Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

With Friends Like These: China Spies on Russian IT Orgs

State-linked hackers stayed under the radar by using a variety of commercial cloud services for command-and-control communications.

DARKReading
As Gen Z Enters Cybersecurity, Jury Is Out on AI's Impact

Despite possibly supplanting some young analysts, one Gen Z cybersecurity specialist sees AI helping teach those willing to learn and removing drudge work.

'JackFix' Attack Circumvents ClickFix Mitigations

A new ClickFix variant ratchets up the psychological pressure to 100 and addresses some technical mitigations to classic ClickFix attacks.

ShadowRay 2.0 Turns AI Clusters into Crypto Botnets

A threat actor is leveraging a flaw in the Ray framework to hijack AI infrastructure worldwide and distribute a self-propagating cryptomining and data theft botnet.

#botnet
Critical Flaw in Oracle Identity Manager Under Exploitation

The exploitation of CVE-2025-61757 follows a breach of Oracle Cloud earlier this year as well as a recent extortion campaign targeting Oracle E-Business Suite customers.

Infamous Shai-hulud Worm Resurfaces From the Depths

This campaign introduces a new variant that executes malicious code during preinstall, significantly increasing potential exposure in build and runtime environments, researchers said.

Vision Language Models Keep an Eye on Physical Security

Advancements in vision language models expanded models reasoning capabilities to help protect employee safety.

Deja Vu: Salesforce Customers Hacked Again, Via Gainsight

In a repeat of similar attacks during the summer, threat actors affiliated with the ShinyHunters extortion group used a third-party application to steal organizations' Salesforce data.

LINE Messaging Bugs Open Asian Users to Cyber Espionage

In a potential gift to geopolitical adversaries, the encrypted messaging app uses a leaky custom protocol that allows message replays, impersonation attacks, and sensitive information exposure from chats.

Cloudflare's One-Stop-Shop Convenience Takes Down Global Digital Economy

Even the most advanced systems like Cloudflare can fall victim to software issues and become a global point of failure, Dr. David Utzke argues, adding that the recent outage should be a warning for enterprises.