Attention: You are using an outdated browser, device or you do not have the latest version of JavaScript downloaded and so this website may not work as expected. Please download the latest software or switch device to avoid further issues.
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings. More...
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while disp… More...
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform ta… More...
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR to… More...
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation. More...
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large fin… More...
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over … More...
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Te… More...
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls. More...
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer. More...
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk. More...
The new AI security controls follow the Hugging Face incident last month, though experts say many of these additions should have been in place prior t… More...
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-194… More...
A spear-phishing campaign by a China-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by … More...
The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should thes… More...
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face. More...
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. More...
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. More...
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. More...
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors. More...
Ernst & Young has begun notifying clients of a data breach after an attacker compromised a third-party support platform and downloaded documents conta… More...