All Episodes

Security Stuff — 550 episodes

#
Title
1

‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials

2

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

3

Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm

4

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks

5

How to Conduct a Successful Audit of AI-Driven Software Development

6

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

7

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

8

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

9

Identity Lifecycle Management Wasn't Built for AI Agents

10

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

11

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

12

Massive Password Spray Campaign Targeting Azure CLI

13

Dawnguard Raises $6.3 Million for Security Architecture Automation Platform

14

Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari

15

Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors

16

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

17

Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities

18

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

19

Microsoft Accelerates Post-Quantum Cryptography Shift to 2029

20

2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

21

Safe Events Start With Threat Intel and Digital Security

22

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

23

Nissan Employee Data Breached in Oracle PeopleSoft Hack

24

The AI Token Costs That Can Break Cybersecurity

25

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

26

Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History

27

Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat

28

Aflac Japan Data Breach Impacts 4.38 Million

29

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

30

BlueHammer Vulnerability Exploited in Ransomware Attacks

31

Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

32

New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

33

AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

34

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

35

What the Numbers Say About FIFA 2026 Cyber Risk

36

AI-Generated Workflows Are a Silent Security Disaster

37

OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI

38

US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve

39

OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review

40

‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access

41

Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack

42

Chinese Framework Powers 200,000 Scam Sites

43

OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards

44

New Enterprise-Ready MCP Specification Brings New Security Challenges

45

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

46

Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

47

$3 Million Reportedly Stolen in Polymarket Hack

48

Linux Foundation Unveils New Open Source Security Project Akrites

49

Nebulock Raises $25 Million for AI-Native Contextual Security

50

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

51

Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff

52

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

53

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

54

Guardian Agents: The Next Layer of Identity Governance

55

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

56

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

57

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

58

Thanks for Crushing the Submissions Inbox. We're Trying to Keep Up

59

Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex

60

Chrome 149 Update Resolves 18 Severe Vulnerabilities

61

NIST Opens Updated IoT Security Guidance to Public Review

62

25-Year-Old Vulnerability Patched in Curl

63

GitLab Patches Code Execution, Information Disclosure Vulnerabilities

64

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

65

Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply

66

Runlayer Raises $30 Million in Series A Funding

67

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

68

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

69

Surviving the Mythos Era: Richard Bejtlich on the Case for NDR

70

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

71

Europe Evolves Into Ransomware's Favorite Region

72

Webinar Today: Modern Exposure Validation in the AI Era

73

BeyondTrust, LastPass Impacted by Klue-Salesforce Incident

74

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking

75

New ‘Mistic’ RAT Opens Door to Several Ransomware Families

76

Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed

77

Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs

78

Third DraftKings Hacker Sentenced to 18 Months in Prison

79

macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

80

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering

81

Dawn of the Apex Agentic Adversary

82

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

83

Apple's MacOS Gap Lets Users Disable Security Tools

84

More Cybersecurity Firms Disclose Impact From Klue Hack

85

Fortinet Responds to FortiBleed Campaign

86

New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones

87

What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks

88

North Korean Hackers Blamed for Mastra NPM Supply Chain Attack

89

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

90

Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

91

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

92

⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More

93

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

94

Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries

95

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

96

French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

97

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

98

Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

99

Cybersecurity Firms Impacted by Klue Supply Chain Attack

100

FortiBleed: 86,000 Fortinet Device Credentials Compromised

101

CryptoBandits Malware Doubles as a Backdoor, Abuses Tor

102

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

103

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

104

From Assistive to Agentic: The AI Shift That's Redefining Threat Management

105

Stressors, AI Forcing Changes to Cybersecurity Teams

106

Kodak Admits Data Breach After ShinyHunters Hack Claims

107

SailPoint to Acquire Entro in Reported $200 Million Deal

108

F5 Patches Critical, High-Severity NGINX Vulnerabilities

109

Critical Command Execution Vulnerability Patched in Cisco ISE

110

Rokarolla Banking Trojan Targets 200 Applications

111

Atlassian, Splunk Patch Critical Vulnerabilities

112

Dream Raises $260 Million at $3 Billion Valuation

113

No Exploits Required

114

Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push

115

The Scripts on Your Checkout Page Are Now a PCI DSS Problem

116

Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network

117

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

118

EU Gets a Head Start in Developing 6G Network Security

119

Get Out of Security Debt by Tackling the Exposure Problem

120

Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

121

Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities

122

Oracle’s Second Monthly Security Updates Deliver 245 Patches

123

Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day

124

Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

125

Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software

126

Tenet Security Emerges From Stealth With $6 Million Seed Funding

127

1Password Acquires Apono in Reported $250M-$300M Deal

128

144 Mastra npm Packages Compromised via Hijacked Contributor Account

129

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

130

The Top 10 Attack Surface Exposures in 2026

131

Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization

132

UK Social Media Ban for Minors Has Privacy Experts Worried

133

Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices

134

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure

135

Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models

136

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

137

White House Issues Memo to Bolster NSS Cybersecurity

138

Cal Water Investigating Iranian Hackers’ Claims

139

Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire

140

Cybercrime Group Claims Novo Nordisk Hack

141

Endpoint Security Startup Ent Emerges From Stealth With $100 Million Seed Round

142

AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask

143

Magnitude Emerges From Stealth Mode With $10 Million in Funding

144

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

145

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

146

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

147

Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive

148

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

149

Maine Disables Data Breach Portal Due to Fake Submissions

150

FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service

151

ShinyHunters Claims Council of Europe Hack

152

French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker

153

Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems

154

Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

155

NewCore Emerges From Stealth Mode With $66 Million in Funding

156

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

157

152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic

158

The Onboarding Password Mistake That Creates Unnecessary Risk

159

US Cracks Down on Anthropic AI Models Amid Abuse Concerns

160

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

161

Anthropic Disputes Fable 5 AI Jailbreak

162

Chrome 149 Update Patches 28 Vulnerabilities

163

Ivanti Sentry Exploitation Attempts Hitting Honeypots

164

Iranian Cyber Group Handala Claims Cal Water Hack

165

Industry Reactions to Claude Fable 5: Feedback Friday

166

INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator

167

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

168

Rethinking MDR as Attackers and Defenders Embrace AI

169

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

170

Claude Fable 5 Doesn't Change the Mythos Security Story

171

University of Nottingham Confirms Breach After Hackers Leak Data

172

‘GreatXML’ Zero-Day Exploit Bypasses BitLocker

173

Splunk, Palo Alto Networks Patch Severe Vulnerabilities

174

FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers

175

Siemens Says Desigo CC Files Flagged as Malware by Security Engines

176

Hackers Exploit Langflow Vulnerability for Remote Code Execution

177

OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month

178

CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk

179

Alert Fatigue Is Becoming a Security Threat of Its Own

180

Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks

181

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack

182

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

183

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories

184

Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories

185

Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks

186

Raising the Cybersecurity Stakes: Ante up for the Agentic Era

187

Gitea Vulnerability Exposed 30,000 Deployments to Attacks

188

New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails

189

IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”

190

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

191

New BTMOB Android Malware Enables Full Device Takeover

192

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

193

New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"

194

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

195

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

196

Nordic CISOs Handle Rising Cyber Threats Remarkably Well

197

Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security

198

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

199

LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers

200

GlassWorm Botnet Disrupted

201

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

202

The Credential Crisis: How Stolen Credentials Defeat Modern Security

203

Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform

204

Romanian Hacker Sentenced to Prison in US for Selling Access to State Network

205

RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries

206

SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon Bay

207

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

208

Gitea Vulnerability Exposes Private Container Images without Authentication

209

5 Steps to Managing Shadow AI Tools Without Slowing Down Employees

210

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

211

Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security

212

Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands

213

Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries

214

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images

215

Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available

216

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

217

Anthropic Expands Claude’s Enterprise Security Governance With 28 New Integrations

218

185,000 Likely Impacted by 7-Eleven Data Breach

219

Iranian APT Targets Aviation, Software Companies With Updated Tools

220

AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security

221

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

222

CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

223

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

224

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

225

[THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back

226

Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading

227

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

228

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

229

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

230

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

231

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

232

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

233

TrendAI Patches Apex One Zero-Day Exploited in the Wild

234

‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested

235

Canadian Man Arrested for Operating Kimwolf Botnet

236

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

237

Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective

238

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

239

China's Webworm Uses Discord, Microsoft Graphs to Hack EU Governments

240

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

241

Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI

242

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

243

Socket Raises $60 Million at $1 Billion Valuation

244

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking

245

Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

246

Ocean Emerges From Stealth With $28M for Agentic Email Security Platform

247

Cisco Patches Critical Vulnerability in Secure Workload

248

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

249

When Identity is the Attack Path

250

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

251

ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

252

Content Delivery Exploit Opens Websites to Brand Hijacking

253

Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks

254

GitHub Confirms Hack Impacting 3,800 Internal Repositories

255

Virtual Event Today: Threat Detection & Incident Response Summit

256

Real-World ICS Security Tales From the Trenches

257

Caught Off Guard: Securing AI After It Hits Production

258

Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack

259

Anthropic Silently Patches Claude Code Sandbox Bypass

260

1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials

261

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

262

Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem

263

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

264

Agent AI is Coming. Are You Ready?

265

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

266

Interpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle East

267

PoC Released for DirtyDecrypt Linux Kernel Vulnerability

268

201 Arrested in Crackdown on Cybercrime in Middle East, North Africa

269

Cyber Resilience is the New Business Continuity Plan

270

B1ack’s Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards

271

Unpatched ChromaDB Vulnerability Can Lead to Server Takeover

272

Legacy Windows Tool MSHTA Fuels Surge in Silent Malware Attacks

273

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

274

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

275

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

276

The New Phishing Click: How OAuth Consent Bypasses MFA

277

Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution

278

Exploitation of Critical NGINX Vulnerability Begins

279

Grafana Confirms Breach After Hackers Claim They Stole Data

280

First Shai-Hulud Worm Clones Emerge

281

Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE

282

7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand

283

‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery

284

Millions Impacted Across Several US Healthcare Data Breaches

285

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

286

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

287

Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws

288

Developer Workstations Are Now Part of the Software Supply Chain

289

How to Reduce Phishing Exposure Before It Turns into Business Disruption

290

The Boring Stuff is Dangerous Now

291

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

292

PoC Code Published for Critical NGINX Vulnerability

293

Chrome 148 Update Patches Critical Vulnerabilities

294

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code

295

OpenAI Hit by TanStack Supply Chain Attack

296

American Lending Center Data Breach Affects 123,000 Individuals

297

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

298

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

299

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

300

Cyber Pioneers Ponder Past as Prologue

301

Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

302

High-Severity Vulnerability Patched in VMware Fusion

303

Hackers Targeted PraisonAI Vulnerability Hours After Disclosure

304

F5 Patches Over 50 Vulnerabilities

305

G7 Countries Release AI SBOM Guidance

306

Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns

307

Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million

308

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere

309

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation

310

New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

311

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

312

How AI Hallucinations Are Creating Real Security Risks

313

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

314

Foxconn Attack Highlights Manufacturing's Cyber Crisis

315

AI Drives Cybersecurity Investments, Widening 'Valley of Death'

316

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

317

Chipmaker Patch Tuesday: Intel and AMD Patch 70 Vulnerabilities

318

Fortinet, Ivanti Patch Critical Vulnerabilities

319

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

320

716,000 Impacted by OpenLoop Health Data Breach

321

Government to Scrutinize Instructure Over Canvas Disruption, Data Breach

322

Webinar Today: ROI for Cyber-Physical Security Programs

323

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data

324

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

325

Most Remediation Programs Never Confirm the Fix Actually Worked

326

[Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It)

327

Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

328

Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

329

China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm

330

LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly

331

TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

332

Is the SOC Obsolete, and We Just Haven’t Admitted It Yet?

333

Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means

334

SAP Patches Critical S/4HANA, Commerce Vulnerabilities

335

Apple Patches Dozens of Vulnerabilities in macOS, iOS

336

West Pharmaceutical Services Hit by Disruptive Ransomware Attack

337

Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform

338

Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware

339

Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak

340

Why Agentic AI Is Security's Next Blind Spot

341

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

342

Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help

343

New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

344

20 Leaders Who Built the CISO Era: 2 Decades of Change

345

Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested

346

New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks

347

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools

348

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

349

SailPoint Discloses GitHub Repository Hack

350

Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring

351

Skoda Data Breach Hits Online Shop Customers

352

Google Detects First AI-Generated Zero-Day Exploit

353

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

354

Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room

355

⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

356

Cyber Espionage Group Targets Aviation Firms to Steal Map Data

357

Hackers Use AI for Exploit Development, Attack Automation

358

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

359

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

360

Ransomware Group Takes Credit for Trellix Hack

361

‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials

362

Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom

363

AI Firm Braintrust Prompts API Key Rotation After Data Breach

364

Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants

365

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

366

One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk

367

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

368

WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities

369

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs

370

Karakurt Ransomware Negotiator Sentenced to Prison

371

Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server

372

Critical Remote Code Execution Vulnerability Patched in Android

373

Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft

374

Hacker Conversations: Joey Melo on Hacking AI

375

Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

376

ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows

377

We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is

378

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

379

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

380

How the Story of a USB Penetration Test Went Viral

381

Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats

382

Over 40,000 Servers Compromised in Ongoing cPanel Exploitation

383

OpenAI Rolls Out Advanced Security for ChatGPT Accounts

384

Exploitation of ‘Copy Fail’ Linux Vulnerability Begins

385

DigiCert Revokes Certificates After Support Portal Hack

386

Cybersecurity M&A Roundup: 33 Deals Announced in April 2026

387

Trellix Source Code Repository Breached

388

Cisco Moves to Acquire Astrix Security to Tackle Non-Human Identity Risks

389

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks

390

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia

391

2026: The Year of AI-Assisted Attacks

392

⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More

393

Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

394

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

395

How Dark Reading Lifted Off the Launchpad in 2006

396

Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia

397

Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability

398

US Military Reaches Deals With 7 Tech Companies to Use Their AI on Classified Systems

399

New Bluekit Phishing Kit Features AI Assistant

400

1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom

401

FBI Warns of Surge in Hacker-Enabled Cargo Theft

402

Hugging Face, ClawHub Abused for Malware Distribution

403

Cisco Releases Open Source Tool for AI Model Provenance

404

Sophisticated Deep#Door Backdoor Enables Espionage, Disruption

405

Two US Security Experts Sentenced to Prison for Helping Ransomware Gang

406

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

407

Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks

408

Top Five Sales Challenges Costing MSPs Cybersecurity Revenue

409

20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage

410

Name That Toon: Mark of (Security) Progress

411

Sandhills Medical Says Ransomware Breach Affects 170,000

412

‘Copy Fail’ Logic Flaw in Linux Kernel Enables System Takeover

413

Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months

414

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

415

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks

416

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

417

New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions

418

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

419

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

420

Oracle Red Bull Racing Team Revs Up Automation to Boost Security

421

Chrome 147, Firefox 150 Security Updates Rolling Out

422

38 Vulnerabilities Found in OpenEMR Medical Software

423

Iranian Cyber Group Handala Targets US Troops in Bahrain

424

Checkmarx Confirms Data Stolen in Supply Chain Attack

425

Hundreds of Internet-Facing VNC Servers Expose ICS/OT

426

Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure

427

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

428

Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately

429

What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)

430

Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

431

Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities

432

Alleged Chinese State Hacker Extradited to US

433

VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi

434

Spectrum Security Emerges From Stealth Mode With $19 Million

435

Germany Suspects Russia Is Behind Signal Phishing That Targeted Top Officials

436

No Patch for New PhantomRPC Privilege Escalation Technique in Windows

437

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety

438

Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable

439

Dozens of Open VSX Extension Clones Linked to GlassWorm Malware

440

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks

441

After Mythos: New Playbooks For a Zero-Window Era

442

Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

443

Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About

444

Firefox Vulnerability Allows Tor User Fingerprinting

445

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator

446

Easily Exploitable ‘Pack2TheRoot’ Linux Vulnerability Leads to Root Access

447

UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware

448

Energy and Water Management Firm Itron Hacked

449

Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google

450

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years

451

Incomplete Windows Patch Opens Door to Zero-Click Attacks

452

Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware

453

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks

454

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

455

⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

456

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

457

Parsing Agentic Offensive Security's Existential Threat

458

20-Year-Old Malware Rewrites History of Cyber Sabotage

459

Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation

460

Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments

461

Ransomware Hits Automotive Data Expert Autovista

462

Cisco Patches Critical Vulnerabilities in Webex, ISE

463

NIST Prioritizes NVD Enrichment for CVEs in CISA KEV, Critical Software

464

Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest

465

Splunk Enterprise Update Patches Code Execution Vulnerability

466

Artemis Emerges From Stealth With $70 Million in Funding

467

Data Breach at Tennessee Hospital Affects 337,000

468

Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu

469

Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

470

Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution

471

[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment

472

ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories

473

Fortinet Patches Critical FortiSandbox Vulnerabilities

474

Trump Urges Extending Foreign Surveillance Program as Some Lawmakers Push for US Privacy Protections

475

$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks

476

Two Vulnerabilities Patched in Ivanti Neurons for ITSM

477

Mirax RAT Targeting Android Users in Europe

478

Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities

479

Microsoft, Salesforce Patch AI Agent Data Leak Flaws

480

Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities

481

Nightclub Giant RCI Hospitality Reports Data Breach

482

Google Adds Rust DNS Parser to Pixel Phones for Better Security

483

Triad Nexus Evades Sanctions to Fuel Cybercrime

484

SAP Patches Critical ABAP Vulnerability

485

Europe’s Largest Gym Chain Says Data Breach Impacts 1 Million Members

486

108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

487

Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)

488

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads

489

Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users

490

Fake Claude Website Distributes PlugX RAT

491

CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads

492

International Operation Targets Multimillion-Dollar Crypto Theft Schemes

493

OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack

494

North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware

495

Your MTTD Looks Great. Your Post-Alert Gap Doesn't

496

Your Next Breach Will Look Like Business as Usual

497

Hims Breach Exposes the Most Sensitive Kinds of PHI

498

Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users

499

Google Rolls Out Cookie Theft Protections in Chrome

500

Critical Marimo Flaw Exploited Hours After Public Disclosure

501

MITRE Releases Fight Fraud Framework

502

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000

503

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

504

Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday

505

Juniper Networks Patches Dozens of Junos OS Vulnerabilities

506

In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack

507

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

508

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

509

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

510

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

511

Can Anthropic Keep Its Exploit-Writing AI Out of the Wrong Hands?

512

Industrial Controllers Still Vulnerable As Conflicts Move to Cyber

513

Orange Business Reimagines Enterprise Voice Communications With Trust and AI

514

FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats

515

300,000 People Impacted by Eurail Data Breach

516

Adobe Reader Zero-Day Exploited for Months: Researcher

517

Google Warns of New Campaign Targeting BPOs to Steal Corporate Data

518

The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security

519

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities

520

Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access

521

Can we Trust AI? No – But Eventually We Must

522

Apple Intelligence AI Guardrails Bypassed in New Attack

523

Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region

524

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

525

The Hidden Security Risks of Shadow AI in Enterprises

526

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

527

Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks

528

US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking

529

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover

530

Evasive Masjesu DDoS Botnet Targets IoT Devices

531

Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption

532

FBI: Cybercrime Losses Neared $21 Billion in 2025

533

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

534

Data Leakage Vulnerability Patched in OpenSSL

535

Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long

536

Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs

537

N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust

538

Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems

539

Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

540

APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

541

Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

542

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

543

Iranian Threat Actors Disrupt US Critical Infrastructure Via Exposed PLCs

544

Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams

545

Niobium Introduces The Fog

546

Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus

547

Fraud Rockets Higher in Mobile-First Latin America

548

AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties

549

Threat Actors Get Crafty With Emojis to Escape Detection

550

Russia's Forest Blizzard Nabs Rafts of Logins Via SOHO Routers