Dark Reading
VerifiedOnline/Digital
Long one of the most widely-read cyber security news sites on the Web, Dark Reading is now the most trusted online community for security professionals like you. Our community members include thought-leading security researchers, CISOs, and technology specialists, along with thousands of other security professionals. We want you to join us. Source
Actions
Media Outlet details
| Scope | International, Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesAustralian Gov't Weighs Mandatory AI Incident Reporting
Australia's government is sounding out artificial intelligence (AI) industry leaders this week, as it evaluates how to best regulate and manage investing in the emerging, and some say dangerous, technology. The move comes after goal-oriented OpenAI agents once again made headlines for slipping their sandboxes and hacking third-party targets on their own, this time networks affiliated with Australia's Medicare system. In Sydney on Oct.
Citizen Lab Slams Trump Administration, 'Techno-Fascist' Executives
SecTor 2026 – Toronto — Citizen Lab director Ron Deibert had a stern warning for the world about the rise of commercial spyware and surveillance, and how the US government and technology companies are driving it. During his keynote address at the SecTor 2026 conference, Deibert opined that the Trump administration and the technology leaders that have allied themselves with the US president are pushing an authoritarian agenda and "techno-fascism" movement.
Anthropic Gives Vetted Defenders Fewer Claude Guardrails
Anthropic will merge Project Glasswing into its existing Cyber Verification Program (CVP) to create an expanded, tiered program that gives vetted security professionals access to advanced AI cyber capabilities with varying levels of safeguards that experts say may or may not prevent misuse.
OpenAI Agent Escape Causes Wikimedia Service Outage
Autonomous OpenAI agents caused a partial outage of a Wikimedia online service and tried to use others as proxies as part of a series of unauthorized activities it performed across the nonprofit's wiki sites.
Critical Healthcare Systems Aren't Quantum-Ready
IT and Internet of Things (IoT) systems across the healthcare sector appear largely unprepared for the post-quantum cryptography (PQC) era, leaving sensitive data potentially vulnerable to "harvest now, decrypt later" attacks. The situation is particularly acute for Internet-exposed healthcare systems, many of which lack support for TLS 1.3, the foundation for deploying standardized post-quantum cryptography.
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Attackers are altering ClickFix tactics to hide payloads until after the victim has already performed the trusted action, as two recent examples showcase. ClickFix has become a prominent social engineering technique in the past few years, due largely to how it exploits human problem solving tendencies as well as trust in software.
IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
AI is changing cybersecurity teams — but not necessarily by replacing the people who work on them. New research from IANS finds that CISOs are largely looking to AI to help their existing teams do more, while rethinking how work gets divided between junior and senior security professionals.
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
A Google internal AI agent has discovered more than 500 cross-site scripting (XXS) flaws on the company's own Web applications, by using a combination of AI and validation to provide an overview of vulnerabilities that can likely be exploited and thus should be addressed.
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
A novel proof-of-concept (PoC) cyberattack technique is capable of preventing Windows Defender from receiving updates without exploiting a vulnerability in the process. Dubbed "BigDiskBuster" by researchers from LevelBlue, the PoC was originally published on Sept. 19 by security researcher and former Microsoft employee Abdelhamid Naceri, who goes by MSNightmare (aka Nightmare-Eclipse). The GitHub page for the PoC has since been taken down, but LevelBlue researchers were able to reproduce it.
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Researchers have uncovered a new Linux malware strain that exploits a growing list of known vulnerabilities in Internet of Things (IoT) devices to maintain a persistent foothold on enterprise networks. What makes the malware especially noteworthy is its use of legitimate public STUN servers to help maintain connectivity with compromised devices, allowing the attackers to obscure their infrastructure in otherwise legitimate Internet traffic.