A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into technical and strategic ...
In a "near-autonomous" attack, a Chinese-language operator used a complex AI framework to target and compromise government ...
Threat actors can trick a Copilot instance into giving up details about its own architecture, paving the way for a novel prompt injection attack. Varonis reported CoSnitch to Microsoft in December ...
One Caledonian government agency reported a breach, thanks to a third-party training contractor that may have serviced other ...
Explore the latest news and expert commentary on Threat Intelligence, brought to you by the editors of Dark Reading ...
Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors.
Former chief information officers explain the role of executive support, creative tactics, and organization-wide buy-in.
A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, ...
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open ...
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real ...
A critical vulnerability in VMware vCenter came under heavy exploitation via a single threat actor just days after public disclosure. CVE-2026–59310 is a critical directory traversal flaw with a 9.8 ...
The big-box giant scaled its defenses by encouraging trust. Good communications, transparency, and team spirit are key factors.