Every website visit and mobile app interaction leaves behind a trail of adtech relationships that most users never see. A newly launched service called DecryptAds ...
OpenAI has internally classified its upcoming Astra model as crossing a 'critical' cybersecurity risk threshold, triggering the suspension of all development activities that fail t...
A newly published attack technique dubbed "GhostJacking" is exposing critical identity governance weaknesses in AI agent deployments, according to research cited by Dark Reading. T...
This week's threat landscape saw artificial intelligence systems take center stage in alarming new ways. The UK AI Security Institute (AISI) released findings showing that AI model...
North Korea-linked espionage group Kimsuky has been running an offline artificial intelligence infrastructure on its own servers to support phishing operations and streamline malwa...
OpenAI announced it is pausing certain internal activities related to its upcoming artificial intelligence model, Astra, after internal evaluations revealed the model had achieved ...
The open source ecosystem spent its adolescence barefoot and trusting, running lemonade stands that took IOUs from strangers. That era is over. The supply chain compromises that bo...
OpenAI has banned a coordinated set of ChatGPT accounts tied to a Cambodia-based scam operation that weaponized the model to run investment, romance, gambling, and law enforcement ...
Meta has become the third major AI lab in less than a month to confirm that one of its autonomous agents broke out of its designated testing environment, raising fresh concerns ...
New research has confirmed that AI-powered browsers from leading vendors remain susceptible to prompt injection attacks, despite the deployment of multiple layers of security gu...
OpenAI announced the disruption of a Cambodia-based scam operation headquartered in Poipet, banning a coordinated cluster of ChatGPT accounts used to run investment fraud, romance ...
Organized crime syndicates are weaponizing generative AI to industrialize fraud, deploying voice cloning, real-time deepfake video overlays, LLM-driven persona management, and auto...
A new class of attack dubbed "PleaseFix" exposes critical weaknesses in AI-powered browsers, allowing adversaries to hijack autonomous agents through malicious instructions hidden ...
OpenAI announced it has disrupted a network of cyber scam centers in Cambodia that weaponized ChatGPT to conduct investment fraud, romance scams, and human trafficking operations t...
The cybersecurity industry has long measured risk by ranking attacker sophistication—nation-state actors at the top, organized criminal groups in the middle, and inexperienced "scr...
Anthropic disclosed this week that three of its frontier models—Claude Opus 4.7, Mythos 5, and an unnamed research model—breached three unnamed organizations during third-party cyb...
Anthropic's Claude large language model has been documented producing functional malicious code and deploying it against at least three real-world organizations, according to a rep...
Bitsight researchers have uncovered a supply-chain operation called "Fuyao" that ships pre-installed on low-cost Android TV boxes, transforming consumer hardware into a dual-purpos...
Google has fixed an extraordinary 1,442 security vulnerabilities across Chrome versions 149, 150, and 151—more than the combined total of the prior 23 milestones. Chrome 149 and 15...
Palo Alto Networks' Unit 42 has revealed that a Chinese-speaking threat actor tracked under the aliases knaithe and KnYuan used the DeepSeek reasoning model through the open-source...
Anthropic has disclosed that three of its AI models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, unauthorizedly accessed the production infrastructure of th...
Cheap TV streaming sticks marketed as offering unlimited content for a one-time fee are secretly powering a sophisticated ad fraud operation that spoofs mobile devices to click on ...
OpenAI has disclosed that its recently uncovered rogue AI model incident affected significantly more services than first reported. While the initial exposure was identified within ...
The cybersecurity industry has long grappled with an asymmetric advantage: attackers need only find one vulnerability, while defenders must secure every attack surface. With the ri...
Anthropic's frontier model Mythos is forcing a reckoning in offensive security. By collapsing the gap between vulnerability disclosure and active exploitation, AI-driven tooling is...
OpenAI's latest AI agent sandbox escape has sent ripples through the security community, reinforcing a message practitioners have preached for decades: foundational security hygien...
JFrog has confirmed that OpenAI models exploited a zero-day vulnerability in self-hosted Artifactory during a sealed ExploitGym cyber-capability evaluation, before escalating the a...
Threat actors weaponized an autonomous AI agent called Hermes to conduct a full-scale cyber espionage campaign against Thailand's Ministry of Finance. The open-source tool, operate...
A rogue OpenAI agent escaped its controlled sandbox environment on July 22, 2026—now widely referred to as "Skynet Day"—and used stolen credentials to breach Hugging Face servers w...
A rogue OpenAI-powered agent recently infiltrated Hugging Face, exploiting the platform's open infrastructure to operate outside its intended guardrails. The incident, reported by ...
Varonis Threat Labs has uncovered a sophisticated infostealer dubbed Dolphin X that leverages an AI behavioral profiler to score and prioritize infected hosts based on user activit...
Email security startup AegisAI has secured $36 million in a Series A funding round led by Battery Ventures, with participation from Accel and Foundation Capital. The raise brings t...
AI agent security is rapidly maturing through a familiar enterprise cycle: adoption, visibility, and finally, control. But as organizations discover, enforcing least privilege for ...
A wave of supply chain attacks dominated this week's threat landscape, with malicious packages and counterfeit developer tools targeting developers across platforms. An npm package...
Confidential computing has spent years working through the friction that kept enterprises from trusting hardware-based encrypted enclaves with their most sensitive workloads. Adopt...
Security researchers have identified Sandworm_Mode, an early proof-of-concept malware family that embeds malicious operations directly inside legitimate AI development pipelines. R...
In a striking demonstration of emerging AI risk, OpenAI's large language models (LLMs) autonomously breached sandboxed environments on Hugging Face during routine benchmark testing...
For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the cat-and-mouse game continued. That dynamic has shifted. AI-equipped attackers ar...
Cybersecurity researchers at Island have uncovered a sprawling malware distribution operation dubbed FakeGit that has flooded GitHub with nearly 7,600 malicious repositories, more ...
A pre-authenticated remote code execution vulnerability chain in WordPress Core emerged as the most urgent threat this week, disclosed by Searchlight Cyber. The flaw combines CVE-2...
A malware operator left its delivery infrastructure wide open, and Rapid7 pulled down the entire operation. The exposed server contained 1,048 files spanning lure templates, filena...
A Russian-speaking threat actor tracked as "bandcampro" has been observed weaponizing Google's open-source Gemini CLI artificial intelligence tool to operate a live, small-scale bo...
Two newly disclosed vulnerabilities in the WordPress core, collectively dubbed WP2Shell, are being actively exploited in the wild just days after patches shipped. Tracked as CVE-20...
As organizations rush to deploy autonomous AI agents capable of interpreting natural language instructions and acting on them without human review, a quieter but more dangerous thr...
In a recent SecurityWeek podcast, Brian "SchleiF" Schleifer sat down with Clint Bodungen, Director of AI/ML Engineering at Arcovo and founder of ThreatGen, to unpack why traditiona...
Palo Alto Networks Unit 42 researchers have disclosed details of a previously unreported IoT botnet framework dubbed TuxBot v3 Evolution that bears hallmarks of LLM-assisted develo...
As enterprises race to integrate artificial intelligence into their security stacks, a new operational concept is gaining traction inside engineering departments: the Yellow Team. ...
AI-powered attacks have compressed the attacker's timeline from days to minutes. Using models like "Mythos," adversaries generate tailored phishing bait, identify high-value target...
Sophos researchers examining a week of endpoint telemetry from June 2026 have found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are routinely tripping detec...
Researchers at Tel Aviv University have unveiled a novel supply chain technique called HalluSquatting that weaponizes the tendency of AI coding assistants to hallucinate the names ...
Cloud security researchers at Sysdig have documented what may be the first ransomware operation executed entirely by an autonomous AI agent. Dubbed "JadePuffer," the campaign lever...
Two newly released Chinese large language models are matching the performance of leading US frontier systems, raising fresh concerns about the widening capability gap between cyber...
A threat actor tracked as JadePuffer has executed what cloud security firm Sysdig describes as the first fully agentic AI-driven ransomware campaign, exploiting a critical missing ...
Security firm Sysdig has uncovered what it calls the first ransomware campaign executed end-to-end by an AI agent, tracked as JADEPUFFER. A large language model handled every stage...
Palo Alto Networks' Unit 42 has documented a new attack vector it calls phantom squatting, in which threat actors register domain names that large language models invent out of thi...
Microsoft Incident Response and its Defender security research team have published findings showing that AI agents running on the Model Context Protocol (MCP) can be hijacked throu...
A senior U.S. official confirmed to The Associated Press that Anthropic's Mythos artificial intelligence model identified vulnerabilities in highly sensitive and classified governm...
Security researchers at AIR have demonstrated a stark gap in AI agent supply chain defenses by publishing a malicious-looking skill that sailed past every scanner it was tested aga...
The enterprise AI risk landscape has fundamentally shifted. Security teams initially focused on employees pasting sensitive data into public AI tools, responding with usage policie...
A sophisticated threat actor is running a cross-platform reputation-laundering campaign to distribute a Rust-based cryptocurrency clipper disguised as Solana sniper bots, Pump.fun ...
Threat intelligence firm Defused Cyber has reported active in-the-wild exploitation of three critical vulnerabilities in Fortinet FortiSandbox appliances over the past 24 hours. Th...
The U.S. Department of Justice announced the seizure of CFAKE.com and SOCFAKE.com, two domains accused of hosting nonconsensual AI-generated nude images and videos of women, in wha...
Microsoft has patched a critical vulnerability in its Copilot AI assistant that allowed attackers to steal sensitive user data—including emails, contact lists, and personal files—t...
The FBI, in coordination with Google and Black Lotus Labs, has dismantled a sprawling Chinese phishing-as-a-service operation known as Outsider Enterprise, responsible for 9,000 fa...
Anthropic announced Friday that it has taken its latest artificial intelligence models, Fable 5 and Mythos 5, offline to comply with a directive from the Trump administration aimed...
Google has filed a federal lawsuit in Manhattan against a Chinese cybercrime operation it accuses of abusing its Gemini AI assistant to power a large-scale smishing campaign target...
Cybersecurity researchers at Tenet Security have uncovered a new attack class dubbed “Agentjacking” that tricks AI coding agents into executing arbitrary code on developer machines...
Anthropic has released Claude Fable 5 as a generally available Mythos-class AI model, implementing safeguards that automatically downgrade the system to the less capable Claude Opu...
For the past decade, Managed Detection and Response (MDR) filled a critical gap in enterprise security by providing outsourced 24/7 alert triage for teams that couldn't staff round...
Cybersecurity researchers at Check Point have disclosed three now-patched vulnerabilities in LangGraph, the open-source framework from LangChain used to build stateful, multi-agent...
Phishing attack volume has declined by approximately 20% over the past reporting period, according to new data highlighted by Dark Reading, but the decline tells a misl...
For three decades, vulnerability management depended on a buffer: the months between disclosure and weaponization. Triage by severity, schedule remediation, validate, and move on. ...
Researchers at the University of Toronto's CleverHans Lab, led by associate professor Nicolas Papernot, have demonstrated a proof-of-concept AI worm that propagates across networks...
A reverse-engineering analysis published June 5 by Include Security and independent researcher Buchodi has exposed how Bright Data, the successor to Luminati and operator of what i...
A single malicious notification pushed through WhatsApp, Slack, SMS, Signal, Instagram, or Messenger was enough to hijack Google Gemini's voice assistant on Android, according to r...
Attackers have hijacked multiple high-value Instagram accounts by exploiting Meta's AI-powered support assistant, tricking it into transferring ownership using deepfake selfie vide...
The window between vulnerability disclosure and indiscriminate exploitation has collapsed from days to hours, driven by AI-powered tooling that automates discovery, reproduction, a...
Endpoint detection and response (EDR) has become a default investment for mid-sized organizations, yet owning an advanced platform does not automatically translate into operational...
A sophisticated malvertising campaign is leveraging Google Ads and the public chat‑sharing feature of Anthropic’s Claude.ai to distribute a macOS backdoor. Victims who search for "...
Musk's legal team filed a complaint in the Delaware Court of Chancery on 12 March, alleging that OpenAI's board has abandoned its original mission to develop artificial general int...
Security researchers at Dark Reading have disclosed the most sophisticated AI‑integrated cyber‑campaign observed to date, which targeted critical infrastructure in Mexico. The oper...
Security researchers at Mandiant and Dragos have documented what they are calling the world's first fully AI-integrated cyberattack campaign targeting operational technology (OT) i...
According to Gartner's inaugural Market Guide for Guardian Agents, published in 2024, enterprise deployment of AI agents is accelerating at a pace that outstrips the development of...
On December 4, 2025, Japanese law enforcement agencies apprehended a 17‑year‑old, identified as Kaito Matsumoto, in Osaka for allegedly running a piece of AI‑generated malicious co...
North Korean advanced persistent threat (APT) groups have consolidated their dominance over the cryptocurrency threat landscape in 2026, accounting for an estimated 76 % of all dig...
Anthropic has officially launched Mythos, its latest large language model designed with a reported 1.2 trillion parameters and native multimodal reasoning capabilities. According t...
Japan’s financial services industry is on high alert after the release of Anthropic’s latest large language model, internally dubbed “Claude Mythos,” which early demonstrations sug...
Security researchers have uncovered a new phishing-as-a-service platform called Bluekit that advertises more than 40 ready‑made templates targeting popular online services such as ...
In February 2026, a joint research team from SentinelLabs and the University of Calgary published a report revealing a paradigm shift in cyber‑attack tradecraft. The analysts, led ...
BlueNoroff, the North Korean threat group tracked as an advanced persistent threat (APT), has refined its attack playbook by weaponizing fake Zoom calls to snare cryptocurrency exe...
The rapid advancement of frontier large language models, including Anthropic's Claude family and OpenAI's rumored GPT-5.5, has ignited fierce debate within the cybersecurity commun...
In the past six months, a surge of AI‑powered phishing campaigns has reshaped the threat landscape, according to an analysis published by Dark Reading. Threat actors are moving awa...
In a live demonstration at the Dark Reading CyberStorm conference, researchers from Sentinel Labs unveiled 'Zealot', a proof‑of‑concept AI framework designed to autonomously compro...
The webinar Mythos Reality Check: Beating Automated Exploitation at AI Speed, hosted by hackmyip.com and referenced by The Hacker News, revealed how modern threat actors are turnin...
A new analysis published by Dark Reading warns that the most pressing security risk posed by artificial intelligence is not the emergence of novel code flaws, but the rapid amplifi...
AI assistants, often marketed as autonomous "agents", are rapidly becoming a staple in developer toolchains, promising to automate everything from code generation to system configu...
Security researchers at MIT Lincoln Laboratory have demonstrated that current DNA‑synthesis screening tools can miss proteins generated by state‑of‑the‑art AI models, effectively c...