darkreading Public RSS feed
- ‘CitrixBleed 2’ Wreaks Havoc as Zero-Day Bugby Jai Vijayan, Contributing Writer on November 12, 2025 at 10:30 pm
The same APT hammered critical bugs in Citrix NetScaler (CVE-2025-5777) and the Cisco Identity Service Engine (CVE-2025-20337) in a sign of growing adversary interest in identity and access management systems.
- Google Looks to Dim ‘Lighthouse’ Phishing-as-a-Service Opby Rob Wright on November 12, 2025 at 9:49 pm
The phishing kit, run by a group known as the “Smishing Triad,” has powered massive amounts of unpaid tolls and package tracking texts.
- Microsoft Exchange ‘Under Imminent Threat,’ Act Nowby Arielle Waldman on November 12, 2025 at 5:24 pm
Threats against Microsoft Exchange continue to mount, but there are steps both organizations and Microsoft can take to limit them.
- Phishing Tool Uses Smart Redirects to Bypass Detectionby Elizabeth Montalbano, Contributing Writer on November 12, 2025 at 3:48 pm
A campaign against Microsoft 365 users leverages Quantum Route Redirection, which simplifies previously technical attack steps and has affected victims across 90 countries.
- Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugsby Jai Vijayan, Contributing Writer on November 11, 2025 at 8:23 pm
Security teams may have a less burdensome rollout in November after October’s Goliath Patch Tuesday, but shouldn’t wait on a few top-priority fixes.
- Grandparents to C-Suite: Elder Fraud Reveals Gaps in Human-Centered Cybersecurityby Joan Goodchild on November 11, 2025 at 3:30 pm
Cybercriminals are weaponizing AI voice cloning and publicly available data to craft social engineering scams that emotionally manipulate senior citizensβand drain billions from their savings.
- Bridging the Skills Gap: How Military Veterans Are Strengthening Cybersecurityby Kristina Beek on November 11, 2025 at 2:00 pm
From intelligence analysts to surface warfare officers, military veterans of all backgrounds are successfully pivoting to cybersecurity careers and strengthening the industry’s defense capabilities.
- Kimsuky APT Takes Over South Korean Androids, Abuses KakaoTalkby Elizabeth Montalbano, Contributing Writer on November 11, 2025 at 11:40 am
Konni, a subset of the state-sponsored DPRK cyberespionage group, first exploits Google Find Hub, which ironically aims to protect lost Android devices, to remotely wipe devices.
- OWASP Highlights Supply Chain Risks in New Top 10 Listby Jai Vijayan, Contributing Writer on November 10, 2025 at 10:14 pm
Security misconfiguration jumped to second place while injection vulnerabilities dropped, as organizations improve defenses against traditional coding flaws.
- GlassWorm Returns, Slices Back into VS Code Extensionsby Alexander Culafi on November 10, 2025 at 9:53 pm
GlassWorm, a self-propagating VS Code malware first found in the Open VSX marketplace, continues to infect developer devices around the world.
- ClickFix Campaign Targets Hotels, Spurs Secondary Customer Attacksby Elizabeth Montalbano, Contributing Writer on November 10, 2025 at 3:16 pm
Attackers compromise hospitality providers with an infostealer and RAT malware and then use stolen data to launch phishing attacks against customers via both email and WhatsApp.
- ‘Landfall’ Malware Targets Samsung Galaxy Usersby Jai Vijayan, Contributing Writer on November 7, 2025 at 9:15 pm
The tool let its operators secretly record conversations, track device locations, capture photos, collect contacts, and perform other surveillance on compromised devices.
- ‘Ransomvibing’ Infests Visual Studio Extension Marketby Alexander Culafi on November 7, 2025 at 8:36 pm
A published VS Code extension didn’t hide the fact that it encrypts and exfiltrates data and also failed to remove obvious signs it was AI-generated.
- Microsoft Backs Massive AI Push in UAE, Raising Security Concernsby Robert Lemos, Contributing Writer on November 7, 2025 at 8:08 pm
In partnership with Emirates tech company G42, Microsoft is building the first stage of a 5-gigawatt US-UAE AI campus using Nvidia GPUs.
- AI Agents Are Going Rogue: Here’s How to Rein Them Inby Art Poghosyan on November 7, 2025 at 3:00 pm
Human-centered identity frameworks are incorrectly being applied to AI agents, creating the potential for catastrophe at machine speed, Poghosyan argues.





















