Sign in

Dark Reading

@darkreading.bsky.social
1.7K followers 20 following 1.1K posts

One of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.

PostsRepliesMedia
Dark Reading @darkreading.bsky.social · 10h
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net bit.ly/4xVeXGz by Elizabeth Montalbano
darkreading.com
Russia’s Star Blizzard Ditches ClickFix to Widen Phishing Net
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets to limit victim interaction and deploy its CosmicPulse backdoor.
000
Dark Reading @darkreading.bsky.social · 10h
South Africa Seeks Help After Cyberattack Targets Air Traffic Control bit.ly/4AL7sVu by Robert Lemos #DRGlobal
darkreading.com
South Africa Seeks Aid After Air Traffic Control Cyberattack
As aviation suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one OT network.
000
Dark Reading @darkreading.bsky.social · 29/09/2026
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution bit.ly/4yxyaiH by Alexander Culafi
darkreading.com
Unsloth Studio Flaw Turns Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
000
Dark Reading @darkreading.bsky.social · 29/09/2026
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks bit.ly/3TrM1Ic by Jai Vijayan
darkreading.com
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
012
Dark Reading @darkreading.bsky.social · 29/09/2026
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers www.darkreading.com/vulnerabilit...
darkreading.com
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
000
Dark Reading @darkreading.bsky.social · 29/09/2026
'NeedyMantis' Provides Long-Term Access to Compromised Networks www.darkreading.com/threat-intel...
darkreading.com
'NeedyMantis' Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using the modular malware in intrusions against telcos, universities, medical, and government organizations.
110
Dark Reading @darkreading.bsky.social · 29/09/2026
Latest on @darkreading.bsky.social #DRTechnology: Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities zpr.io/TYtZLXSaAfZE #darkreading #cybersecurity
zpr.io
Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities
The Open Agent Safety Platform relies on both hardware and software components to monitor agent activities and quarantine unruly agents before they cause harm.
001
Dark Reading @darkreading.bsky.social · 28/09/2026
One Packet Can Crash OT Servers in Industrial Sectors www.darkreading.com/ics-ot-secur... #darkreading #cybersecurity
darkreading.com
One Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.
000
Dark Reading @darkreading.bsky.social · 28/09/2026
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts www.darkreading.com/identity-acc... #darkreading #cybersecurity
darkreading.com
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The Carbonato botnet compromises exposed Docker hosts, deploys an AI agent to steal AI API keys, and then spreads to other exposed Docker services.
001
Dark Reading @darkreading.bsky.social · 28/09/2026
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions www.darkreading.com/application-... #darkreading #cybersecurity
darkreading.com
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.
000
Dark Reading @darkreading.bsky.social · 28/09/2026
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack www.darkreading.com/cloud-securi... #darkreading #cybersecurity
darkreading.com
JadePuffer AI Actor Compromises Azure in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
011
Dark Reading @darkreading.bsky.social · 28/09/2026
Are rogue AI incidents good marketing for Google, OpenAI, & Anthropic? Can you be a “white hat” hacker if you steal more than $300 million in cryptocurrency from a company, give most of it back, but keep $50 million for yourself? Our latest "What We Missed" video: www.darkreading.com/cyber-risk/w...
darkreading.com
What We Missed: Google Gemini Joins the AI Escape Party
In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including Google Gemini models breaking containment.
000
Dark Reading @darkreading.bsky.social · 28/09/2026
DPRK IT workers infected more than 30k devices across 100+ countries to exfiltrate funds. Training recruiters and revamping HR policies can make a difference. www.darkreading.com/cyber-risk/s...
darkreading.com
Stopping IT Worker Scams Requires Revamped HR Process
Training human-resource managers in the latest tactics and warning signs helps blunt the threat, but automated analysis can help even more.
000
Dark Reading @darkreading.bsky.social · 27/09/2026
Latest on @darkreading.bsky.social #DRTheEdge: How the CISO CFO Relationship is a Key to Cybersecurity Success zpr.io/u2vdEGi5hYaV #darkreading #cybersecurity
zpr.io
How the CISO CFO Relationship is a Key to Cybersecurity Success
Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today's threat landscape.
000
Dark Reading @darkreading.bsky.social · 25/09/2026
Latest on @darkreading.bsky.social #DRTheEdge: What We Missed: Google Gemini Joins the AI Escape Party zpr.io/kVhurUVSCKiP #darkreading #cybersecurity
zpr.io
What We Missed: Google Gemini Joins the AI Escape Party
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.
000
Dark Reading @darkreading.bsky.social · 25/09/2026
Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more. Read @darkreading.bsky.social's latest: Stopping IT Worker Scams Requires Revamped HR Process www.darkreading.com/cyber-risk/s...
darkreading.com
Stopping IT Worker Scams Requires Revamped HR Process
Training human-resource managers in the latest tactics and warning signs helps blunt the threat, but automated analysis can help even more.
000
Dark Reading @darkreading.bsky.social · 25/09/2026
Russia's Hybrid Cyber-Physical War in Europe Heats Up www.darkreading.com/physical-sec... #DRGlobal #darkreading
darkreading.com
Russia's Hybrid Cyber-Physical War in Europe Heats Up
A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide support to Ukraine.
010
Dark Reading @darkreading.bsky.social · 25/09/2026
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing www.darkreading.com/application-... #darkreading #cybersecurity
darkreading.com
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
000
Dark Reading @darkreading.bsky.social · 24/09/2026
3 Cyber Threats That Defined the Summer of 2026 www.darkreading.com/cyberattacks-da… #DRTheEdge
darkreading.com
3 Cyber Threats That Defined the Summer of 2026
This Reporters' Notebook video discusses AI agents breaching Hugging Face, Fairlife's ransomware attack, and threat actors targeting a dozen water systems.
001
Dark Reading @darkreading.bsky.social · 24/09/2026
Prompt-Injection Bug Hits $4B Agentic AI App 'Manus' bit.ly/4ACOZub by Nate Nelson
darkreading.com
Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.
010
Dark Reading @darkreading.bsky.social · 24/09/2026
Latest on @darkreading.bsky.social #DRTheEdge: 3 Cyber Threats That Defined the Summer of 2026 zpr.io/sLj28jqP77rg #darkreading #cybersecurity
zpr.io
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
000
Dark Reading @darkreading.bsky.social · 24/09/2026
Ghost Service Accounts Enable M365 Data Theft in Chile bit.ly/4rO4Nq1 by Nate Nelson #DRGlobal
bit.ly
Ghost Service Accounts Enable M365 Data Theft in Chile
Even if employee accounts are locked down, forgotten and lost service accounts can undo an organization's entire M365 environment.
000
Dark Reading @darkreading.bsky.social · 24/09/2026
Latest on @darkreading.bsky.social #DRTechnology: How to Build A SASE Framework for Modern Cybersecurity zpr.io/tGDYXF8EZj53 #darkreading #cybersecurity
zpr.io
How to Build A SASE Framework for Modern Cybersecurity
Keeping edge computing safe requires organizations to fundamentally rethink security governance. Here is a path forward: a step-by-step guide to building a SASE framework.
000
Dark Reading @darkreading.bsky.social · 24/09/2026
Latest on @darkreading.bsky.social #DRTechnology: SASE Converges Network & Security Into One Cloud Solution zpr.io/8k5PuaXznyAg #darkreading #cybersecurity
zpr.io
SASE Converges Network & Security Into One Cloud Solution
Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls.
000
Dark Reading @darkreading.bsky.social · 23/09/2026
EDR Evasion Stack Helps Process Injection Slip Past Defenses bit.ly/3VLZQ4M by Alexander Culafi
darkreading.com
EDR Evasion Stack Helps Process Injection Slip Past Defenses
The process parameter poisoning EDR evasion technique bypasses security tools by hiding payloads in Windows process initialization structures.
010
Dark Reading @darkreading.bsky.social · 23/09/2026
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks bit.ly/4iFcFYd by Rob Wright
bit.ly
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
011
Dark Reading @darkreading.bsky.social · 23/09/2026
UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks www.darkreading.com/threat-intellig… by Robert Lemos #DRGlobal
darkreading.com
UAE, KSA Face Spike in Increasingly Complex Cyberattacks
The United Arab Emirates and Saudi Arabia absorbed half of all cyberattacks recorded across the Gulf region in the first half of 2026.
000
Dark Reading @darkreading.bsky.social · 23/09/2026
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign bit.ly/3Tkr4yM by Elizabeth Montalbano
darkreading.com
Attackers Manipulate AI in Mass Disinformation, Phishing Campaign
Hackers are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
021
Dark Reading @darkreading.bsky.social · 23/09/2026
Relays Are Masking Chinese Access to Frontier AI Models in the US bit.ly/4xzVueh by Jai Vijayan
darkreading.com
Relays Are Masking Chinese Access to US Frontier AI Models
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge LLMs, probably to clone them.
021
Dark Reading @darkreading.bsky.social · 23/09/2026
Microsoft Disrupts EvilTokens Device Code Phishing Service bit.ly/4rAQyVm by Alexander Culafi
darkreading.com
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft disrupted the EvilTokens phishing platform, which used AI-powered device code phishing to compromise thousands of organizations globally.
000
Dark Reading @darkreading.bsky.social · 23/09/2026
Google, Microsoft, and xAI argue for a potential pause in AI deployment. Still, enterprises need the time too: Many businesses now have AI policies, best practices & a defined risk appetite, but "what they often lack is a way to enforce and verify those policies in practice." bit.ly/4yIMfJG
bit.ly
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment underscore AI risks, both large AI labs and regular businesses are searching for better way to keep control and be secure.
011
Dark Reading @darkreading.bsky.social · 23/09/2026
Paying a ransom doesn't necessarily mean stolen data disappears. The ShinyHunters-Cl0p feud is a stark example of why: Once data is outside of an organization's control, it can potentially be stolen again, resold, exposed, or used for another round of extortion. bit.ly/4hlkf83
bit.ly
ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?
ShinyHunters breached rival ransomware gang Cl0p's leak site, threatening to expose victim payment data and raising concerns about secondary data exposure.
001
Dark Reading @darkreading.bsky.social · 23/09/2026
Latest on @darkreading.bsky.social #DRTechnology: Deception by Design: CISA's Guide to Tricking Cybercriminals zpr.io/8GBi8ZVS8Nem #darkreading #cybersecurity
zpr.io
Deception by Design: CISA's Guide to Tricking Cybercriminals
The Cybersecurity and Infrastructure Security Agency (CISA) is going old-school to help organizations with limited resources set traps for hackers.
000
Dark Reading @darkreading.bsky.social · 23/09/2026
Latest on @darkreading.bsky.social #DRTheEdge: How the CISO-CMO Alliance Builds Trust Before Crisis Strikes zpr.io/wsSAtLQhBXm4 #darkreading #cybersecurity
zpr.io
How the CISO-CMO Alliance Builds Trust Before Crisis Strikes
Cybersecurity and brand reputation are inextricably linked, and organizations that establish regular touchpoints, develop joint crisis communications plans, and translate security risks into their brand impact will significantly outperform those treating security as merely an operational IT concern.
000
Dark Reading @darkreading.bsky.social · 22/09/2026
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data bit.ly/4hF67b4 by Elizabeth Montalbano
darkreading.com
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Cyber-threat actors stole 170 private repositories using an OAuth token stolen from a former employee through the TanStack npm supply chain attack.
000
Dark Reading @darkreading.bsky.social · 22/09/2026
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real bit.ly/4yIMfJG by Robert Lemos
darkreading.com
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment underscore AI risks, both large AI labs and regular businesses are searching for better way to keep control and be secure.
000
Dark Reading @darkreading.bsky.social · 22/09/2026
How AI Agents Can Trigger Runaway Costs for Enterprises bit.ly/4AshEC2 by Jai Vijayan
darkreading.com
How AI Agents Can Trigger Runaway Costs for Enterprises
Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
110
Dark Reading @darkreading.bsky.social · 22/09/2026
ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims? bit.ly/4hlkf83 by Alexander Culafi
darkreading.com
ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?
ShinyHunters breached rival ransomware gang Cl0p's leak site, threatening to expose victim payment data and raising concerns about secondary data exposure.
000
Dark Reading @darkreading.bsky.social · 21/09/2026
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents bit.ly/3VqppIu by Elizabeth Montalbano
bit.ly
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
The AI giant disclosed six examples of concerning model behavior and published a new framework for investigating and disclosing such incidents.
000
Dark Reading @darkreading.bsky.social · 21/09/2026
Cisco Zero-Day Highlights API Endpoint Authentication Issues bit.ly/4jfRR9V by Rob Wright
darkreading.com
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
010
Dark Reading @darkreading.bsky.social · 21/09/2026
MFA Won't Save You From OAuth Consent Abuse bit.ly/479dL7r Commentary by Vishnu Galata, Senior Professional Services Consultant, F5
darkreading.com
MFA Won't Save You From OAuth Consent Abuse
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
000
Dark Reading @darkreading.bsky.social · 18/09/2026
AI Agent Breaches Spanish Organization, Modifies Personal Data bit.ly/4ydlAF9 by Nate Nelson #DRGlobal
darkreading.com
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
000
Dark Reading @darkreading.bsky.social · 18/09/2026
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus bit.ly/4h2XgQc by Jai Vijayan
darkreading.com
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
000
Dark Reading @darkreading.bsky.social · 18/09/2026
China's FamousSparrow APT Spies on US Politics in Latin America bit.ly/4AmcBTt by Nate Nelson #DRGlobal
darkreading.com
China's FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
011
Dark Reading @darkreading.bsky.social · 17/09/2026
AI Security Spending Jumps as Fear Outpaces Proof of Value bit.ly/3VlmlgN by Jai Vijayan
darkreading.com
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
001
Dark Reading @darkreading.bsky.social · 16/09/2026
Fighting Your Dragons Through Tough Tech Times bit.ly/4h4SHUg Cybersecurity industry vet Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns in our latest Dark Reading Confidential podcast.
darkreading.com
Finding Hope During Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and shares advice on building connections during tech industry downturns.
001
Dark Reading @darkreading.bsky.social · 16/09/2026
Microsoft Issues Emergency Fixes After Massive Patch Tuesday bit.ly/4h4EA1e by Rob Wright
darkreading.com
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
000
Dark Reading @darkreading.bsky.social · 16/09/2026
Cyber Op Targets South Korean Media & Automotive Sectors bit.ly/4rgnl1L by Robert Lemos #DRGlobal
darkreading.com
Cyber Op Targets South Korean Media & Automotive Sectors
A North Korean APT group used a new Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
000
Dark Reading @darkreading.bsky.social · 16/09/2026
BragJack Turns a Browser’s Agentic AI Against It (Forever Security) bit.ly/3UV8bms by Elizabeth Montalbano
darkreading.com
BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks AI assistants built directly into a browser to access sensitive information, execute malicious actions, and exfiltrate data.
000
Dark Reading @darkreading.bsky.social · 15/09/2026
VectraRAT Can Hack Windows Enterprises for $250 per Month bit.ly/4j5M3Q8 by Elizabeth Montalbano
darkreading.com
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service MaaS platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
000