access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison
Lytvynenko Admitted Developing Malware and Stealing Data for Conti. A U.S. court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison after he admitted developing malware and stealing data for Conti, the ransomware operation blamed for more than 1,000 victims and $150 million in payments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ukrainian-conti-ransomware-developer-gets-4-years-in-us-prison-a-32805 also…
-
Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks
Threat Report Finds Multi-Agent Tools Let Less-Skilled Actors Scale Complex Operations. Anthropic’s Threat Intelligence team identified a series of attempted attacks using its AI systems by malicious actors. The report focuses not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources. First…
-
Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks
Threat Report Finds Multi-Agent Tools Let Less-Skilled Actors Scale Complex Operations. Anthropic’s Threat Intelligence team identified a series of attempted attacks using its AI systems by malicious actors. The report focuses not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources. First…
-
Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks
Threat Report Finds Multi-Agent Tools Let Less-Skilled Actors Scale Complex Operations. Anthropic’s Threat Intelligence team identified a series of attempted attacks using its AI systems by malicious actors. The report focuses not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources. First…
-
Cylake Gets $245M to Build Cloud-Free Cybersecurity Platform
Nir Zuk’s Startup Targets Firms Unable to Send Sensitive Security Data to the Cloud. Cylake, led by Palo Alto Networks founder Nir Zuk, raised $245 million to build an on-premises cybersecurity system combining hardware, storage, security software and local AI for regulated organizations that can’t send sensitive data to external clouds. First seen on govinfosecurity.com…
-
ID Verification Firm IDScan.net Confirms Data Breach
IDScan.net Confirms Breach – But Leaves Victim Count and Point of Entry Unanswered. A Louisiana identity verification company has confirmed a breach reportedly tied to the darkweb sale of more than 153 million U.S. and Canadian driver’s licenses, but its notice does not say how many people were affected or how attackers got in. First…
-
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. First seen on cyberscoop.com Jump to article: cyberscoop.com/dot-rule-airline-cyberattack-flight-delays/ also interesting: HHS Office for Civil Rights Proposes Measures to Strengthen Cybersecurity in Health Care Under HIPAA UK Cybersecurity Weekly News…
-
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors Top 10 Cybersecurity Predictions for 2026 Cybersecurity Snapshot:…
-
AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech
Tags: aiSee what you missed in Daily Tech Insider from Sept. 711. The post AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/ai-agents-foldables-cyberthreats-and-chip-deals-define-this-week-in-tech/ also interesting: RSAC: Researchers Share Lessons from the World’s First AI Security Incident Response Team Sysdig führt AI…
-
ISMG Editors: Can Humans Still Keep AI Agents in Check?
Also: AI Agents Breathe New Life in Zero Trust, OpenAI’s Chip Puts Nvidia on Notice. In this week’s panel, four ISMG editors discussed the growing challenge of keeping human beings in control of AI agents, what security leaders are saying about AI and cloud risk, and whether OpenAI’s new chip could pose a serious challenge…
-
FTC rescinds policy statement requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/ also interesting: Prudential Financial data breach impacted over 2.5 million individuals Massive NBI Data Breach Exposes Millions of Users Records Online…
-
FTC rescinds policy statement requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/ also interesting: Prudential Financial data breach impacted over 2.5 million individuals Massive NBI Data Breach Exposes Millions of Users Records Online…
-
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer’s personal device. First seen on therecord.media Jump to article: therecord.media/florida-shiny-hunters-motor-vehicle also interesting: Romanian elections targeted with cyberattacks by foreign state-sponsored actors Cybersecurity Snapshot: Study Raises Open…
-
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days also interesting: Operation Endgame 2.0: DanaBusted Top 10 Cybersecurity Predictions for 2026 13 ways attackers use generative AI to exploit your systems 13 ways attackers use generative AI…
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/ also interesting: What is Security Posture Management and Why is it Important? What…
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/ also interesting: What is Security Posture Management and Why is it Important? What…
-
US lawmakers call for UK court to lift secrecy over Apple ‘backdoor’ surveillance
Congress warns that the UK’s unprecedented secrecy over a ‘backdoor’ surveillance order against Apple is straining relations between the two countries First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650365/US-lawmakers-call-for-UK-court-to-lift-secrecy-over-Apple-backdoor-surveillance also interesting: Apple pulls iCloud endend encryption feature for UK users after government demanded backdoor Apple encryption row: Does law enforcement need to use Technical Capability…
-
US lawmakers call for UK court to lift secrecy over Apple ‘backdoor’ surveillance
Congress warns that the UK’s unprecedented secrecy over a ‘backdoor’ surveillance order against Apple is straining relations between the two countries First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650365/US-lawmakers-call-for-UK-court-to-lift-secrecy-over-Apple-backdoor-surveillance also interesting: macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users Apple withdraws encrypted iCloud storage from UK after government demands ‘backdoor’ access 6…
-
US lawmakers call for UK court to lift secrecy over Apple ‘backdoor’ surveillance
Congress warns that the UK’s unprecedented secrecy over a ‘backdoor’ surveillance order against Apple is straining relations between the two countries First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650365/US-lawmakers-call-for-UK-court-to-lift-secrecy-over-Apple-backdoor-surveillance also interesting: macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users Apple withdraws encrypted iCloud storage from UK after government demands ‘backdoor’ access 6…
-
US lawmakers call for UK court to lift secrecy over Apple ‘backdoor’ surveillance
Congress warns that the UK’s unprecedented secrecy over a ‘backdoor’ surveillance order against Apple is straining relations between the two countries First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650365/US-lawmakers-call-for-UK-court-to-lift-secrecy-over-Apple-backdoor-surveillance also interesting: macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users Apple withdraws encrypted iCloud storage from UK after government demands ‘backdoor’ access 6…
-
Report Surfaces Attacks Are Aimed at Narrow Range of Edge Computing Devices
SentinelOne and Tenable have released a joint report that suggests that both state-sponsored actors and ransomware operators are squarely focused on specific edge computing platforms that have a small set of high-severity vulnerabilities that are being regularly exploited. Luke Tamagna-Darr, vice president of research at Tenable, said that pattern suggests cybersecurity teams should prioritize those..…
-
Why AI Is So Good at Scamming Humans
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-scamming-humans also interesting: Meta and YouTube Update Their AI Content Policies Snapchat Revises AI Privacy Policy Following UK…
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate also interesting: Cybersecurity Snapshot: Prompt Injection and Data Disclosure Top OWASP’s List of Cyber Risks for GenAI LLM Apps Cybersecurity Snapshot: Expert Advice for Securing Critical…
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate also interesting: Cybersecurity Snapshot: Prompt Injection and Data Disclosure Top OWASP’s List of Cyber Risks for GenAI LLM Apps Cybersecurity Snapshot: Expert Advice for Securing Critical…
-
Meta Sued Over Training Data for Its AI and Face-Recognition Systems
The proposed class action alleges Meta illegally harvested people’s Facebook and Instagram photos to train its AI image-generation models and to build its unreleased “NameTag” face recognition feature. First seen on wired.com Jump to article: www.wired.com/story/meta-sued-over-training-data-for-its-ai-and-face-recognition-systems/ also interesting: Catching the ghost in the machine: Adapting threat detection to cloud speed Is AI here to take…
-
AI-Accelerated Attacks and Zero-Days Push Defenders Toward Machine Speed
Weekly summary of Cybersecurity Insider newsletters First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-accelerated-attacks-and-zero-days-push-defenders-toward-machine-speed/ also interesting: The zero-day timeline just collapsed. Here’s what security leaders do next Patch windows collapse as timeexploit accelerates Five steps to become Mythos ready TDL 028 – When Privacy Creates Blind Spots – Andrew Campling
-
AI-Accelerated Attacks and Zero-Days Push Defenders Toward Machine Speed
Weekly summary of Cybersecurity Insider newsletters First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-accelerated-attacks-and-zero-days-push-defenders-toward-machine-speed/ also interesting: ICYMI: Exposure Management Academy on Attack Surface Management, Proactive Security and More 9 top bug bounty programs launched in 2025 Cybersecurity Snapshot: AI Will Take Center Stage in Cyber in 2026, Google Says, as MITRE Revamps ATTCK Framework TDL…
-
Rhysida Publishes 1.4 Million Berlin Government Files After Ransom Refusal
Rhysida published nearly 1.4 million files stolen from Berlin after a Euro2 million ransom demand failed, exposing personal and sensitive government data. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-berlin-cyberattack-rhysida-dark-web-emea/ also interesting: US takes aim at healthcare cybersecurity with proposed HIPAA changes Ransomware Group Threatens to Dump Paraguayan Citizens’ Data UK government wants ransomware victims…
-
AI Agents Used in PaperCut Attacks on 395 Organizations
GreyNoise Says Attacker Used Hundreds of Agents in 48-Country Campaign. A likely Russian-speaking attacker used hundreds of AI agents to exploit PaperCut systems, compromising at least 440 systems at 395 organizations in 48 countries. GreyNoise said the attacker used the agents to develop exploits, find targets and attack systems in parallel. First seen on govinfosecurity.com…
-
GitLab’s critical flaw is already drawing internet-wide probes
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. First seen on cyberscoop.com Jump to article: cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/ also interesting: 14 million OpenSSH servers exposed to the internet via regression flaw Cybersecurity Snapshot: CISA’s Best Cyber Advice on Securing Cloud, OT, Apps and More…
-
Breach of Confidence, 11 September 2026
I’ve discovered that the best way to avoid working is to write a newsletter about work. It’s meta-procrastination. My therapist would be proud if I could afford one after this week’s Claude bill. Grizzly Bears Understand Infrastructure Better Than Most… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/breach-of-confidence-11-september-2026/ also interesting: Cybersecurity Snapshot: CISA’s Best Cyber…
-
The Cost of Silence: Why Fear Kills Phishing Reporting
An employee clicks a link in an urgent email that seems to come from payroll. A login page flashes, then vanishes. In that split second, a cold wave of dread hits them. Their stomach drops, their heart rate spikes, and their… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-cost-of-silence-why-fear-kills-phishing-reporting/ also interesting: Don’t trust that email: It…
-
Surface SaaS and AI Threats
Surface SaaS and AI Threats Know who has access to your data before attackers do. CHALLENGE Threat actors target new attack vectors every day. Every SaaS and AI app your organization adopts expands your attack surface. Threats such as stolen… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/surface-saas-and-ai-threats/ also interesting: Security for AI: How Shadow…
-
AI-Powered Security
AI-Powered Security AI is built into the SaaS apps you already run: Claude in your workflows, Now Assist inside ServiceNow, Agentforce across Salesforce. AppOmni defends this AI layer with the same SSPM principles that secures the rest of your SaaS… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-powered-security/ also interesting: Meta1st embraces AI for new…
-
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a…
-
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under…
-
AI Governance Can’t Wait
Adversaries can manipulate AI defensive reasoning to silently compromise target networks. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-governance-cannot-wait also interesting: Leveraging AI for enhanced compliance and governance How Can SMBs Keep Up With AI Governance? Quantensouveräne KI vom kritischen Risiko zur vertrauenswürdigen Lösung What is Security Posture Management and Why is it Important?
-
Anthropic Discloses Fourth Incident of Claude Breaching Real Systems During Security Tests
Anthropic has disclosed a fourth incident in which one of its Claude models broke into genuine third-party systems during what was supposed to be a contained cybersecurity evaluation, deepening industry concern over the risks posed by increasingly autonomous AI agents. The AI company said the episode dates back to January 2026 and involved an early…
-
Anthropic Says Claude Used in Possible Bioweapon Research
Tags: aiAnthropic says researchers used Claude for biological work that could support weapons development, exposing new challenges for AI safeguards. The post Anthropic Says Claude Used in Possible Bioweapon Research appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-anthropic-claude-bioweapon-research/ also interesting: Hackers Target US AI Experts With Customized RAT Deepfake Phone Scams for…
-
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Tags: access, breach, cloud, credentials, cyber, data, data-breach, defense, exploit, extortion, github, group, infrastructureCyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints. Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it’s dubbed a Hardcoded Horrorshow that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.…
-
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public…
-
Microsoft sees some new wrinkles in invoice-scam emails
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI. First seen on therecord.media Jump to article: therecord.media/invoice-scam-emails-new-features-microsoft-researchers also interesting: 7 biggest cybersecurity stories of 2024 TDL 008 – Defending the Frontline: Ransomware, AI, and Real-World Lessons TDL…
-
Agentic AI Doesn’t Eliminate Humans. It Moves Them to the Only Place That Matters
The conversation around agentic AI in cybersecurity is starting to sound familiar: machines are faster, humans are slow, therefore remove humans from the loop. It’s a clean narrative”¦ and it’s also the wrong one. The real question isn’t whether humans should be involved in AI-driven defense. It’s where they should be involved. And if you..…
-
Microsoft, Red Hat, Linux und Ajax.NET – Fünf alte Sicherheitslücken werden aktiv ausgenutzt
First seen on security-insider.de Jump to article: www.security-insider.de/cisa-kev-alte-schwachstellen-red-hat-sql-linux-kernel-a-e9e77ee9249d771d100a0f215a073ada/ also interesting: Microsoft reagiert auf lahmgelegte Linux-Bootloader durch Windows Update Bei Digital-Produkten auch auf Ausfallrisiken achten Bei Digital-Produkten auch auf Ausfallrisiken achten 10 promising cybersecurity startups CISOs should know about
-
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain also interesting: Time of Reckoning Reviewing My 2024 Cybersecurity Predictions AI-Powered Cyber Warfare, Ransomware Evolution, and Cloud Threats Shape 2025 Cyber Landscape…
-
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors The 2024 cyberwar playbook: Tricks used by nation-state actors Ivanti…
-
Balancing AI Innovation with GDPR and EU AI Act Guardrails in Europe
Enterprise adoption of agentic AI is moving at breakneck speed, but governance is struggling to keep pace. Gartner projects that AI regulatory violations will drive a spike in tech-related litigation within the next few years. Yet, only 23% of GRC… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/balancing-ai-innovation-with-gdpr-and-eu-ai-act-guardrails-in-europe/ also interesting: What is Security Posture Management…
-
ISO 42001: What It Actually Certifies, and Whether You Need It
Tags: socA prospect’s security team asks whether you hold ISO 42001. Eighteen months ago almost nobody asked. Now it shows up in procurement checklists next to SOC 2, and the people asking frequently cannot say what a yes would actually tell… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/iso-42001-what-it-actually-certifies-and-whether-you-need-it/ also interesting: Channel Brief: Citi Ventures Invests…

