Zoom warns of critical account takeover vulnerability

Zoom Issues Critical Warning for Account Takeover Vulnerability Affecting Millions of Users Worldwide A critical vulnerability has been discovered in Zoom’s desktop client and software development kit for Windows, which could be exploited by an unauthenticated party to hijack user accounts. The security issue, tracked as CVE-2026-53412, affects millions of users who rely on the … Read more

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

A new iteration of the TuxBot malware, dubbed TuxBot v3 Evolution, has been discovered, showcasing an alarming trend towards leveraging Large Language Models (LLMs) for developing IoT botnets. This sophisticated threat not only highlights the evolving cyber threats landscape but also underscores the importance of bolstering IoT security measures. TuxBot v3 Evolution is a refined … Read more

Guten Tag, Bonjour, Hola to Our European Cyber Defenders!

Europe’s Cyber Defenders Get a Boost with New Region-Specific Intelligence In a bid to provide cybersecurity professionals across Europe and the UK with tailored intelligence and insights, Dark Reading has launched its latest section: DR Global Europe. This new initiative aims to fill a critical gap in threat intelligence by offering region-specific analysis that speaks … Read more

We built a vulnerability vending machine: AI tokens in, zero-days out

Cybersecurity researchers at Intruder have made a groundbreaking discovery in the field of vulnerability research, leveraging artificial intelligence (AI) tokens to automatically identify zero-day vulnerabilities in production software. In an experiment that has sparked both excitement and concern, the team successfully used Large Language Models (LLMs) to find a novel SQL injection zero-day in a … Read more

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A sophisticated malware framework, OkoBot, has been discovered injecting phishing attacks into popular cryptocurrency wallet apps Ledger and Trezor, compromising user accounts and potentially leading to significant financial losses. The malicious software injects a fake seed phrase into these wallets’ authentication screens, tricking users into entering their sensitive information. This deception is made possible by … Read more

CISA warns admins to patch actively exploited SharePoint flaws

Critical SharePoint Vulnerabilities Being Actively Exploited, CISA Warns A major cybersecurity threat has been identified by the US Cybersecurity and Infrastructure Security Agency (CISA), which warns that attackers are actively exploiting three vulnerabilities in Microsoft’s popular SharePoint Server software. The affected flaws, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, allow hackers to bypass authentication, gain remote … Read more

We built a vulnerability vending machine: AI tokens in, zero-days out

Cybersecurity researchers at Intruder have developed a cutting-edge system that leverages artificial intelligence (AI) to automatically discover and exploit previously unknown security vulnerabilities in production software. Dubbed a “vulnerability vending machine,” this AI-powered pipeline has successfully identified a zero-day SQL injection vulnerability in a popular WordPress plugin used by over 300,000 users. The Intruder team’s … Read more

​ ​AsyncAPI npm packages infected with credential-stealing malware

A Supply-Chain Attack Unfolds: AsyncAPI Packages Compromised with Credential-Stealing Malware In a brazen supply-chain attack, five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in just four hours and seven minutes. The compromised packages, part of the @asyncapi namespace, had a staggering cumulative weekly download count of over 2.25 million. … Read more