darkreading
Please support the site operations by clicking ads.
[Virtual Event] Building a Secure AI Strategy for the Enterprise
3 weeks 5 days hence
Indonesia Hit by Android Banking App-Cloning Campaign
16 hours 59 minutes ago
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
Alexander Culafi
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
21 hours 23 minutes ago
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
Nate Nelson
Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
1 day 2 hours ago
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
Elizabeth Montalbano
EU Cyber Resilience Act to Enforce New Reporting Requirements
1 day 10 hours ago
Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.
Nate Nelson
Mythos Vulnerability Firehose Hits a Human Bottleneck
1 day 20 hours ago
An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.
Jai Vijayan
US Government Accuses Chinese AI Firms of Distilling Frontier Models
1 day 22 hours ago
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
Alexander Culafi
Identity-Based AI Attack Threatens Security of Enterprise Data
2 days 3 hours ago
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
Elizabeth Montalbano
Patch Tuesday Sets Another Record With 974 CVEs
2 days 20 hours ago
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
Jai Vijayan
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
2 days 20 hours ago
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Alexander Culafi
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
2 days 21 hours ago
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Nate Nelson
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
3 days ago
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Elizabeth Montalbano
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
3 days 5 hours ago
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Robert Lemos
Companies Have 6 Months to Prepare for Automated Attacks
1 week ago
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.
Robert Lemos
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
1 week ago
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Alexander Culafi
Insurers Search for Answers to Rein in Rogue AI
1 week ago
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Robert Lemos
Large Enterprises Targeted in Fake Merger & Acquisition Scams
1 week ago
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Nate Nelson
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
1 week ago
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
Rob Wright, Alexander Culafi
What the AI Warning Letter Completely Missed
1 week 1 day ago
The recent open letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
James Lyne
Checked
13 hours 54 minutes ago
Public RSS feed
darkreading feed