Global Intelligence Search
Query the entire database for vulnerabilities, news articles, open-source security tools, and known threat actors.
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, researchers have...
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
A ransomware affiliate is approaching victims of the attacks it may have helped carry out, in an interesting technique that actually undermines its own business model. According to the GuidePoint Research and...
Video Call Exploit Chains Two Flaws in Unisoc Modems
Researchers have uncovered a new flaw in Unisoc T612 modem firmware that, when chained with a previously disclosed remote code execution (RCE) vulnerability, could allow an attacker to gain privileged access to the...
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
It turns out that AI agents don't always play nice together. In the latest episode of agentic AI producing unexpected results , Anthropic recently observed "a multiagent turf war" between three instances of the same...
Hugging Face Breach Raises Big Questions About AI Security Controls
OpenAI's rogue agents have sparked a new set of questions and concerns for cyber defenders, and Dark Reading's senior news director Rob Wright sat down at the News Desk with threat modelling expert Adam Shostack to find...
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
Yet another Mirai-derived botnet is on the loose, targeting Linux systems by exploiting flaws in various Internet-facing devices to combine distributed denial of service (DDoS) attacks with a broader set of malicious...
Mission-Driven Security: Inside a Global Bank's Defense
In an era where cyber threats evolve at breakneck speed and financial institutions remain prime targets for sophisticated adversaries, the role of the chief information security officer (CISO) has never been more...
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
The National Institute of Standards and Technology (NIST) is seeking guidance on the future of the National Vulnerability Database (NVD) and to what degree AI should be integrated into its management of the service and...
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
A contractor has leaked Scottish government employees' personal information, and the full scope of the breach may be far greater than what is currently being reported. On Aug. 13, Scotland's Crown Office and Procurator...
What Boards Need to Know About Tech Risk
OPINION Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That...
Cyera's Oasis Security Buy Is All About AI Agent Control
In a move to add nonhuman identity (NHI) and artificial intelligence (AI) agent management to its data security platform, Cyera has plans to acquire Oasis Security for approximately $1 billion in cash and stock. The...
Global Threat Campaign Hits Critical VMware vCenter Flaw
A critical vulnerability in VMware vCenter came under heavy exploitation via a single threat actor just days after public disclosure. CVE-2026–59310 is a critical directory traversal flaw with a 9.8 CVSS score that...