Latest stories — Page 88

Critical Argument Injection Zero-Day in Gogs Puts Self-Hosted Git Servers at Risk
A CVSS 9.4 flaw lets authenticated attackers execute arbitrary code through maliciously named pull-request branches — no patch is available.

GREYVIBE: The Russian-Speaking Threat Actor Targeting Ukraine
Persistent attacks align with Kremlin interests, spotlighting continuous geopolitical cyber warfare.

Shadow Builders: When Employees Ship Production Apps Without Auth
Vibe-coded internal tools are graduating to public URLs, and most identity stacks never see them coming.

California Sues 23andMe's Bankruptcy Successor Over 2023 Data Breach
AG Rob Bonta is going after Chrome Holding Co. — the shell 23andMe rebranded into after its bankruptcy — arguing the company failed to adequately protect the genetic and personal data of millions of users.

Typosquatted NuGet 'Sicoob.Sdk' Hoovers PFX Certs From Brazilian Banks
A poisoned package impersonating Brazil's Sicoob co-op banking network exfiltrates client IDs and PFX certificates — the same certs that sign API calls into the financial system.

What S&P 200 CISOs Are Actually Telling the SEC About Cybersecurity
A fresh read of 2024–2025 10-K Section 1.C filings shows NIST CSF dominance, audit committee capture, and a suspicious abundance of 'no material impact' disclosures.

Gentlemen Ransomware Spreads Before It Encrypts — That's the Whole Point
Microsoft's analysis of the Go-based Gentlemen encryptor shows why lateral movement, not file-locking, is now the primary design goal of serious ransomware operations.

GDPR Fines and the Looming AI Regulation Battle
As AI tech faces scrutiny, GDPR's enforcement lessons underline the coming regulatory challenges.

Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets
The DPRK-linked crew is spoofing Webex pages and antivirus installers to drop new implants on military and corporate networks.

Critical Argument Injection Flaw in Gogs Remains Unpatched
Authenticated users can exploit a critical flaw in Gogs, posing security risks for internal Git deployments.

Dark Reading Turns 20: The Name That Toon Caption Contest Is Back
A cybersecurity cartoon contest is a low-stakes way to mark two decades of covering an industry that never stops generating material.

GreyVibe's AI Playbook: What Russia-Linked Operators Are Actually Doing With ChatGPT and Gemini
A threat actor researchers are calling GreyVibe is reportedly weaving commercial AI tools into its attack workflow. The real story isn't the hype — it's the operational specifics.

Authenticated RCE in Gogs Hits CVSS 9.4 — and There's No CVE Yet
A critical flaw in the self-hosted Git service lets any logged-in account execute arbitrary code on the server. The auth bar is low. The blast radius isn't.

Geordie Lands $30M to Tackle AI Security and Governance
Balderton Capital leads a Series A into the AI governance startup, joined by Crosspoint Capital and returning backers General Catalyst and Ten Eleven Ventures.

Patched FortiClient EMS Flaw Still a Live Attack Vector for Credential Theft
Attackers are piggybacking on Fortinet's endpoint management tooling to push infostealers disguised as legitimate agent updates.

Microsoft Reasserts Coordinated Disclosure Norms After Researcher Drops Zero-Days
Redmond is invoking CVD principles after a researcher publicly posted unpatched flaws, raising fresh questions about the boundary between disclosure ethics and platform enforcement.

When 'Minor Foothold' Means Full Account Takeover: The Week IAM Bent the Wrong Way
A Claude security plugin, an Azure privilege-escalation chain, and a Kali365 MFA bypass all land in the same news cycle. Identity is still the soft underbelly.

FortiClient EMS Flaw Sees Fresh Exploitation After April Hotfix
Attackers are still hitting a critical FortiClient EMS vulnerability that Fortinet patched — and flagged as actively exploited — months ago.

The Real Bottleneck in Network Incidents Isn't Detection — It's Everything After
Monitoring catches the spike in seconds. Then the Slack thread starts, and the clock keeps running.

IBM and Red Hat Pledge $5 Billion to Lock Down Open Source Supply Chains via Project Lightwell
The initiative targets a deceptively hard problem: patching vulnerabilities in open source dependencies without breaking production workloads that millions of systems depend on.

Enterprise AI Risk Concentrates in a Sliver of Power Users, Report Finds
A new visibility study says the bulk of corporate AI exposure traces back to a thin slice of heavy users — most of it invisible to security teams.