Global Intelligence Search
Query the entire database for vulnerabilities, news articles, open-source security tools, and known threat actors.
TikTok reaches $400M settlement with US over COPPA violations
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA). The TikTok...
Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators....
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in...
U.S. Bank says breach claims related to fourth-party incident
Image: Urvish Oza via Unsplash U.S. Bank says breach claims related to fourth-party incident U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a...
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen Canada’s largest pediatric health center suffered a recent cybersecurity incident that exposed the personal information of...
Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers
Image: Unsplash+/Getty Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers Russian software developer Microolap confirmed that hackers had compromised some of its systems but denied...
Lawmakers call for investigation into impact of CISA staffing cuts
Image: Getty via Unsplash+/CISA Lawmakers call for investigation into impact of CISA staffing cuts Members of Congress have asked a government watchdog to examine the effect staffing cuts at the Cybersecurity and...
OpenAI Adds Controls That Should've Been There Already
OpenAI has committed to a number of security and guardrail improvements in the wake of an incident last month where cutting edge models inadvertently breached AI application store Hugging Face during a cyber capability...
Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near
Chip makers are baking post-quantum cryptography acceleration into hardware as the threat of quantum systems breaking current encryption rises. The technology is still years away from the general market, but defenders...
New CUSTODY Framework Constrains AI Agents Inside the Network
Jake Williams told Dark Reading he felt compelled to act after OpenAI disclosed its models had breached Hugging Face . The cybersecurity expert and vice president of R&D at Hunter Strategies had been working on a new...
OWASP Flags Top AI Skill Risks in New Security Blueprint
In early July, a cyberattacker reserved a look-alike domain impersonating a popular agentic AI work platform, Paperclip, and produced both Trojanized Python packages and weaponized AI skills to compromise users'...
Calling on Cyber Pros to Help Defend City Hall
OPINION A government agency I work with lost nearly a million dollars and never heard an alarm. No ransom note, no locked-up servers. Attackers slipped into a handful of staff email accounts, watched how the agency...