Global Intelligence Search
Query the entire database for vulnerabilities, news articles, open-source security tools, and known threat actors.
Hugging Face Breach Raises Big Questions About AI Security Controls
OpenAI's rogue agents have sparked a new set of questions and concerns for cyber defenders, and Dark Reading's senior news director Rob Wright sat down at the News Desk with threat modelling expert Adam Shostack to find...
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
Yet another Mirai-derived botnet is on the loose, targeting Linux systems by exploiting flaws in various Internet-facing devices to combine distributed denial of service (DDoS) attacks with a broader set of malicious...
Mission-Driven Security: Inside a Global Bank's Defense
In an era where cyber threats evolve at breakneck speed and financial institutions remain prime targets for sophisticated adversaries, the role of the chief information security officer (CISO) has never been more...
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
The National Institute of Standards and Technology (NIST) is seeking guidance on the future of the National Vulnerability Database (NVD) and to what degree AI should be integrated into its management of the service and...
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
A contractor has leaked Scottish government employees' personal information, and the full scope of the breach may be far greater than what is currently being reported. On Aug. 13, Scotland's Crown Office and Procurator...
What Boards Need to Know About Tech Risk
OPINION Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That...
Cyera's Oasis Security Buy Is All About AI Agent Control
In a move to add nonhuman identity (NHI) and artificial intelligence (AI) agent management to its data security platform, Cyera has plans to acquire Oasis Security for approximately $1 billion in cash and stock. The...
Global Threat Campaign Hits Critical VMware vCenter Flaw
A critical vulnerability in VMware vCenter came under heavy exploitation via a single threat actor just days after public disclosure. CVE-2026–59310 is a critical directory traversal flaw with a 9.8 CVSS score that...
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Researchers have identified an advanced persistent threat (APT) group for hire in China that performs both international cyber espionage and lowly cryptocurrency theft. With one hand, the mercenary group "Jewelbug"...
Belgium's eID Authentication Opens Citizen Accounts to RCE
A browser extension central to Belgium's national identity card system was built like Swiss cheese, letting hackers steal victims' identities and payment information, and even perform code execution on their local...
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
An unknown threat actor has been using a custom toolset to probe Salesforce and ServiceNow instances with overly permissive guest access and steal data for more than a year. The targets have spanned multiple sectors,...
Walmart Takes a 'Trusted Agent' Approach to Purple Teaming
Many organizations struggle with the inherent tension between red and blue teams — where offensive security testers and defensive operators often work in silos or even develop adversarial relationships. But Walmart has...