Ciberseguridad
darkreading Public RSS feed
- AI Agent Drives Espionage Attack on Thai Ministry of Financeen 28 de julio de 2026
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
- 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azureen 27 de julio de 2026
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
- FBI: Breaking Affiliate Trust Sped Along LockBit's Takedownen 27 de julio de 2026
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
- Adversaries Don't Need a Zero-Day — They Read Your Rulebooken 27 de julio de 2026
Confidence in autonomous security tools is declining, and here's why.
- CISOs vs. Boards: Myth or Misunderstanding?en 24 de julio de 2026
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to […]
- Escape Artists: 'Incorrigible' AI Models Resist Rehabilitationen 24 de julio de 2026
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
- Vatican's Official Prayer App Leaks 700K+ Global Users' PIIen 24 de julio de 2026
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.
- Default Azure Automation Setting Enables Cross-Tenant Identity Takeoveren 24 de julio de 2026
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity […]
- Europe's Multilingual Reality Exposes AI Security Gapsen 24 de julio de 2026
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
- Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targetsen 23 de julio de 2026
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
- Agentic AI Challenges Progress in Confidential Computingen 23 de julio de 2026
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some […]
- Brazilian Banking Trojan Actively Spreading in Portugalen 23 de julio de 2026
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
- Ransomware Attack Puts a Chill on Japanese Frozen-Food Chainen 23 de julio de 2026
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.
- Flaws in Passkey Implementation Show Old Attacks Still Worken 22 de julio de 2026
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.
- Attackers Are Learning to Live Off the AI Toolchainen 22 de julio de 2026
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal […]















