A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
0
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
Thứ Sáu, 31 tháng 7, 2026
Việt Nam Hacker
0
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
Việt Nam Hacker
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.
0
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
Thứ Năm, 30 tháng 7, 2026
Việt Nam Hacker
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
0
AI Harnesses Burst With Potential Exploit Opps
Việt Nam Hacker
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
0
Red Agents vs. Blue Agents: How to Make AI Better At Defense
Thứ Tư, 29 tháng 7, 2026
Việt Nam Hacker
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
0
When AppSec Scanners Become a Supply Chain Attack Vector
Việt Nam Hacker
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
0
Flaw From 2002 Exposes Data Centers to Server Takeover
Thứ Ba, 28 tháng 7, 2026
Việt Nam Hacker
Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.
0
Stronger AI Safety Requires Peeking Inside the 'Black Box'
Việt Nam Hacker
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
0
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Việt Nam Hacker
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
0
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Thứ Hai, 27 tháng 7, 2026
Việt Nam Hacker
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
0
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
Việt Nam Hacker
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
0
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
Việt Nam Hacker
0
CISOs vs. Boards: Myth or Misunderstanding?
Thứ Sáu, 24 tháng 7, 2026
Việt Nam Hacker
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
0
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
Việt Nam Hacker
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
0
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Việt Nam Hacker
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant's identity and access other tenants' data, credentials, and cloud workloads.
0
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
Việt Nam Hacker
A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser.
0
Europe's Multilingual Reality Exposes AI Security Gaps
Việt Nam Hacker
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
0
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Thứ Năm, 23 tháng 7, 2026
Việt Nam Hacker
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
0
Brazilian Banking Trojan Actively Spreading in Portugal
Việt Nam Hacker
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
0
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
Thứ Tư, 22 tháng 7, 2026
Việt Nam Hacker
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.
0
Attackers Are Learning to Live Off the AI Toolchain
Việt Nam Hacker
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
0
Fake Bahrain Alert App Deploys Android Surveillance Malware
Việt Nam Hacker
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.
0
EU Financial Institutions Leak Data Through Cookie Trackers
Việt Nam Hacker
European banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.
0
Ransomware Is Accelerating, But It's Not Because of AI
Thứ Ba, 21 tháng 7, 2026
Việt Nam Hacker
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
0
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
Việt Nam Hacker
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.
0
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
Việt Nam Hacker
A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
0
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Thứ Hai, 20 tháng 7, 2026
Việt Nam Hacker
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
0
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
Việt Nam Hacker
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions.
0
CISOs Feel the Heat Over AI Risk
Việt Nam Hacker
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
0
Attackers Combo Up Evasion Tactics for BEC Phishing
Việt Nam Hacker
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
0
Cybersecurity Keeps Events 'Uneventful'
Việt Nam Hacker
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.
0
Inc Ransomware Exploits SonicWall SMA Zero-Days
Thứ Sáu, 17 tháng 7, 2026
Việt Nam Hacker
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.
0
The Real AI Threat Is Blind Trust
Việt Nam Hacker
0
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
Việt Nam Hacker
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.
0
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
Việt Nam Hacker
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks.
0
Agentic AI Is Untamable: Ask the Right Security Questions
Thứ Năm, 16 tháng 7, 2026
Việt Nam Hacker
Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.
0
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Việt Nam Hacker
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
0
Forgotten Bootloaders Expose Secure Boot Blind Spot
Thứ Tư, 15 tháng 7, 2026
Việt Nam Hacker
Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.
0
Identity Attacks Overtake Exploits as Top Ransomware Cause
Việt Nam Hacker
Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
0
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
Việt Nam Hacker
We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity intelligence beyond North America.
0
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
Việt Nam Hacker
The US government's restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant cyber implications.
0
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
Việt Nam Hacker
The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.
0
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
Thứ Ba, 14 tháng 7, 2026
Việt Nam Hacker
Three of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.
0
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
Việt Nam Hacker
Automated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.
0
Manage Vendor Risk in a Few Practical Steps
Việt Nam Hacker
Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.
0
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
Việt Nam Hacker
Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.
0
Weak Security Continues to Fuel Russian Cyberattacks
Thứ Hai, 13 tháng 7, 2026
Việt Nam Hacker
In a first, the UK and the EU jointly impose sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.
0
'Yellow Teams' Are Defining the Future of AI Security
Việt Nam Hacker
In some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat.
0
GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
Việt Nam Hacker
A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.
0
Turning the Tables on Email Scammers With 'ScamBuster'
Việt Nam Hacker
An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.
0
Jen Ellis: Connecting Cyber Community With Political Machinery
Thứ Sáu, 10 tháng 7, 2026
Việt Nam Hacker
Security Pro File: On the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Jen Ellis' advocacy on behalf of security researchers.
0
Turning the Tables on Email Scammers With 'ScamBuster'
Việt Nam Hacker
An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.
0
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
Việt Nam Hacker
While cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.
0
AI Coding: Do Security Risks Outweigh Productivity Gains?
Việt Nam Hacker
AI coding tools cost $19-$200/month/user, but security scanning, remediation, and false positives add hidden costs. Are the productivity gains worth it?
0
AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
Thứ Năm, 9 tháng 7, 2026
Việt Nam Hacker
If you're handling them like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.
0
Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure
Việt Nam Hacker
Obscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats.
0
Microsoft Reins in RoguePlanet Zero-Day Threat
Việt Nam Hacker
The researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft zero-days.
0
European Organizations Have a Collaboration Security Confidence Gap
Việt Nam Hacker
A new survey shows security leaders have an inflated sense of safety regarding their collaboration tools and platforms.
0
Mexico's New Cyber Plan Faces Its First Real Test
Thứ Tư, 8 tháng 7, 2026
Việt Nam Hacker
The Latin American nation's cybersecurity plan — still in the expansion phase — has to survive its own knockout round during the FIFA World Cup.
0
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
Việt Nam Hacker
The attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer.
0
Vidar Infostealer Hammers SMBs via Malvertising Campaign
Việt Nam Hacker
A financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining.
0
State IDs for AI Agents: Will Estonia Set a Precedent?
Việt Nam Hacker
0
Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Thứ Ba, 7 tháng 7, 2026
Việt Nam Hacker
Varonis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security.
0
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
Việt Nam Hacker
The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too.
0
'BusySnake' Infostealer Slithers into Critical Infrastructure Networks
Thứ Hai, 6 tháng 7, 2026
Việt Nam Hacker
A threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan.
0
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Việt Nam Hacker
Attackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).
0
JadePuffer: The First Complete LLM-Driven Ransomware Attack
Việt Nam Hacker
An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.
0
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
Thứ Năm, 2 tháng 7, 2026
Việt Nam Hacker
Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data.
0
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
Việt Nam Hacker
Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker.
0
He Thought He Was Secure; His Phone Number Was Stolen Anyway
Việt Nam Hacker
Threat actors can easily steal one-time passwords sent by text when they conduct a SIM swap attack. This can lead to account takeovers, so users must layer up their security measures.
0
When Too Much Security Data Became the Risk
Việt Nam Hacker
Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM.
0
Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
Thứ Tư, 1 tháng 7, 2026
Việt Nam Hacker
Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.
0
And the Winner in Dominant Malware Delivery? ClickFix
Việt Nam Hacker
Researchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule.
Đăng ký:
Bài đăng (Atom)
