Who we are:
Cybrfunk was created on January 17, 2021 with the intent of making reliable cyber security news and threat intelligence more accessible to the public. With this in mind, we aim to provide a central hub for all of the best cyber security news and threat intelligence. In an ever changing landscape we hope to make your trip a little easier and safer.
Latest Articles:
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks.
Friday Squid Blogging: I Caught a Squid
On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA. We caught many cod (none of which we could keep),…
AI Scramble Drives Cybersecurity M&A Boom
Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What's different: Many of the buyers…
What We Missed: FBI Strikes Back at ShinyHunters
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected…
Security Threats Don’t Stop at the Office: Why Executives’ Families Need Training Too
Those closest to executives must match their security postures because the weakest link in a family becomes the entry point for attacks.
Hundreds of thousands impacted by data breach at biosensor firm iRhythm
A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer.
FBI touts another ShinyHunters arrest in response to data breach
“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate,"…
Belarusian hacktivists admit to 2023 breach of Russian state healthcare network
The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health.
How to keep AI agents within their permissions
AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains…
OpenAI says it disrupted Russian and Iranian influence ops that used ChatGPT
A Latin American propaganda operation run by Russians and a cluster of Iranian fake journalist identities each had help from now-closed ChatGPT accounts, OpenAI's safety…
Social Engineering AI Agents: The New BEC for 2026
As AI agents gain authority over business systems, attackers can manipulate them like business email compromise (BEC) victims.
Max severity SonicWall SMA1000 flaw now exploited in attacks
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.
In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry.
Man admits to running network of 15,000 money mules for cybercriminals
A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide.
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.