darkreading
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
1 day 10 hours ago
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.
Jeffrey Schwartz
Thousands of Data Center Controllers Open to Takeover
1 day 11 hours ago
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
Jai Vijayan
When AI Agents Escape Sandboxes, Old Security Rules Apply
1 day 11 hours ago
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
Alexander Culafi
Stronger AI Safety Requires Peeking Inside the 'Black Box'
1 day 12 hours ago
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
Robert Lemos
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
1 day 15 hours ago
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
Elizabeth Montalbano
Former Citigroup CISO Blauner on What Makes A Great Security Leader
1 day 19 hours ago
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
Kristina Beek
AI Agent Drives Espionage Attack on Thai Ministry of Finance
2 days 7 hours ago
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
Alexander Culafi
Agentic Browsers Rewind Web Security by 20 Years
2 days 10 hours ago
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.
Ericka Chickowski
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
2 days 11 hours ago
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
Rob Wright
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
2 days 11 hours ago
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
Elizabeth Montalbano
Why Resetting Passwords No Longer Stops Attackers
2 days 13 hours ago
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions.
Jai Vijayan
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
2 days 14 hours ago
Confidence in autonomous security tools is declining, and here's why.
Burak Oktenli
CISOs vs. Boards: Myth or Misunderstanding?
5 days 10 hours ago
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
Arielle Waldman
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
5 days 12 hours ago
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
Robert Lemos
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
5 days 19 hours ago
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.
Nate Nelson
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
5 days 19 hours ago
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and cloud workloads.
Jeffrey Schwartz
Europe's Multilingual Reality Exposes AI Security Gaps
6 days 1 hour ago
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
Alexander Culafi
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
6 days 10 hours ago
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
Rob Wright
Agentic AI Challenges Progress in Confidential Computing
6 days 20 hours ago
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.
Agam Shah
Checked
16 hours 50 minutes ago
Public RSS feed
darkreading feed