0

Anthropic Users Hit by Infostealer Attacks, Session Thefts

Thứ Hai, 31 tháng 8, 2026
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
0

'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
0

AI Model Rules Are Not Security Controls

OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
0

Hundreds of OpenAI Agents Invaded Hugging Face Servers

Thứ Sáu, 28 tháng 8, 2026
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
0

Offensive Security Investments Surge as AI Threats Increase

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
0

Defining an AI Kill Switch Is Hard, But Necessary

Proposed legislation could mandate that companies be able to "throttle, suspend, or shut ... down" AI agents, but how and when to do that remain open questions.
0

The Vulnpocalypse Is Repricing the Bug Bounty Economy

The surge of AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
0

Chinese Routers Sold Worldwide Contain Backdoors

Thứ Năm, 27 tháng 8, 2026
An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
0

Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026

This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.
0

'HTTP Terminator' Hunts for Novel Desync Attacks

James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.
0

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Thứ Tư, 26 tháng 8, 2026
GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.
0

Red Flags That Expose Fake North Korean IT Workers

North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.
0

Android Malware Hijacks Update System for Car Head Units

Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.
0

Nigeria Looks to Sovereign Cloud for Cyber, National Security

The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.
0

Hidden Prompts Trick AI Into False Email Summaries

Thứ Ba, 25 tháng 8, 2026
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
0

Is Cyber Facing an Affordability Crisis?

As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
0

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

Thứ Hai, 24 tháng 8, 2026
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
0

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
0

The Vulnerability Gap: Why Discovery Is Outrunning Repair

AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.
0

ToxicPanda Banking Trojan Matures into Enterprise Threat

The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
0

Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near

Chủ Nhật, 23 tháng 8, 2026
The coming threat of super-powerful computers capable of cracking today’s algorithms requires upgrading encryption now. Tech companies have begun building defenses.
0

OWASP Flags Top AI Skill Risks in New Security Blueprint

Thứ Sáu, 21 tháng 8, 2026
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.
0

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

Thứ Năm, 20 tháng 8, 2026
In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.
0

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress.
0

N-able Bug Exposes Password Vault Master Keys

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?
0

Agentic AI Presents New Insider Threat Model for Orgs

Katie Moussouris of Luta Security talks with the Dark Reading News Desk about how enterprises will now need to monitor risks posed by their own agents in the wake of the recent Hugging Face attack.
0

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Thứ Tư, 19 tháng 8, 2026
The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.
0

The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed

Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to take away from AI agents escaping their environments to launch attacks.
0

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.
0

China-Linked Hacker Shows AI Capabilities in APAC Attack

Thứ Ba, 18 tháng 8, 2026
In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.
0

Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
0

CISOs Break Their Silence in 'Declassified' Docuseries

Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.
0

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.
0

Video Call Exploit Chains Two Flaws in Unisoc Modems

Thứ Hai, 17 tháng 8, 2026
Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.
0

'Turf War' Between Claude Agents Leads to Self-Replicating Malware

Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.
0

Adam Shostack Talks Hugging Face & PHANTOM-B

World-class threat modeler Adam Shostack shared he was "blown away" by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both "lightweight yet still usable."
0

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
0

Mission-Driven Security: Inside a Global Bank's Defense

Thứ Sáu, 14 tháng 8, 2026
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.
0

Amid AI-Driven Bug Tsunami, NIST Looks to…AI

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
0

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office

One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.
0

What Boards Need to Know About Tech Risk

Why do so many boards underestimate technology risk until it becomes a crisis?
0

Cyera's Oasis Security Buy is All About AI Agent Control

The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.
0

Global Threat Campaign Hits Critical VMware vCenter Flaw

Thứ Năm, 13 tháng 8, 2026
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
0

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
0

Belgium's eID Authentication Opens Citizen Accounts to RCE

The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
0

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

Thứ Tư, 12 tháng 8, 2026
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
0

Walmart's "Trusted Agent" Approach to Purple Teaming

Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
0

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
0

Walmart Leaders Transform Security Operations Without Going Bananas

The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.
0

Microsoft's Patch Tuesday Deluge Continues With August Updates

Thứ Ba, 11 tháng 8, 2026
Security experts say prioritization should be the main focus for the August updates, not the massive CVE volume.
0

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
0

Multistate Water System Attacks Widen, Iran Suspected

Thứ Hai, 10 tháng 8, 2026
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
0

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
0

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
0

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
0

Sherlock Holmes was the “OG” Social Engineer

The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers.
0

AI-Generated Patches Fail Half the Time

Thứ Sáu, 7 tháng 8, 2026
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
0

Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride

In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.
0

The Coordination Gap: How Attackers Are Outpacing Law Enforcement

Thứ Năm, 6 tháng 8, 2026
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
0

Researcher Claims Control of ChatGPT Secure Sandbox

A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.
0

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

Former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.
0

AI Sends Global Crime Syndicates Into Fraud Nirvana

Thứ Tư, 5 tháng 8, 2026
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
0

CSS: The Hidden Threat Lurking in Your Inbox

CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.
0

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
0

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.
0

Angola's Largest Telco Breached Hours Before IPO

Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.
0

Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

Thứ Ba, 4 tháng 8, 2026
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
0

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
0

New Tool Traces AI Videos Back to Their Source

Thứ Hai, 3 tháng 8, 2026
Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.
0

Anthropic: AI Attacks Result of Security Gaps, Not Model Issues

Last month's incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.
0

Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm

Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
0

Is There Really a Fix for CISO Fatigue?

Accountability without any real authority is driving CISO burnout, and organizations need to take notice.
0

Cybersecurity, Then & Now

Chủ Nhật, 2 tháng 8, 2026
Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.