Cybersecurity news & advisories
Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
Researchers say they have discovered thousands of malicious software packages uploaded to an online public software repository that were left by a “swarm” of OpenAI agents. According to an incident timeline published…
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
Beginning next month, if a flight is canceled or delayed because of a cyberattack, feds will give airlines clearance not to hand out meal vouchers or hotels. The change is the result of a broader rule the Transportation…
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police…
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
GitLab’s critical flaw is already drawing internet-wide probes
GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already…
Microsoft sees some new wrinkles in invoice-scam emails
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
Why AI Is So Good at Scamming Humans
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
My Talk at DEF CON
Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI…
More JFrog Artifactory bugs under attack, and all 3 have patches
JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor…
Behind the Blog: How to Talk About AI Doom
This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss AI doomers, 9/11 posting, and Barbie. JOSEPH: I do always get…
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from…
Phishing Research Challenges Conventional Security Awareness Testing
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.
AI Governance Can't Wait
Adversaries can manipulate AI defensive reasoning to silently compromise target networks.
Automattic’s Matt Mullenweg Claims He’s Back 'In Control'
Less than 48 hours after announcing he was forcibly placed on a leave of absence by the Automattic board on Wednesday, Automattic’s Matt Mullenweg posted in a company-wide Slack channel claiming that he’s back “in…
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.
GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.
Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software…
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
Crypto customers targeted by scammers after email marketing provider breach
An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident…
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating…
Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis
Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a safety-sensitive request inside an otherwise ordinary script comment…
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.
New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then…
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude…