
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.

Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.

Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.

The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises

Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.

The most concerning bug in the batch is CVE-2026-62878 (CVSS: 9.8), a remote code execution (RCE) vulnerability in Windows DNS Server that requires no user interaction.

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.

Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.

It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.

A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.

The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.

The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.

In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.

A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.

Two former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support — and a dose of absurdity.

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.

Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.

AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.

CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.

Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.

The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.

A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.

Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.

Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.

Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.

Last month's incidents in which the AI model breached real-world systems derived from over-permissioning, especially with Internet access.

Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.

Accountability without any real authority is driving CISO burnout, and organizations need to take notice.

A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.

The most valuable move any security team can make is building a certificate and key inventory.

When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.

Hundreds of thousands of California residents have already registered for the Delete Request and Opt-out Platform (DROP), which launches Aug. 1. Other states could follow if the process goes smoothly.

The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the...

A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.

A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.

In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?

The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.

A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.

Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.

OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.

The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.

Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of...