Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Enterprise cybersecurity expert Jake Williams released a new agentic AI framework called CUSTODY that constrains AI agents within the network. The framework was developed in response to the OpenAI attacks on Hugging Face and the growing need for AI agent security controls.
The Rust Project removed malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases containing typosquatted dependencies. The malicious code executed during the build process, installing info-stealing malware on developers' systems.
Three distinct suspected Russian cyber espionage threat clusters are abusing legitimate authentication flows to target individuals in academia, defense, and government sectors. The attackers use sophisticated social engineering tactics to compromise personal accounts across multiple platforms.
Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign targeting Central Asian governments. The SilkParasite espionage operation leverages AI to create more sophisticated and evasive malware.
Dark Reading editors discuss recently uncovered security stories including a Delta flight disrupted by a Wi-Fi hack and the US government's new hack back strategy. The Wi-Fi hack demonstrated how in-flight connectivity can be exploited to disrupt aircraft systems.
AWS Network Firewall now supports rule hit count, allowing security teams to identify which firewall rules are actively matching traffic. This feature helps teams optimize firewall rule sets by identifying rules that consume capacity without matching traffic.