All Episodes
Security Stuff — 550 episodes
‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
How to Conduct a Successful Audit of AI-Driven Software Development
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Identity Lifecycle Management Wasn't Built for AI Agents
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
Massive Password Spray Campaign Targeting Azure CLI
Dawnguard Raises $6.3 Million for Security Architecture Automation Platform
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors
Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack
Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
Safe Events Start With Threat Intel and Digital Security
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
Nissan Employee Data Breached in Oracle PeopleSoft Hack
The AI Token Costs That Can Break Cybersecurity
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History
Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat
Aflac Japan Data Breach Impacts 4.38 Million
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
BlueHammer Vulnerability Exploited in Ransomware Attacks
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
What the Numbers Say About FIFA 2026 Cyber Risk
AI-Generated Workflows Are a Silent Security Disaster
OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review
‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access
Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
Chinese Framework Powers 200,000 Scam Sites
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
New Enterprise-Ready MCP Specification Brings New Security Challenges
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
$3 Million Reportedly Stolen in Polymarket Hack
Linux Foundation Unveils New Open Source Security Project Akrites
Nebulock Raises $25 Million for AI-Native Contextual Security
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Guardian Agents: The Next Layer of Identity Governance
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
Thanks for Crushing the Submissions Inbox. We're Trying to Keep Up
Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex
Chrome 149 Update Resolves 18 Severe Vulnerabilities
NIST Opens Updated IoT Security Guidance to Public Review
25-Year-Old Vulnerability Patched in Curl
GitLab Patches Code Execution, Information Disclosure Vulnerabilities
Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply
Runlayer Raises $30 Million in Series A Funding
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
Europe Evolves Into Ransomware's Favorite Region
Webinar Today: Modern Exposure Validation in the AI Era
BeyondTrust, LastPass Impacted by Klue-Salesforce Incident
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
New ‘Mistic’ RAT Opens Door to Several Ransomware Families
Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed
Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs
Third DraftKings Hacker Sentenced to 18 Months in Prison
macOS Weaknesses Chained to Silently Disable Endpoint Security Agents
DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
Dawn of the Apex Agentic Adversary
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Apple's MacOS Gap Lets Users Disable Security Tools
More Cybersecurity Firms Disclose Impact From Klue Hack
Fortinet Responds to FortiBleed Campaign
New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones
What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries
New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC
Cybersecurity Firms Impacted by Klue Supply Chain Attack
FortiBleed: 86,000 Fortinet Device Credentials Compromised
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
Forget Data Leakage: Shadow AI's Real Threat Is Access Control
From Assistive to Agentic: The AI Shift That's Redefining Threat Management
Stressors, AI Forcing Changes to Cybersecurity Teams
Kodak Admits Data Breach After ShinyHunters Hack Claims
SailPoint to Acquire Entro in Reported $200 Million Deal
F5 Patches Critical, High-Severity NGINX Vulnerabilities
Critical Command Execution Vulnerability Patched in Cisco ISE
Rokarolla Banking Trojan Targets 200 Applications
Atlassian, Splunk Patch Critical Vulnerabilities
Dream Raises $260 Million at $3 Billion Valuation
No Exploits Required
Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push
The Scripts on Your Checkout Page Are Now a PCI DSS Problem
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
EU Gets a Head Start in Developing 6G Network Security
Get Out of Security Debt by Tackling the Exposure Problem
Joomla, LiteSpeed Vulnerabilities Exploited in Attacks
Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities
Oracle’s Second Monthly Security Updates Deliver 245 Patches
Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software
Tenet Security Emerges From Stealth With $6 Million Seed Funding
1Password Acquires Apono in Reported $250M-$300M Deal
144 Mastra npm Packages Compromised via Hijacked Contributor Account
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
The Top 10 Attack Surface Exposures in 2026
Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization
UK Social Media Ban for Minors Has Privacy Experts Worried
Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices
Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure
Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
White House Issues Memo to Bolster NSS Cybersecurity
Cal Water Investigating Iranian Hackers’ Claims
Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire
Cybercrime Group Claims Novo Nordisk Hack
Endpoint Security Startup Ent Emerges From Stealth With $100 Million Seed Round
AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask
Magnitude Emerges From Stealth Mode With $10 Million in Funding
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Maine Disables Data Breach Portal Due to Fake Submissions
FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service
ShinyHunters Claims Council of Europe Hack
French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker
Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems
Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges
NewCore Emerges From Stealth Mode With $66 Million in Funding
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
The Onboarding Password Mistake That Creates Unnecessary Risk
US Cracks Down on Anthropic AI Models Amid Abuse Concerns
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Anthropic Disputes Fable 5 AI Jailbreak
Chrome 149 Update Patches 28 Vulnerabilities
Ivanti Sentry Exploitation Attempts Hitting Honeypots
Iranian Cyber Group Handala Claims Cal Water Hack
Industry Reactions to Claude Fable 5: Feedback Friday
INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
Rethinking MDR as Attackers and Defenders Embrace AI
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
Claude Fable 5 Doesn't Change the Mythos Security Story
University of Nottingham Confirms Breach After Hackers Leak Data
‘GreatXML’ Zero-Day Exploit Bypasses BitLocker
Splunk, Palo Alto Networks Patch Severe Vulnerabilities
FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers
Siemens Says Desigo CC Files Flagged as Malware by Security Engines
Hackers Exploit Langflow Vulnerability for Remote Code Execution
OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month
CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk
Alert Fatigue Is Becoming a Security Threat of Its Own
Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories
Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories
Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
Raising the Cybersecurity Stakes: Ante up for the Agentic Era
Gitea Vulnerability Exposed 30,000 Deployments to Attacks
New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails
IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”
Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks
New BTMOB Android Malware Enables Full Device Takeover
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
Nordic CISOs Handle Rising Cyber Threats Remarkably Well
Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security
FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data
LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers
GlassWorm Botnet Disrupted
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems
The Credential Crisis: How Stolen Credentials Defeat Modern Security
Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform
Romanian Hacker Sentenced to Prison in US for Selling Access to State Network
RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries
SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon Bay
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
Gitea Vulnerability Exposes Private Container Images without Authentication
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands
Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries
Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images
Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available
Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
Anthropic Expands Claude’s Enterprise Security Governance With 28 New Integrations
185,000 Likely Impacted by 7-Eleven Data Breach
Iranian APT Targets Aviation, Software Companies With Updated Tools
AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security
Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
MFA Prompt Bombing: Why Your Second Factor Isn't Saving You
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
[THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back
Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading
‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
TrendAI Patches Apex One Zero-Day Exploited in the Wild
‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested
Canadian Man Arrested for Operating Kimwolf Botnet
Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks
Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
China's Webworm Uses Discord, Microsoft Graphs to Hack EU Governments
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility
Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
Socket Raises $60 Million at $1 Billion Valuation
Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking
Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention
Ocean Emerges From Stealth With $28M for Agentic Email Security Platform
Cisco Patches Critical Vulnerability in Secure Workload
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
When Identity is the Attack Path
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories
Content Delivery Exploit Opens Websites to Brand Hijacking
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks
GitHub Confirms Hack Impacting 3,800 Internal Repositories
Virtual Event Today: Threat Detection & Incident Response Summit
Real-World ICS Security Tales From the Trenches
Caught Off Guard: Securing AI After It Hits Production
Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
Anthropic Silently Patches Claude Code Sandbox Bypass
1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem
GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos
Agent AI is Coming. Are You Ready?
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
Interpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle East
PoC Released for DirtyDecrypt Linux Kernel Vulnerability
201 Arrested in Crackdown on Cybercrime in Middle East, North Africa
Cyber Resilience is the New Business Continuity Plan
B1ack’s Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards
Unpatched ChromaDB Vulnerability Can Lead to Server Takeover
Legacy Windows Tool MSHTA Fuels Surge in Silent Malware Attacks
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
The New Phishing Click: How OAuth Consent Bypasses MFA
Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution
Exploitation of Critical NGINX Vulnerability Begins
Grafana Confirms Breach After Hackers Claim They Stole Data
First Shai-Hulud Worm Clones Emerge
Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE
7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand
‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery
Millions Impacted Across Several US Healthcare Data Breaches
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Developer Workstations Are Now Part of the Software Supply Chain
How to Reduce Phishing Exposure Before It Turns into Business Disruption
The Boring Stuff is Dangerous Now
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
PoC Code Published for Critical NGINX Vulnerability
Chrome 148 Update Patches Critical Vulnerabilities
TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code
OpenAI Hit by TanStack Supply Chain Attack
American Lending Center Data Breach Affects 123,000 Individuals
Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface
Cyber Pioneers Ponder Past as Prologue
Researcher Drops YellowKey, GreenPlasma Windows Zero-Days
High-Severity Vulnerability Patched in VMware Fusion
Hackers Targeted PraisonAI Vulnerability Hours After Disclosure
F5 Patches Over 50 Vulnerabilities
G7 Countries Release AI SBOM Guidance
Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns
Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million
Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere
New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation
How AI Hallucinations Are Creating Real Security Risks
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure
Foxconn Attack Highlights Manufacturing's Cyber Crisis
AI Drives Cybersecurity Investments, Widening 'Valley of Death'
Hundreds of Malicious Packages Force RubyGems to Suspend Registrations
Chipmaker Patch Tuesday: Intel and AMD Patch 70 Vulnerabilities
Fortinet, Ivanti Patch Critical Vulnerabilities
Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises
716,000 Impacted by OpenLoop Health Data Breach
Government to Scrutinize Instructure Over Canvas Disruption, Data Breach
Webinar Today: ROI for Cyber-Physical Security Programs
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws
Most Remediation Programs Never Confirm the Fix Actually Worked
[Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It)
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly
TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack
Is the SOC Obsolete, and We Just Haven’t Admitted It Yet?
Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means
SAP Patches Critical S/4HANA, Commerce Vulnerabilities
Apple Patches Dozens of Vulnerabilities in macOS, iOS
West Pharmaceutical Services Hit by Disruptive Ransomware Attack
Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform
Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
Why Agentic AI Is Security's Next Blind Spot
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
20 Leaders Who Built the CISO Era: 2 Decades of Change
Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested
New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks
Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
SailPoint Discloses GitHub Repository Hack
Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring
Skoda Data Breach Hits Online Shop Customers
Google Detects First AI-Generated Zero-Day Exploit
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Cyber Espionage Group Targets Aviation Firms to Steal Map Data
Hackers Use AI for Exploit Development, Attack Automation
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
Ransomware Group Takes Credit for Trellix Hack
‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials
Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom
AI Firm Braintrust Prompts API Key Rotation After Data Breach
Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants
New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials
One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities
MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs
Karakurt Ransomware Negotiator Sentenced to Prison
Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server
Critical Remote Code Execution Vulnerability Patched in Android
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft
Hacker Conversations: Joey Melo on Hacking AI
Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API
ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows
We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
How the Story of a USB Penetration Test Went Viral
Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats
Over 40,000 Servers Compromised in Ongoing cPanel Exploitation
OpenAI Rolls Out Advanced Security for ChatGPT Accounts
Exploitation of ‘Copy Fail’ Linux Vulnerability Begins
DigiCert Revokes Certificates After Support Portal Hack
Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
Trellix Source Code Repository Breached
Cisco Moves to Acquire Astrix Security to Tackle Non-Human Identity Risks
Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
2026: The Year of AI-Assisted Attacks
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
How Dark Reading Lifted Off the Launchpad in 2006
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
US Military Reaches Deals With 7 Tech Companies to Use Their AI on Classified Systems
New Bluekit Phishing Kit Features AI Assistant
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
FBI Warns of Surge in Hacker-Enabled Cargo Theft
Hugging Face, ClawHub Abused for Malware Distribution
Cisco Releases Open Source Tool for AI Model Provenance
Sophisticated Deep#Door Backdoor Enables Espionage, Disruption
Two US Security Experts Sentenced to Prison for Helping Ransomware Gang
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks
Top Five Sales Challenges Costing MSPs Cybersecurity Revenue
20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage
Name That Toon: Mark of (Security) Progress
Sandhills Medical Says Ransomware Breach Affects 170,000
‘Copy Fail’ Logic Flaw in Linux Kernel Enables System Takeover
Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
EnOcean SmartServer Flaws Expose Buildings to Remote Hacking
Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades
New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
Chrome 147, Firefox 150 Security Updates Rolling Out
38 Vulnerabilities Found in OpenEMR Medical Software
Iranian Cyber Group Handala Targets US Troops in Bahrain
Checkmarx Confirms Data Stolen in Supply Chain Attack
Hundreds of Internet-Facing VNC Servers Expose ICS/OT
Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately
What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)
Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
Alleged Chinese State Hacker Extradited to US
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
Spectrum Security Emerges From Stealth Mode With $19 Million
Germany Suspects Russia Is Behind Signal Phishing That Targeted Top Officials
No Patch for New PhantomRPC Privilege Escalation Technique in Windows
Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety
Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable
Dozens of Open VSX Extension Clones Linked to GlassWorm Malware
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
After Mythos: New Playbooks For a Zero-Window Era
Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About
Firefox Vulnerability Allows Tor User Fingerprinting
US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator
Easily Exploitable ‘Pack2TheRoot’ Linux Vulnerability Leads to Root Access
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
Energy and Water Management Firm Itron Hacked
Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years
Incomplete Windows Patch Opens Door to Zero-Click Attacks
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
Parsing Agentic Offensive Security's Existential Threat
20-Year-Old Malware Rewrites History of Cyber Sabotage
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments
Ransomware Hits Automotive Data Expert Autovista
Cisco Patches Critical Vulnerabilities in Webex, ISE
NIST Prioritizes NVD Enrichment for CVEs in CISA KEV, Critical Software
Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest
Splunk Enterprise Update Patches Code Execution Vulnerability
Artemis Emerges From Stealth With $70 Million in Funding
Data Breach at Tennessee Hospital Affects 337,000
Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu
Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment
ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories
Fortinet Patches Critical FortiSandbox Vulnerabilities
Trump Urges Extending Foreign Surveillance Program as Some Lawmakers Push for US Privacy Protections
$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks
Two Vulnerabilities Patched in Ivanti Neurons for ITSM
Mirax RAT Targeting Android Users in Europe
Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities
Microsoft, Salesforce Patch AI Agent Data Leak Flaws
Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities
Nightclub Giant RCI Hospitality Reports Data Breach
Google Adds Rust DNS Parser to Pixel Phones for Better Security
Triad Nexus Evades Sanctions to Fuel Cybercrime
SAP Patches Critical ABAP Vulnerability
Europe’s Largest Gym Chain Says Data Breach Impacts 1 Million Members
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users
Fake Claude Website Distributes PlugX RAT
CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads
International Operation Targets Multimillion-Dollar Crypto Theft Schemes
OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
Your MTTD Looks Great. Your Post-Alert Gap Doesn't
Your Next Breach Will Look Like Business as Usual
Hims Breach Exposes the Most Sensitive Kinds of PHI
Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users
Google Rolls Out Cookie Theft Protections in Chrome
Critical Marimo Flaw Exploited Hours After Public Disclosure
MITRE Releases Fight Fraud Framework
Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000
Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday
Juniper Networks Patches Dozens of Junos OS Vulnerabilities
In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
Can Anthropic Keep Its Exploit-Writing AI Out of the Wrong Hands?
Industrial Controllers Still Vulnerable As Conflicts Move to Cyber
Orange Business Reimagines Enterprise Voice Communications With Trust and AI
FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats
300,000 People Impacted by Eurail Data Breach
Adobe Reader Zero-Day Exploited for Months: Researcher
Google Warns of New Campaign Targeting BPOs to Steal Corporate Data
The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security
Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities
Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access
Can we Trust AI? No – But Eventually We Must
Apple Intelligence AI Guardrails Bypassed in New Attack
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
The Hidden Security Risks of Shadow AI in Enterprises
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks
US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking
Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover
Evasive Masjesu DDoS Botnet Targets IoT Devices
Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption
FBI: Cybercrime Losses Neared $21 Billion in 2025
RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years
Data Leakage Vulnerability Patched in OpenSSL
Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs
N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust
Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
Iranian Threat Actors Disrupt US Critical Infrastructure Via Exposed PLCs
Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams
Niobium Introduces The Fog
Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus
Fraud Rockets Higher in Mobile-First Latin America
AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties
Threat Actors Get Crafty With Emojis to Escape Detection
Russia's Forest Blizzard Nabs Rafts of Logins Via SOHO Routers