Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 24/09/20263 Cyber Threats That Defined the Summer of 2026 www.darkreading.com/cyberattacks-da… #DRTheEdge darkreading.com3 Cyber Threats That Defined the Summer of 2026This Reporters' Notebook video discusses AI agents breaching Hugging Face, Fairlife's ransomware attack, and threat actors targeting a dozen water systems. 011
Reposted by Jim DonahueEric Geller @ericjgeller.com · 24/09/2026CISA has released its election security plan for the midterms. It's nothing exciting: summaries of how election infrastructure works, what cyber/physical vulnerabilities exist, and what services CISA offers, plus a push for information sharing. www.cisa.gov/sites/defaul... 294
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 23/09/2026Paying a ransom doesn't necessarily mean stolen data disappears. The ShinyHunters-Cl0p feud is a stark example of why: Once data is outside of an organization's control, it can potentially be stolen again, resold, exposed, or used for another round of extortion. bit.ly/4hlkf83 bit.lyShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?ShinyHunters breached rival ransomware gang Cl0p's leak site, threatening to expose victim payment data and raising concerns about secondary data exposure. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 23/09/2026Google, Microsoft, and xAI argue for a potential pause in AI deployment. Still, enterprises need the time too: Many businesses now have AI policies, best practices & a defined risk appetite, but "what they often lack is a way to enforce and verify those policies in practice." bit.ly/4yIMfJGbit.lyAmid Ongoing Rogue Incidents, Debate Over AI Safety Gets RealAs more reports of misalignment underscore AI risks, both large AI labs and regular businesses are searching for better way to keep control and be secure. 011
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 18/09/2026China's FamousSparrow APT Spies on US Politics in Latin America bit.ly/4AmcBTt by Nate Nelson #DRGlobaldarkreading.comChina's FamousSparrow APT Spies on US Politics in Latin AmericaAmid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight. 011
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 17/09/2026AI Security Spending Jumps as Fear Outpaces Proof of Value bit.ly/3VlmlgN by Jai Vijayandarkreading.comAI Security Spending Jumps as Fear Outpaces Proof of ValueCISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move? 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 16/09/2026Fighting Your Dragons Through Tough Tech Times bit.ly/4h4SHUg Cybersecurity industry vet Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns in our latest Dark Reading Confidential podcast. darkreading.comFinding Hope During Tough Tech TimesCybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and shares advice on building connections during tech industry downturns. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 10/09/2026Patch Tuesday Sets Another Record With 974 CVEs In 2022, Microsoft disclosed and patched 917 total CVEs across 12 Patch Tuesdays. On Tuesday, the software giant fixed a record 974 vulnerabilities for its September Patch Tuesday alone. Is this the new normal? bit.ly/4xPfUkCdarkreading.comPatch Tuesday Sets Another Record With 974 CVEsAttackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 31/08/2026Bug bounty report volume is exploding. What happens when vulnerability discovery becomes easier, faster, and more abundant? That's the question behind Alexander Culafi’s latest reporting on the "vulnpocalypse" and the changing economics of bug bounties. bit.ly/4gAP2gR bit.lyThe Vulnpocalypse Is Repricing the Bug Bounty EconomyThe surge of AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 27/08/2026Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026: bit.ly/4A0biK3 #DRTheEdgedarkreading.comAgentic AI Risks, CVE Program Concerns Permeate Black Hat 2026This installment of the Reporters' Notebook video series discusses several topics such as AI's effects on vulnerability reporting and security research. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 27/08/2026Red Flags That Expose Fake North Korean IT Workers: www.darkreading.com/insider-threats… by Alexander Culafidarkreading.comRed Flags That Expose Fake North Korean IT WorkersNorth Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 26/08/2026'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month: bit.ly/3SWGjh1 by Elizabeth Montalbanodarkreading.com'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a MonthThe AitM service lowers the barrier to entry for actors to create phishing attacks that steal more than just user credentials. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 24/08/2026The Vulnerability Gap: Why Discovery Is Outrunning Repair bit.ly/4qwYmXw Commentary by Christopher Robinson, Chief Security Architect, Open Source Security Foundation darkreading.comThe Vulnerability Gap: Why Discovery Is Outrunning RepairAI is discovering more vulnerabilities, faster, and the entire cybersecurity community must pitch in to respond. 001
Reposted by Jim DonahueEric Geller @ericjgeller.com · 11/08/2026One of the biggest topics at last week's Black Hat and @defcon.bsky.social conferences was the future of the CVE Program, which assigns vulnerability IDs that are used all over the place. My new story wraps together everything we heard from key CVE figures: www.cybersecuritydive.com/news/cve-pro... 1179
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 03/08/2026As we head into Black Hat USA 2026, hear the voices that have been sounding the alarm for two decades, including: ✓ Bruce Schneier ✓ Katie Moussouris ✓ Rich Mogull ✓ Robert "RSnake" Their favorite Dark Reading columns from the past 20 years are still relevant today. bit.ly/45COi5Abit.lyCyber Pioneers Ponder Past as PrologueRobert "RSnake" Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier consider whether columns they penned have stood test of time. 021
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 28/07/2026AI models and agents routinely plow through guardrails, leaving companies the task of ensuring they are behaving well. "[N]o matter how good the model is, you cannot yet trust their guardrails 100 percent." — Nico Waisman, CISO, XBOW bit.ly/4fByFzQ By Robert Lemosbit.lyEscape Artists: 'Incorrigible' AI Models Resist RehabilitationThe hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 22/07/2026When AI Attacks: OpenAI Models Autonomously Hack Hugging Face: bit.ly/4vGQB28 by Elizabeth Montalbanodarkreading.comWhen AI Attacks: OpenAI Models Autonomously Hack Hugging FaceAdvanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. 011
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 22/07/2026A quarter of security executives considered leaving their job in the past 12 months, as securing AI in the workplace raises stress: "[S]uddenly, lower-skilled attackers have access to new tools that allow them to do a lot of damage," says Michael Fanning, CISO at Splunk. bit.ly/3R50Jnmbit.lyCISOs Feel the Heat Over AI RiskJob pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position. 011
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 20/07/2026Inc Ransomware Exploits SonicWall SMA Zero-Days: bit.ly/4wTBX8R by Nate Nelsonbit.lyInc Ransomware Exploits SonicWall SMA Zero-DaysWhen chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances. 002
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 20/07/2026The White House's new Gold Eagle clearinghouse targets a real vulnerability coordination gap. Whether it can solve the remediation challenge is another question. bit.ly/4bIyKR9 by Alexander Culafibit.lyGold Eagle Clearinghouse Targets Real Gap, but How Is UnclearThe White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 20/07/2026Cybersecurity Keeps Events 'Uneventful': bit.ly/45faD96 Commentary by Olga Polishchuk, ZeroFoxdarkreading.comCybersecurity Keeps Events 'Uneventful'From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with enormous security demands. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 16/07/2026🌍✨ Dark Reading just launched European cybersecurity coverage! From Germany to Greece, France to Italy—we're bringing you threat intelligence that understands YOUR unique challenges. Find out why Europe's cyber landscape needs its own lens 👀 #CyberDefense #Europe #InfoSec bit.ly/3Q3ERrHbit.lyDark Reading | EuropeBreaking cybersecurity news, news analysis, commentary, and other content from Europe. 011
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 15/07/2026In our latest episode of Reporters' Notebook, Sharon Shea from TechTarget Cybersecurity talks about how much information is at risk when schools are targeted by threat actors. Check out the full episode here: bit.ly/4vtf1MF 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 16/07/2026At 622 CVEs, Microsoft's July 2026 Patch Tuesday is the biggest ever. But the real story is how AI-driven vulnerability discovery is forcing organizations to rethink how they prioritize and deploy patches. bit.ly/4po2o3N by Jai Vijayanbit.lyRecords Are Made to Be Broken: Patch Tuesday Raises Triage StakesThree of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 16/07/2026European nations were already looking to reduce their reliance on American tech companies, but the US government's ban on Anthropic's frontier models threw petrol on the tech sovereignty fire. bit.ly/4vBB6bT by Rob Wright bit.lyTech-xit? UK Steps Up Sovereignty Push Amid AI StrifeThe US government's restrictions on Anthropic frontier models intensifies calls in the UK to reduce reliance on US tech, with cyber implications. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 16/07/2026"I want to change the law," Jen Ellis told Rapid7’s then-CEO Corey Thomas. That statement changed the relationship between industry and government. Check out Dark Reading’s Security Pro File by Ericka Chickowski | Jen Ellis: Connecting Cyber Community With Political Machinery bit.ly/4aX2oSAbit.lyJen Ellis: Connecting Cyber Community with Political MachineryOn the heels of recent honors for her contribution to cyber policy, Jen Ellis looks back at the events that shaped her advocacy for security researchers. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 14/07/2026ClickFix's Mushrooming Ecosystem Demands New Defense Tactics: bit.ly/44uD1Us by Elizabeth Montalbanodarkreading.comClickFix's Mushrooming Ecosystem Demands New Defense TacticsThe attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 14/07/2026Weak Security Continues to Fuel Russian Cyberattacks: bit.ly/3RcrhD6 by Jai Vijayan darkreading.comWeak Security Continues to Fuel Russian CyberattacksIn a first, the UK and the EU jointly imposed sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region. 012
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 14/07/2026Manage Vendor Risk in a Few Practical Steps: bit.ly/4fzxDpf Commentary by Daniel Nutkis, HITRUST darkreading.comManage Vendor Risk in a Few Practical StepsRisk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance. 001
Reposted by Jim DonahueDark Reading @darkreading.bsky.social · 14/07/2026Engineers are using Claude Mythos and GPT-5.5 to build defenses against futuristic AI cyberattacks. Along the way, they're also building the tools hackers will use to carry out those attacks. bit.ly/4wJvBsH by Nate Nelson darkreading.com'Yellow Teams' Are Defining the Future of AI SecurityIn some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat. 001
Jim Donahue @jimdonahue-cyber.bsky.social · 07/05/2026I retired this acct when I ... well, retired. But I wanted to share this story about Dark Reading's 20th anniversary. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 27/08/2025I'm retiring as of tomorrow, so this work account will be going dark. (It seems likely I'll do some freelance work in 2026, so I'm not shutting down the acct. But I'm taking it easy a few months.) I do have a personal account here, but it seems weird to post the link. Feel free to DM me, though. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 19/08/2025New on @darkreading.bsky.social, commentary by Liad Cohen and Eyal Paz, OX Security: "By addressing these risk vectors, organizations can continue leveraging GitHub's innovation while protecting against the sophisticated supply chain attacks targeting our interconnected software ecosystem."darkreading.com10 Major GitHub Risk Vectors Hidden in Plain SightBy addressing these overlooked risk vectors, organizations can continue leveraging GitHub's innovation while protecting against sophisticated supply chain attacks targeting interconnected software. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 18/08/2025New on @darkreading.bsky.social, commentary by Aditya K. Sood, VP of Security Engineering & AI Strategy, Aryaka: "Today's RATs don't just exploit technical vulnerabilities. They also take advantage of the blind spots created by how enterprise architects establish their security environments."darkreading.comHow Evolving RATs Are Redefining Enterprise Security ThreatsA more unified and behavior-aware approach to detection can significantly improve security outcomes. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 15/08/2025New on @darkreading.bsky.social, commentary by Ivanti's Field CISO Mike Riemer: "When security becomes part of the development culture rather than an external constraint, teams start thinking about security implications naturally as they build features."darkreading.comUsing Security Expertise to Bridge the Communication GapCybersecurity-focused leadership delivers better products and business outcomes. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 11/08/2025New on @darkreading.bsky.social, commentary by Ofri Ouzan, Security Researcher & Advocate, JFrog: CVE scoring systems "often fail to account for the unique context of each organization's environment. As a result, teams risk focusing on theoretical risks while genuine threats may be overlooked."darkreading.comThe Critical Flaw in CVE ScoringWith informed decision-making, organizations can strengthen their overall resilience and maintain the agility needed to adapt to emerging threats, without sacrificing innovation or productivity. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 11/08/2025New on @darkreading.bsky.social, commentary by Lane Sullivan, Chief Information Security & Strategy Officer, Concentric AI: "Being a CISO today is a balancing act of strategic leadership, financial literacy, technical expertise, and human connection, regardless of [company size]."darkreading.comRedefining the Role: What Makes a CISO GreatSecurity is everyone's responsibility, but as a CISO, it starts with you. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 11/08/2025New on @darkreading.bsky.social, commentary by Melina Scotto, Founder, Mastin & Associates: "Consider securing AI as your next career opportunity to transform challenges into a strategic advantage and build cyber resilience in a rapidly changing, AI-enabled, digital world."darkreading.comWill Secure AI Be the Hottest Career Path in Cybersecurity?Securing AI systems represents cybersecurity's next frontier, creating specialized career paths as organizations grapple with novel vulnerabilities, regulatory requirements, and cross-functional deman... 000
Jim Donahue @jimdonahue-cyber.bsky.social · 05/08/2025New on @darkreading.bsky.social, commentary by Pritesh Parekh, CISO, PagerDuty: "In an era where cyber threats are increasingly sophisticated and pervasive, the importance of post-incident security reviews cannot be overstated." Get tips on organizing your own reviews.darkreading.comBuilding the Perfect Post-Security Incident Review PlaybookBy creating a safe environment for open discussion, prioritizing human context alongside technical data, and involving diverse stakeholders, organizations can turn security incidents into accelerators... 000
Jim Donahue @jimdonahue-cyber.bsky.social · 05/08/2025New on @darkreading.bsky.social, commentary by Trend Micro's Jon Clay: "While the cybercriminal underground has professionalized and become more organized in recent years, threat actors are, to a great extent, still using the same attack methods today as they were in 2020."darkreading.comWhy the Old Ways Are Still the Best for Most CybercriminalsWhile the cybercrime underground has professionalized and become more organized in recent years, threat actors are, to a great extent, still using the same attack methods today as they were in 2020. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 05/08/2025Get the latest news from Black Hat this week. www.darkreading.com/keyword/blac...darkreading.comBlack Hat NewsBlack Hat News 000
Reposted by Jim DonahueEric Geller @ericjgeller.com · 30/07/2025Scoop: CISA's contract with ICF has expired, reducing the JCDC's contractor workforce from 100+ to just 10. CISA can use emergency money & 2-week extensions to keep those 10 around, but only through Sept. Other contracts also caught up in huge backlog. www.cybersecuritydive.com/news/cisa-jo... 21913
Jim Donahue @jimdonahue-cyber.bsky.social · 30/07/2025New on @darkreading.bsky.social, commentary by Alisdair Faulkner, Darwinium: "We must accept that malicious agents will often appear legitimate — and gain access. Defending against them requires speed, but not at the expense of paralyzing online commerce."darkreading.comHow to Spot Malicious AI Agents Before They StrikeThe rise of agentic AI means the battle of the machines is just beginning. To win, we'll need our own agents — human and machine — working together. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 30/07/2025New on @darkreading.bsky.social, commentary by Roger Cressey, Mountain Wave Ventures: "As we reflect on the anniversary of the largest outage in IT history, organizations everywhere need to make an active effort to ... create a more robust and resilient cyber ecosystem moving forward."darkreading.comThe CrowdStrike Outage Was Bad but Could Have Been WorseA year after the largest outage in IT history, organizations need to make an active effort to diversify their technology and software vendors and create a more resilient cyber ecosystem moving forward... 000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025New on @darkreading.bsky.social : "By tying security investments to measurable outcomes — like reduced breach likelihood and financial impact — CISOs can align internal stakeholders and justify spending based on real-world risk." Commentary by Kara Sprague, CEO, HackerOnedarkreading.comSecuring the Budget: Demonstrating Cybersecurity's ReturnBy tying security investments to measurable outcomes — like reduced breach likelihood and financial impact — CISOs can align internal stakeholders and justify spending based on real-world risk. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025New on @darkreading.bsky.social: "Many CISOs still find themselves speaking a technical language that fails to resonate with other leaders. Technical terms often fall flat in boardrooms more concerned with revenue growth and brand reputation." Commentary by Ashley Rose, Living Securitydarkreading.comTranslating Cyber-Risk for the BoardroomWhen security leaders embrace this truth and learn to speak in the language of leadership, they don't just protect the enterprise, they help lead it forward. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025New on @darkreading.bsky.social: "Today's insider threats aren't lone wolves acting out of spite — they're pawns in the hands of sophisticated, organized criminal networks." Commentary by Rob Juncker, Mimecastdarkreading.comHow Criminal Networks Exploit Insider VulnerabilitiesCriminal networks are adapting quickly, and they're betting that companies won't keep pace. Let's prove them wrong. 000
Jim Donahue @jimdonahue-cyber.bsky.social · 24/07/2025New on @darkreading.bsky.social: "Agentic AI could be a disaster for authorization systems in software-as-a-service (SaaS) platforms as we know them today. But it doesn't have to be, if security and IT teams address the challenges proactively." Commentary by Josh Lemos, GitLab. chaosdarkreading.com3 Ways Security Teams Can Minimize Agentic AI ChaosSecurity often lags behind innovation. The path forward requires striking a balance. 000
Reposted by Jim DonahueEric Geller @ericjgeller.com · 27/06/2025My new story about the U.S. government’s fraying partnerships with critical infrastructure operators is packed with new reporting, but there’s a lot more that I couldn’t fit into the story. Here are some more details from my interviews over the past few weeks about where things stand… 34420