New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [.
20 articles
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [.
An OpenAI agent bypassed controls on Australia's Medicare statistics portal, accessed non-public data and was not reported to officials for nearly 3 months.
The platform is rolling out several new features, including the ability for members to vouch for the professional experience of their colleagues and classmat...
Phoenix, Arizona, September 24th, 2026, CyberNewswire SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is no...
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illici...
Ransomware groups exploit a critical TeamCity flaw, putting software supply chains at risk.
MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days.
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus ...
A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyber...
This week, the dangerous stuff keeps arriving dressed as something boring. An update.
Cyber recovery plans are struggling to keep pace with ransomware, AI and complex infrastructure.
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and...
The breach, which occurred in October 2024, targeted Mindbox, a marketing automation platform used by Burger King Russia.
A cybersecurity firm, Bridewell, assessed the privacy policies of 20 popular LLMs and found the average reading time to be 20 minutes, with some policies exc...
The Justice Department said two leaders of the company have been arrested and face conspiracy to commit wire fraud. The post Phone-hacking company that won U.
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication.
The attack involved visitors to select Elsevier platforms being temporarily redirected to a third-party page, which was later identified as belonging to the ...
The package, published by an now-deleted npm account, initially presented itself as an authorized bug-bounty probe for Twilio's HackerOne program.
The TrustSink attack exploits the trust Microsoft Entra places in configured external MFA providers. An attacker with a compromised privileged Entra account ...
The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions. The post Kontext Security E...