Skip to content

Cybersecurity news & advisories

47 / 47 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated 11 Sep 2026 18:52 UTC
Trending News CyberScoop

GitLab’s critical flaw is already drawing internet-wide probes

Vuln

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already…

↗ Open article
News Dark Reading

Why AI Is So Good at Scamming Humans

Research

Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.

↗ Open article
Media Schneier on Security

My Talk at DEF CON

Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI…

↗ Open article
News The Register Security

More JFrog Artifactory bugs under attack, and all 3 have patches

Vuln

JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor…

↗ Open article
News 404 Media

Behind the Blog: How to Talk About AI Doom

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss AI doomers, 9/11 posting, and Barbie. JOSEPH: I do always get…

↗ Open article
Trending News Bleeping Computer

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Ransom Phishing Breach

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from…

↗ Open article
News 404 Media

Automattic’s Matt Mullenweg Claims He’s Back 'In Control'

Less than 48 hours after announcing he was forcibly placed on a leave of absence by the Automattic board on Wednesday, Automattic’s Matt Mullenweg posted in a company-wide Slack channel claiming that he’s back “in…

↗ Open article
Trending News The Hacker News

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Vuln

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is…

↗ Open article
News The Hacker News

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax…

↗ Open article
Advisory Cisco Security Advisories

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software…

↗ Open article
Threat Intel Malwarebytes Labs

Crypto customers targeted by scammers after email marketing provider breach

Breach Crypto

An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident…

↗ Open article
Research SANS Internet Storm Center

The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating…

↗ Open article
News Cyber Security News

Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis

Malware

Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a safety-sensitive request inside an otherwise ordinary script comment…

↗ Open article
News The Hacker News

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Vuln Breach APT

Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The…

↗ Open article
Trending News Cyber Security News

New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks

Vuln Malware DoS

KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then…

↗ Open article
News The Hacker News

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Malware APT

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has…

↗ Open article
News Bleeping Computer

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Malware

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude…

↗ Open article
Podcast Hak5

I Read OpenAI’s Hacking Report. The Implications Are Alarming | Threat Wire

What happens when AI agents being tested for cybersecurity start finding their own way out—and begin sharing what they learn? Ali Diamond breaks down OpenAI’s 38-page report on its internal AI agents, JFrog Artifactory…

↗ Open article
News 404 Media

‘We Did Not Invite You.’ Citizens Rage at Town Hall Over Proposed Nuclear AI Data Center

Representatives from the University of Michigan faced tough questions and a lot of vitriol from the citizens of Ypsilanti Township Wednesday night. The University partnered with America’s nuclear weapons scientists at…

↗ Open article
News Cyber Security News

Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a malicious attachment or software flaw. Instead, it used ordinary…

↗ Open article
Trending Research Rapid7 Blog

Metasploit Wrap Up: This One Goes to Sixteen!

Vuln

This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit…

↗ Open article
Research Rapid7 Blog

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized…

↗ Open article
Trending News Cyber Security News

Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections

Vuln

Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8. Administrators who can reproduce the failure…

↗ Open article
News Cyber Security News

Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide

Ransom Breach

A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation , which compromised more than 1,000 victims worldwide and generated at least $150 million in ransom…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.