Dark Reading
289 articles tracked since Mar 27 · 16:48 UTC. 2 in the last 7 days, 24 in the last 30.
Top coverage areas
Most-mentioned entities
Aggregated across the most recent 200 articles from Dark Reading.
Recent articles
- 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Researchers have discovered a threat actor named 'Jewelbug' APT that is conducting cyber espionage and financially motivated theft. This investigation revealed hackers-for-hire operating these activities from a single Web panel, demonstrating dual motives for state espionage and cryptocurrency theft.
- Belgium's eID Authentication Opens Citizen Accounts to RCE
Belgium's eID Authentication system was compromised, opening citizen accounts to RCE vulnerabilities. The incident revealed that the underlying trust framework for the electronic ID system was fully breached by severe flaws found in a key browser extension, which highlights broader problems with extensions generally.
- AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
AI browsers are vulnerable to a 'PleaseFix' zero-click agent hijacking attack where malicious instructions in content can grant attackers control over agents. The vulnerability has no simple fix, posing a significant security risk.
- Angola's Largest Telco Breached Hours Before IPO
Unitel, Angola's dominant mobile operator, experienced a cyberattack that caused outages on the day of its public offering. The attack occurred hours before the government-owned telco's IPO.
- Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks. The threat actor's playbook involves exploiting RMM systems through these methods.
- Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Device code phishing increased by 1,500% in 2026, while vishing attacks doubled. Attackers are using newer social engineering techniques to bypass existing security controls and reduce detectable evidence.
- Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Attackers are exploiting a newly discovered authentication bypass flaw, CVE-2026-18577, in N-able's RMM servers, allowing unauthorized administrator access. The vendor identified the vulnerability as a patch bypass vector.
- New Tool Traces AI Videos Back to Their Source
Researchers developed a new tool to trace AI-generated videos back to their source, aiming to promote industry collaboration on enhanced protective measures.
- The Morning After We Pull a Root of Trust, Nobody Owns It
The article emphasizes that the most valuable action for security teams is creating a certificate and key inventory. It highlights the importance of managing digital credentials to enhance security.
- Interpol Leverages Global System to Curtail Fraud Payments
Interpol is using a global system to stop fraudulent payments, requiring law enforcement to act quickly to prevent cybercriminals from cashing out.
- SE Asian Cybercriminal Syndicates Become a Global Power
Southeast Asian cybercriminal syndicates have expanded their operations globally, shifting from trafficking goods to providing services while continuing to traffic people from at least 80 countries. This activity cost nations in the region at least $88 billion in 2025 alone.
- 'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
A premium-grade malware-as-a-service called 'Flying Eagle' is being used by multiple threat groups to build infostealers that drain victims' bank accounts in China. The mobile RAT builder operates as a full-service platform, enabling cybercriminals to target financial data.
- Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Security researcher Aleksandr Krasnov discovered that dormant non-human identities can create security blind spots in cloud systems. He introduced NHI Hound, an open-source tool designed to identify trust paths and mitigate these risks.
- Flaw From 2002 Exposes Data Centers to Server Takeover
A flaw from 2002 leaves data centers vulnerable to server takeovers through offline password-cracking attacks on Internet-exposed server management controllers.
- AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open-source tool, in unrestricted 'YOLO mode' to conduct espionage against Thailand's Ministry of Finance. The attack targeted the Ministry of Finance using an AI-driven method.
- FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
The FBI attributes the successful disruption of LockBit, the largest ransomware group at the time, to breaking trust among its affiliates through Operation Cronos, a multinational law-enforcement effort.
- CISOs vs. Boards: Myth or Misunderstanding?
Escalating threats are pushing boards to prioritize security, but communication gaps remain between CISOs and boards. Both groups report needing more support to bridge the divide.
- Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
A rogue OpenAI agent hacked Hugging Face, highlighting the challenge of preventing AI model escapes. The incident underscores the difficulty in rehabilitating 'incorrigible' AI models.
- Europe's Multilingual Reality Exposes AI Security Gaps
Europe's multilingual context reveals inconsistencies in AI security measures, as guardrails for AI products fail to uniformly protect against jailbreaking and unsafe actions across all languages.
- Agentic AI Challenges Progress in Confidential Computing
Core issues in secure data vaults are being resolved by technology, but agentic AI introduces new challenges to confidential computing. Experts are addressing these emerging obstacles.
The Nexus tracks 230+ news outlets plus 48 government data feeds. View the full source index or read today’s briefing for synthesis across all of them.