 Conference
1 month 2 weeks hence
Attackers Harvest Dropbox Logins Via Fake PDF Lures
7 hours 25 minutes ago
A malware-free phishing campaign targets corporate inboxes and asks employees to view "request orders," ultimately leading to Dropbox credential theft.
Alexander Culafi
County Pays $600K to Wrongfully Jailed Pen Testers
7 hours 49 minutes ago
Iowa police arrested two penetration testers in 2019 for doing their jobs, highlighting the risk to security professionals in red teaming exercises.
Nate Nelson, Contributing Writer
Chinese Hackers Hijack Notepad++ Updates for 6 Months
9 hours 49 minutes ago
State-sponsored threat actors compromised the popular code editor's hosting provider to redirect targeted users to malicious downloads.
Jai Vijayan, Contributing Writer
ShinyHunters Expands Scope of SaaS Extortion Attacks
13 hours 38 minutes ago
Following its attacks on Salesforce instances last year, members of the cybercrime group have broadened their targeting and gotten more aggressive with extortion tactics.
Elizabeth Montalbano, Contributing Writer
Torq Moves SOCs Beyond SOAR With AI-Powered Hyper Automation
3 days 7 hours ago
Investors poured $140 million into Torq's Series D Round, raising the startup's valuation to $1.2 billion, to bring AI-based "hyper automation" to SOCs.
Jeffrey Schwartz
2026: The Year Agentic AI Becomes the Attack-Surface Poster Child
3 days 8 hours ago
Dark Reading asked readers whether agentic AI attacks, advanced deepfake threats, board recognition of cyber as a top priority, or password-less technology adoption would be most likely to become a trending reality for 2026.
Tara Seals
Out-of-the-Box Expectations for 2026 Reveal a Grab Bag of Risk
3 days 8 hours ago
Security teams need to be thinking about this list of emerging cybersecurity realities to avoid rolling the dice on enterprise security risks (and opportunities).
Tara Seals
Tenable Tackles AI Governance, Shadow AI Risks, Data Exposure
3 days 9 hours ago
The Tenable One AI Exposure add-on discovers unsanctioned AI use in the organization and enforces policy compliance with approved tools.
Jeffrey Schwartz
OpenClaw AI Runs Wild in Business Environments
3 days 13 hours ago
The popular open source AI assistant (aka ClawdBot, MoltBot) has taken off, raising security concerns over its privileged, autonomous control within users' computers.
Robert Lemos, Contributing Writer
Chinese APTs Hacking Asian Orgs With High-End Malware
4 days 3 hours ago
Advanced persistent threat (APT) groups have deployed new cyber weapons against a variety of targets, highlighting the increasing threats to the region.
Nate Nelson, Contributing Writer
Trump Administration Rescinds Biden-Era Software Guidance
4 days 7 hours ago
Federal agencies will no longer be required to solicit software attestations that they comply with NIST's Secure Software Development Framework (SSDF). What that means long term is unclear.
Alexander Culafi
Second Round of Critical RCE Bugs in n8n Spikes Corporate Risk
4 days 7 hours ago
A new around of vulnerabilities in the popular AI automation platform could let attackers hijack servers and steal credentials, allowing full takeover.
Jai Vijayan, Contributing Writer
'Semantic Chaining' Jailbreak Dupes Gemini Nano Banana, Grok 4
4 days 13 hours ago
If an attacker splits a malicious prompt into discrete chunks, some large language models (LLMs) will get lost in the details and miss the true intent.
Nate Nelson, Contributing Writer
From Quantum to AI Risks: Preparing for Cybersecurity's Future
4 days 14 hours ago
In the latest edition of "Reporters' Notebook," a trio of journalists urge the cybersecurity industry to prioritize patching vulnerabilities, preparing for quantum threats, and refining AI applications,
Kristina Beek, Alexander Culafi
How Can CISOs Respond to Ransomware Getting More Violent?
5 days 6 hours ago
Ransomware defense requires focusing on business resilience. This means patching issues promptly, improving user education, and deploying multifactor authentication.
James Doggett
Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest
5 days 6 hours ago
Russian and Chinese nation-state attackers are exploiting a months-old WinRAR vulnerability, despite a patch that came out last July.
Alexander Culafi
Fortinet Confirms New Zero-Day Behind Malicious SSO Logins
5 days 8 hours ago
To stop the ongoing attacks, the cybersecurity vendor took the drastic step of temporarily disabling FortiCloud single sign-on (SSO) authentication for all devices.
Rob Wright
Consumers Reluctant to Shop at Stores That Don't Take Security Seriously
5 days 9 hours ago
The retail sector must adapt as consumers become more cybersecurity-conscious. Increased attack transparency is a good place to start.
Arielle Waldman
Checked
2 hours 46 minutes ago
Public RSS feed
darkreading feed