All Articles
Security Intelligence
3551 articles · Updated every 8 hours
Advertisement
AI's Impact on Vulnerability Discovery & Vendor Readiness
AI-driven vulnerability discovery is overwhelming software vendors, exposing secure-by-design failures and challenging traditional disclosure models.
CVE-2026-19490: Citrix NetScaler Auth Bypass Under Attack
Critical Citrix NetScaler authentication bypass (CVE-2026-19490) is actively exploited in the wild, allowing remote unprivileged access.
Recorded Future's Automated Signatures Combat AI Exploits
Recorded Future launches Automated Signature Creation to rapidly detect and prioritize vulnerabilities, closing the gap against AI-accelerated exploitation.
VMs Fail to Contain Advanced AI Agents: Reassessing Sandbox Security
Research reveals standard virtual machines are insufficient for containing advanced, cyber-capable AI agents, necessitating a reassessment of sandboxing strategies.
Automated AI Attacks Loom: Companies Must Prepare Now
Frontier AI models pose an urgent threat, capable of autonomous, end-to-end cyber compromises. Organizations have six months to prepare for these automated attacks.
Exchange Exploit, Dropbox Breach, & Cloud Phishing Campaigns
SecurityWeek's roundup highlights a critical Exchange Server exploit, Dropbox account compromises, and cloud phishing. Urgent action is advised.
Advertisement
IDScan Sued Over Alleged Breach Impacting 153 Million Drivers
IDScan faces lawsuits after a dark-web service allegedly offered to sell 153 million driver's licenses and millions of other identity documents.
Phishing Campaign Leverages Invisible Unicode to Bypass Filters
A high-volume phishing campaign uses invisible Unicode tag characters to evade email security filters, mimicking financial lures for fraud and credential harvesting.
AI Agents Install Untrusted Code: New Supply Chain Risk Identified
AI coding agents are installing untrusted code on corporate networks via llms.txt files pointing to abandoned domains, creating a supply chain risk.
Voting System Vulnerability: Ballot Order Correlation Risk
A voting system vulnerability, nearly four years old, enables ballot order recovery.
ShinyHunters: Dark Reading on Potential ReliaQuest Breach
Dark Reading editors discuss the latest activities of the ShinyHunters threat group, including inquiries into a potential breach affecting ReliaQuest.
CVE-2026-6471: PostgreSQL Takeover via Logical Decoding Flaw
CVE-2026-6471, a 12-year-old PostgreSQL vulnerability, allows attackers with low replication privileges to achieve RCE and full database server takeover.
Chrome Zero-Day CVE-2026-85046 Actively Exploited: Patch Now
Google released an urgent update for a critical Chrome zero-day, CVE-2026-85046, actively exploited in V8 engine type confusion attacks.
WordPress RCE Exploited via CVE-2026-14894 & CVE-2026-32475
Attackers exploit critical RCE flaws in WordPress Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) to deploy web shells and seize sites.
Cloudflare Enhances Vulnerability Management with AI & Context
Cloudflare introduces a new service leveraging AI and real-world operational context to prioritize and remediate vulnerabilities in customer codebases.
"Phantom Deal" M&A Scams Target Large Enterprises: Averting Financial Fraud
"Phantom Deal" M&A scams target large enterprises, leveraging detailed research and social engineering to trick employees into initiating fraudulent financial transfers.
Capsule Security Launches 'AI Circuit Breaker' for Rogue Agents
Capsule Security introduces an 'AI Circuit Breaker' to prevent autonomous AI agents from executing actions outside their intended scope in real-time.
French Hospital Fined €500K for GDPR Data Breach
France's CNIL fined Hôpital privé de la Loire €500,000 after a data breach exposed sensitive medical data of 727,000 patients.
Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends
Analysis of social engineering campaigns via Microsoft Teams, The Gentlemen ransomware operations, and emerging phishing-as-a-service kits.
H1 2026 Malware & Vulnerability Trends: AI Impact & Evasion
Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.
The AI Safety Penalty: How LLM Guardrails Hinder Defenders
Cisco Talos warns about the 'AI safety penalty,' where large language model guardrails impede legitimate defensive operations, giving attackers an advantage.
AI 'Machine Speed' Accelerates Cyberattacks to Hours
Researchers demonstrate how advanced AI agents can drastically reduce cyberattack timelines, compressing multi-week operations into mere hours.
Manchester Airports Group Data Leak Exposed by FulcrumSec Extortion
FulcrumSec leaks 550GB of data on 8.8 million individuals after Manchester Airports Group refused to pay a ransom demand following a breach.
CVE-2026-73749: HPE ArubaOS-CX RCE Flaw Patched
HPE patches a critical remote code execution flaw, CVE-2026-73749, in ArubaOS-CX switches. Unauthenticated attackers can exploit a buffer overflow.