Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
Read recent coverage from BleepingComputer, Dark Reading, SecurityWeek, and The Hacker News, plus original research from SecurityAlert.
Browse collected headlines and short excerpts from this publisher. Open the original article for the complete reporting.
SecurityAlert keeps the publisher's headline, a short feed excerpt, the publication date when available, and detected security signals. The linked article remains the source.
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
Adversaries can manipulate AI defensive reasoning to silently compromise target networks.
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.
An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Frontier AI models have already demonstrated they can autonomously - and in some cases, inadvertently - conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.
An article can point you toward something worth investigating, but it cannot tell you whether a product is installed in your environment or whether an attack affects your organization.
Read the linked article, check any named CVE or vendor advisory, and use Pulse to compare the story with the technologies and threats you monitor.