In a "near-autonomous" attack, a Chinese-language operator used a complex AI framework to target and compromise government ...
Threat actors can trick a Copilot instance into giving up details about its own architecture, paving the way for a novel prompt injection attack. Varonis reported CoSnitch to Microsoft in December ...
A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, ...
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential ...
One Caledonian government agency reported a breach, thanks to a third-party training contractor that may have serviced other ...
Explore the latest news and expert commentary on Threat Intelligence, brought to you by the editors of Dark Reading ...
Former chief information officers explain the role of executive support, creative tactics, and organization-wide buy-in.
The National Institute of Standards and Technology (NIST) is seeking guidance on the future of the National Vulnerability Database (NVD) and to what degree AI should be integrated into its management ...
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real ...
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open ...
A browser extension central to Belgium's national identity card system was built like Swiss cheese, letting hackers steal victims' identities and payment information, and even perform code execution ...
Unitel, Angola's top mobile operator, continues to recover from a cyberattack that disrupted the government-owned telco on ...