§Source · Dark Reading
Dark Reading
Every dispatch we have aggregated from Dark Reading.
All dispatches
Loading
§Source · Dark Reading
Every dispatch we have aggregated from Dark Reading.
All dispatchesCVE-2026-19478 zero-click GitLab vulnerability lacks technical details, complicating detection for self-managed deployments.
Browser extension vulnerabilities in Belgium's eID framework allow remote code execution and full compromise of citizen accounts.
Jewelbug APT operators run both state espionage and cryptocurrency theft from the same web control panel.
Widening attacks against US water systems continue, targeting Internet-exposed PLCs; attribution reports suggest Iran-linked activity in some cases.
Metabase zero-day allows remote admin takeover and data exfiltration, posing broad downstream risk to analytics consumers.
Numerous internet-exposed remote hardware management controllers are vulnerable to offline password cracking and takeover attempts.
Microsoft patched a high-severity Certighost AD Certificate Services flaw that enables privilege escalation and domain compromise.
Autonomous Hermes AI agent used for espionage against Thailand's Ministry of Finance, facilitating data access and stealthy reconnaissance.
Brazilian banking Trojan campaign actively spreading in Portugal, exploiting language commonality to target local businesses and consumers.
Ransomware disrupted operations at a Japanese frozen-food logistics firm, delaying shipments to major clients including national franchises.
BusySnake infostealer used by 'Armored Likho' reached government agencies and electrical power entities, targeting critical infrastructure.
Researchers report JadePuffer, an agentic ransomware automating attack steps and accelerating operations.
EU organizations and suppliers face rising ransomware pressure; strengthen vendor risk and incident response.
EU organizations and suppliers face rising ransomware pressure; strengthen vendor risk and incident response.
Get these articles delivered to your inbox.
Subscribe free