Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderati…
Appearance and language
Browse all headlines from this category in a dedicated page.
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderati…
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but …
It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to …
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the or…
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belong…
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating…
Researchers built a fake company to study fake employee scams.
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of Shiny…
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs …
The recent AI warning letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detect…
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according…
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from peop…
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket…
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for atta…
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even …
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel recor…
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected…
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cos…
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention fr…