Dark Reading
143 briefings written from Dark Reading's reporting, newest first. Each is a plain-language summary written here for Australian business, with a link to the original.
- AI Agent Used to Breach Spanish Organisation, Alter Personal Data
- CISA Shifts Away from Weekly Vulnerability Bulletins in Favor of Risk-Based Alerts
- Chinese Spy Group FamousSparrow Targets US Political Interests in Latin America
- Businesses Rush to Buy AI Security Tools Before Proof They Work
- Navigating Cybersecurity Careers Through Tough Tech Times
- New 'BragJack' Attack Hijacks Browser AI Assistants to Steal Data
- North Korean Hackers Deploy New Linux Toolkit Against South Korean Media and Auto Firms
- Microsoft Rushes Out Emergency Fixes After Huge Patch Tuesday
- Upcoming Black Hat Talk to Detail How an AI Model Broke Out of Its Test Sandbox
- Cheap Malware-as-a-Service Kit Puts Windows Businesses at Risk
- Russian 'Sandworm' Hackers Return with Upgraded Botnet Malware Targeting Cisco Devices
- Maximum-Severity GitLab Flaw Threatens Software Supply Chains
- Anthropic CEO Calls for a Pause on AI Advancement to Focus on Safety
- AI Lets Scammers Send 1 Million Personalized Fraud Emails in Days
- CISA Pushes for Clearer Breach Reporting as Cyber Outages Rise
- AI-Powered Scanner Aims to Spot Exposed Business Assets Before Attackers Do
- Why AI Chatbots Are Becoming Dangerously Good at Scamming People
- Why Australian Businesses Can't Delay AI Governance
- AI-Driven Attack Swarms Signal a New Phase in Cybercrime
- Fake Banking Apps Target Android Users in Indonesia Cloning Campaign
- Scammers Use Phone Calls and BYOD Devices to Break Into Microsoft 365 Accounts
- Researcher Publishes New Zero-Day Exploit Targeting Windows Defender
- EU's New Cyber Resilience Act Sets 24-Hour Breach Reporting Deadline
- Vulnerability Discovery Is Outpacing Fixes, Research Shows
- US Officials Allege Chinese AI Firms Secretly Copied US Models
- New AI Attack Technique Hijacks Enterprise Workflows Without Credentials
- Microsoft's Latest Patch Tuesday Breaks Records: 974 Vulnerabilities Fixed
- Phishing Scam Hides Behind Trusted Google Links to Steal Credentials
- AI Agents Linked to Wiki Site Breach Ahead of Hugging Face Incident
- ClickFix Scams Evolve: Attackers Abuse Trusted Services to Stay Hidden
- Chinese-Language Hackers Hijack Government Servers to Power Gambling Phishing Network
- AI-Powered Cyberattacks Are Coming: Businesses Have Roughly Six Months to Prepare
- AI-Powered Bug Hunting Is Flooding Vendors With Vulnerability Reports
- Rogue AI Agents Are Causing Real Damage — Insurers Scramble to Keep Up
- ‘Phantom Deal’ Scam Uses Fake Mergers to Trick Employees Into Wire Transfers
- ShinyHunters Claims Another Breach: What SMBs Should Know
- AI Security Warning Letter Raises Alarms — But Leaves Key Questions Unanswered
- AI 'Machine Speed' Turns a Two-Week Cyberattack Into a 10-Hour Breach
- 'Breeze Comet' Threat Group Targets Brazilian and Global Financial Systems
- AI-Driven Vulnerability Surge May Be Less Daunting Than Expected, Research Finds
- SonicWall Edge Devices Hit by New Zero-Day Attacks Enabling Remote Takeover
- AI Is Giving Cybercriminals a Speed Advantage, Warns Former Hacker
- Attackers Exploit Microsoft Teams Trust Through Voice Phishing Scheme
- Unpatched ownCloud Flaw Exposes Philippines Nuclear Agency Data
- Critical Flaw in JFrog Artifactory Under Active Attack—Patch Now
- Ransomware Gangs Turn to Insider Recruitment as Outside Defences Improve
- Critical Flaw in AI Development Platform Langflow Under Active Attack
- AI Safety Researcher METR Targeted in Credential Theft, Racks Up $600,000 in Stolen AI Credits
- Fake CAPTCHA Prompts Hide Malware in Blockchain-Powered Attack
- Infostealer Malware Targets Claude AI Accounts via Stolen Sessions
- New 'TerminalFix' Attack Tricks Users Into Running Malicious PowerShell Commands
- AI Guardrails Alone Won't Stop Attackers, Researcher Warns
- Why AI 'Rules' Aren't Enough: Lessons from a Real-World Agent Attack
- Hundreds of AI Agents Teamed Up to Breach Hugging Face Servers
- Businesses Turn to AI-Powered Offensive Security as Threats Escalate
- Why Australian SMBs Running Industrial Systems Should Consider Cyber Deception
- Why 'Turning Off' AI Might Be Harder Than It Sounds
- AI-Generated Bug Reports Are Flooding Bug Bounty Programs, Driving Down Payouts
- White-Label Routers Made in China Found With Built-In Backdoors
- Black Hat 2026: AI Agents and Vulnerability Reporting Take Centre Stage
- Russian State-Backed Hackers Target EU Officials Through Signal and WhatsApp
- State-Linked Hackers Unveil New Espionage Malware 'GoCaracal'
- New AI Tool Uncovers Fresh HTTP Request-Smuggling Attacks
- Fake North Korean IT Workers: What Australian Businesses Should Watch For
- Car Infotainment Systems Targeted by Android Malware Botnet
- 'NovaCookies' Phishing Kit Lets Criminals Hijack Microsoft 365 Accounts for $320 a Month
- Interpol Operation Targets West African Cybercrime Network Behind 'Black Axe'
- Nigeria Pushes Sovereign Cloud Strategy to Strengthen Cybersecurity and National Security
- AI Email Summaries Can Be Manipulated by Hidden Malicious Code
- Security Flaw in NVIDIA AI Tool Could Let Hackers Poison Business AI Assistants
- Cyber Costs Are Skyrocketing—And Small Businesses Are Being Left Behind
- Urgent Zimbra Email Flaw Under Attack: Patch Now, Experts Warn
- New ClickFix Malware Trick Hides Attacks as Plain Text Files
- New 'SynkLoader' Malware Combines Old Tricks with Modern Evasion to Steal Passwords
- ToxicPanda Banking Trojan Evolves, Expanding Beyond Personal Finance Apps
- AI Is Finding Security Flaws Faster Than Businesses Can Fix Them
- New Research Warns of Risks in Emerging Industrial Networking Protocols
- OWASP Releases New Security Blueprint to Tackle Risks in AI Skills and Add-ons
- Local Governments Need Cybersecurity Volunteers—Here's Why It Matters to Everyone
- Cybersecurity Experts Urged to Help Protect Local Government
- OpenAI Tightens Security Controls Following AI Model Leak Incident
- Chipmakers Race to Quantum-Proof Hardware as Future Threat Looms
- New CUSTODY Framework Aims to Keep AI Agents on a Tighter Leash
- Delta Flight Wi-Fi Hack Highlights Growing Airline Cybersecurity Risks
- Password Vault Flaw Puts MSP and SMB Credentials at Risk
- Why Police Are Struggling to Keep Up With Cybercrime
- Pakistan-Linked Hacking Group Updates Tools to Target Afghan Government Systems
- Banking Trojan 'Grandoreiro' Returns With New Tricks Despite Police Takedown
- Unfiltered AI Tool 'Kriminal' Raises Alarms as Cybercrime Enabler
- AI Agents Could Become Your Newest Insider Threat, Expert Warns
- Chinese-Linked Hacking Group Targets Central Asian Organisations with Remote Access Trojans
- China-Linked Hackers Use AI to Power Near-Autonomous Cyberattack in APAC
- Critical GitLab Zero-Click Flaw Leaves Self-Managed Users Guessing
- New 'CoSnitch' Technique Tricks Microsoft Copilot Into Exposing Its Own Security Weaknesses
- AI Agents Gone Rogue: What Small Businesses Should Learn From Sandbox Failures
- New Docuseries Pulls Back the Curtain on Life as a CISO
- New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services
- Fake 'Ransom Busters': Ransomware Gang Poses as Recovery Experts to Steal Payments
- Answering a Video Call Could Hijack Your Android Phone, Researchers Warn
- AI Agents Turned Rivals: Anthropic Testing Reveals Self-Replicating Malware Risk
- Threat Modeling Expert Highlights Lessons from Hugging Face AI Attack
- New Linux Botnet 'Evooo1Bot' Turns Hacked Devices Into Attacker Toolkits
- Why Today's Top Security Leaders Need Business Skills, Not Just Tech Skills
- AI Is Fueling a Flood of New Vulnerabilities—Can AI Also Help Fix It?
- Scottish Prosecutor's Office Data Breach Linked to Third-Party Vendor
- Why Boards Keep Getting Caught Off Guard by Tech Risk
- Cyera's $1 Billion Acquisition Signals New Era of AI Agent Security
- Critical VMware vCenter Vulnerability Under Active Global Attack
- 'Jewelbug' Hacker Group Blends Espionage with Cryptocurrency Theft
- Flaws in Belgium's Digital ID Browser Extension Expose Citizens to Remote Attacks
- Long-Running 'City-Forum' Campaign Targets Salesforce and ServiceNow Data
- Walmart's Collaborative Security Model: What SMBs Can Learn from 'Purple Teaming'
- Ransomware Strikes Colombian Justice Ministry Ahead of Presidential Handover
- Walmart's Security Playbook: Trust and Communication Over Chaos
- Microsoft's August Patch Tuesday Brings Another Wave of Security Fixes
- Gunra Ransomware Gang Bypasses MFA by Exploiting Old Fortinet Vulnerabilities
- 'GhostJacking' Attack Reveals Hidden Risks in AI Agent Security
- Iran-Linked Hackers Suspected in Widening Attacks on US Water Systems
- Critical Zero-Day in Metabase Analytics Tool Could Expose Countless Business Systems
- Beyond the Checklist: Why Aussie Businesses Need to Rethink How They Patch
- Advanced iPhone Hacking Tools Once Reserved for Spies Now Spreading to Cybercriminals
- Outdated Cybercrime Laws Leave Ethical Hackers Exposed
- What Sherlock Holmes Can Teach Us About Social Engineering
- AI-Written Software Patches Fail Half the Time, Study Finds
- Cybercriminals Are Working Together Faster Than Law Enforcement Can Keep Up
- AI Agents Are Breaking Out of Testing Labs — And Businesses Should Take Notice
- Security Researcher Exposes Weakness in ChatGPT's 'Secure' Sandbox
- Lessons from the DNC: Why a 'Security-First' Culture Needs More Than Just Rules
- AI Fuels a New Golden Age for Global Fraud Syndicates
- New 'PleaseFix' Attack Exposes Hidden Risk in AI-Powered Browsers
- AI Browsers Still Vulnerable to Prompt Injection Attacks, Researchers Warn
- How Simple Web Styling Code Could Be Used to Steal Your Email Data
- 15 Security Flaws Found in TP-Link Devices Raise Questions About Automated Network Setup
- Google Patches AI 'Agent-to-Agent' Flaw That Could Have Hit Software Supply Chains
- Angola's Top Telecom Hit by Cyberattack Right Before Major Stock Launch
- New 'Smoke#Screen' Campaign Hijacks Remote Access Tools to Infiltrate Networks
- AI Meeting Notetaker Flaw Exposed Government and Corporate Video Calls
- Device Code Phishing Surges 1,500% as Attackers Bypass Traditional Security Controls
- Urgent: New Bypass Flaw Found in N-able RMM Software Gives Attackers Admin Access
- New Research Tool Aims to Trace AI-Generated Videos Back to Their Source
- Anthropic: AI Security Incidents Traced to Access Controls, Not Faulty Models
- Chinese Threat Actor Weaponises DeepSeek AI Agent in Attack on Security Firm
- CISO Burnout: When Accountability Outweighs Authority