The former core infrastructure engineer deleted admin accounts, reset hundreds of passwords, and demanded 20 bitcoin to spare the company’s servers.
It Wasn’t Me, It Was the AI Agent” May Not Avoid Liability Under New Senate Proposal
Odia Kagan of FoxRothschild writes: “It wasn’t me, it was the AI agent” may not help companies avoid civil or criminal liability under a new bipartisan…
Ransomware Recovery Scheme Nets $11M Markup
A ransomware recovery operator has been exposed for running a scheme that generated $11 million in markups by secretly paying ransoms and reselling…
Anthropic AI agent gives fake murder tip to US cops in global breach
Georgia Wells and Joseph Pisani report: Rogue AI models have hacked companies and tried to break into government websites. Now one has submitted a fake…
Europol and US GAO Warn of Quantum Computing Threats
Europe’s leading law enforcement agency and the US government’s spending watchdog released reports this week urging organizations to accelerate adoption…
IT Security News Hourly Summary 2026-10-10 13h : 6 posts
6 posts published in the last hour 10:31Oracle Health breach affects nearly 20M 10:31Three days to TechCrunch Disrupt: What’s next for AI and software development 10:31Two characters open up a world of typosquatting opportunities in Chromium browsers 10:05IT Security News…
Oracle Health breach affects nearly 20M
Oracle Health has confirmed that a data breach impacted approximately 20 million individuals, marking a substantial increase from figures reported in…
Three days to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code…
Two characters open up a world of typosquatting opportunities in Chromium browsers
Attackers abusing rare Cyrillic and Latin letters to impersonate popular websites
IT Security News Roundup: 2026-10-10 Morning
IT Security News: Morning roundup, 2026-10-10 REA links AI assistants like Claude Code to reverse-engineering tools. Hackers compromised over 500 GitHub accounts to steal API keys. SANS ISC warned against replacing internal data classifications with TLP. Coupang challenged a massive…
Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
Anthropic on Friday said it’s cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its…
IT Security News Hourly Summary 2026-10-10 12h : 5 posts
5 posts published in the last hour 09:31REA Tool Connects Claude Code and Cursor to Ghidra and IDA Pro to Reverse Engineer Anything 09:31GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials 09:31Why TLP should not…
REA Tool Connects Claude Code and Cursor to Ghidra and IDA Pro to Reverse Engineer Anything
REA, short for Reverse Engineer Anything, connects AI coding agents such as Claude Code and Cursor to tools that inspect software without its source code.…
GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials
A new GhostAction campaign has expanded to more than 500 compromised GitHub accounts and has injected malicious workflows into tens of thousands of…
Why TLP should not replace your internal information classification, (Sat, Oct 10th)
The Traffic Light Protocol (TLP)[1], which is now in its second incarnation, is a wonderful standard that enables one to easily communicate whether…
KR: Coupang files lawsuits against 620 billion won fine over data leak
The Coupang breach in South Korea has stayed in the news cycle for nine months and may offer a useful case study in how not to respond to an incident. In…
IT Security News Hourly Summary 2026-10-10 11h : 8 posts
8 posts published in the last hour 08:31US government lagging in transition to post-quantum encryption, GAO finds 08:31Core to Cloud Appoints David Brown as Managing Director 08:31Apple’s Verified Photography System 08:01Iranian VPN-over-DNS Activity Generates 40 Billion DNS Observations During Military…
US government lagging in transition to post-quantum encryption, GAO finds
Auditors warned that agencies risked leaving sensitive data exposed to future decryption attacks.
Core to Cloud Appoints David Brown as Managing Director
UK cybersecurity specialist Core to Cloud has appointed David Brown as Managing Director, strengthening its leadership team as the company looks to expand…
Apple’s Verified Photography System
Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a…
Iranian VPN-over-DNS Activity Generates 40 Billion DNS Observations During Military Conflict
A newly disclosed unprecedented surge in suspected Iranian VPN-over-DNS activity, with one domain generating 40 billion passive DNS observations within…
Writing the Next Chapter
Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.
US Sentences Empire Market Co-Creator Over $430 Million Criminal Marketplace
Empire Market co-creator Raheim Hamilton was sentenced to 40 years in prison for running a dark web marketplace linked to $430 million in illegal trades.…
DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government Data
DarkBlinders hackers are deploying a fake video meeting application and abusing GitHub repositories in a cyberespionage campaign targeting Israel and the…
