Curated Feed

Security Intelligence Digests

Latest AI and Cyber Security news with Refract Digests—curated insights from trusted sources with BLUF summaries and actionable analysis. (56 articles)

Dark Reading

Outdated Cybercrime Laws Put Security Researchers at Risk

Outdated global cybercrime laws expose security researchers to legal risks, prompting a new five-point framework to protect ethical hacking efforts.

A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.

View More
Dark Reading

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

Attackers are exploiting a new vulnerability called GhostJacking to hijack AI agents by manipulating security alerts. This reveals significant gaps in how organizations govern identity and access for automated systems.

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.

View More
Dark Reading

Multistate Water System Attacks Widen, Iran Suspected

Suspected Iranian hackers are attacking water systems in over a dozen US states by exploiting insecure internet-connected controllers. This campaign highlights critical vulnerabilities in public utility infrastructure security.

Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.

View More
Dark Reading

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A critical unpatched flaw in Metabase allows attackers to take full control of business analytics platforms remotely. This zero-day vulnerability poses a significant risk to organizations using the tool for data analysis.

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.

View More
Schneier on Security

Friday Squid Blogging: Arctic Bobtail Squid Video

This weekly post shares a nature video and invites readers to discuss unreported security news in the comments. It serves as a community hub rather than a formal intelligence briefing.

Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

View More
Schneier on Security

ICE Is Buying Access to Credit Card Records

ICE is purchasing personal credit card application data from commercial data brokers to access financial information without direct consent.

Through data brokers, ICE is buying the information you provided to open a credit card.

View More
Dark Reading

AI-Generated Patches Fail Half the Time

Recent research indicates that half of AI-generated software patches fail or introduce new vulnerabilities despite appearing functional. Organizations using automated remediation tools must verify these fixes manually to prevent worsening security risks.

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.

View More
Krebs on Security

Canadian Man Pleads Guilty in Snowflake Extortions

A Canadian cybercriminal pleaded guilty to hacking over 165 companies via Snowflake and stealing AT&T customer data, marking a significant legal development in recent cloud extortion cases.

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organiz...

View More
Schneier on Security

Adversarial Clothing Designed to Fool Facial Recognition Systems

Vendors are marketing clothing designed to evade facial recognition, though experts warn the technology is untested and primarily serves as a symbolic act of resistance.

There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I worry that it’s mostly security theater: “Our patterns play with th...

View More
Dark Reading

The Coordination Gap: How Attackers Are Outpacing Law Enforcement

Cybercriminals are evolving faster than police can respond because law enforcement agencies still work separately instead of together. This gap allows attackers to stay ahead of legal deterrents and continue their operations.

The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.

View More