What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,922 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 7h ago
-
Gemini Live audio
Tool: Gemini Live audio Google released Gemini 3.8 Live and 3.8 Live Extended Thinking today - two new speech-to-speech models that are a similar shape to OpenAI's GPT-Live family. I pointed GPT-6 Astra Extra High at the documenta…
-
Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants…
-
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face inc…
-
Just remember that when you opt into allowing Apple to use your customer data to train AI, that means humans s…
Just remember that when you opt into allowing Apple to use your customer data to train AI, that means humans seeing and hearing details about your life that maybe you're not so comfortable sharing when you think of it that way. ht…
-
Exein Secures $270M at $1.7B Valuation for Physical AI Security
The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek .
-
AI is now leading driver of new cybersecurity spending
AI investments are expected to help automate security operations and enhance identity and access management.
-
Companies’ AI strategies don’t account for their agentic tools
Businesses are taking AI governance seriously, but their plans lag behind the technology they re using, according to an EY survey.
-
F5 Bot Defense uses real-time risk scoring to detect fraud and abuse
F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities bring persistent device context and continuous risk dec…
-
Postman Passport controls API access without exposing credentials
Postman has announced the general availability of Passport by Postman, marking the company s expansion into API security with a standalone product that gives organizations a secure way to consume APIs as human and non-human identi…
-
UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks
UltraViolet Cyber has announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence Detection Engineering (TIDE) team. Equinox maximizes detection coverage across cu…
-
Globalgig expands managed security portfolio to protect enterprise AI
Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models, and data enterprises are putting into production. The…
-
China spy chief points at US AI models in cyber threat warning
China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery…
-
6 of the Best Autonomous Penetration Testing Companies in 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 15, 2026 – Read the full story from BreachLock Summary Six vendors run autonomous penetration testing as a standalone product today: Breac…
-
OpenAI Investigates Report Linking AI Agents to RubyGems Attack
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on S…
-
Manhattan DA takes down 12 AI deepfake porn sites
Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites allowed users to use the faces and bodies of real p…
-
Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks
A new AI subscription service called Luciferus is being marketed on a hacking forum as an alternative to jailbreaking ChatGPT or Claude, Sophos found. The Counter Threat Unit (CTU) spotted the advertisement on August 24 on the Exp…
-
Microsoft sets security and safety rules for its AI models
Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six w…
-
Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared firs…
-
Akuity gives AI agents operational context to safely ship software
Akuity has introduced its Agentic Control Plane and MCP Server. Akuity s Agentic Control Plane lets AI agents accelerate software delivery by giving them the operational context and permissions to act, all governed by the same con…
-
Traefik Labs brings independent verification to AI agent governance
Traefik Labs has introduced the Sovereign Trust Plane (STP), a set of capabilities in Traefik Hub that brings verifiable evidence to AI agent governance, with general availability planned by September 30, 2026. STP connects delega…
-
Your employees are already using AI tools you never approved
Seventy-four percent of respondents report departmental or scaled AI adoption at their organizations, including within individual teams or departments, across business functions, and as part of processes and operations, according …
-
Most chief audit executives can’t tell you what AI is worth yet
Auditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department has deployed formal use c…
-
AI coming to comms systems as focus shifts to productivity outcomes: Digital Island
The next phase of AI adoption in New Zealand will centre on embedding AI directly into communications, customer engagement and operational workflows where productivity gains can be realised at scale. This is according to Digital I…
-
Anthropic's Misuse Report, Condensed to 117 Findings
The cover of the UL summary of Anthropic's September 2026 misuse report, with the eight section titles down the left side and 117 findings in the corner/images/ul-anthropic-misuse-report-2026.webphttps://share.danielmiessler.com/G…
-
Cybersecurity jobs available right now: September 15, 2026
AI Security Architect SecNinjaz Technologies India On-site View job details As an AI Security Architect, you will design secure and reliable AI agent platforms, including tools, memory, models, evaluations, and backend services. Y…
-
The contagion of fear
The contagion of fear Bryan Cantrill responds to the tweet by former Anthropic employee Jacob Coxon confirming that many Anthropic researchers believe AI "could kill us all by the end of the decade". Bryan shares a story of his ow…
-
This article makes two important points: 1. People using ChatGPT expose sensitive data because they think it i…
This article makes two important points: 1. People using ChatGPT expose sensitive data because they think it is private 2. OpenAI relies on hundreds of human contractors reviewing replies to improve their models https://www. 404me…
-
New York Seizes a Dozen Celebrity Deepfake Websites
In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200 victims.
-
Anthropic CEO: Time to Shift From Improving to Controlling AI
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
-
Using AI for Weapons Development
Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I m still reading it, but I wanted to flag this: We identified a cell of threat actors based in northern Yemen running t…
-
Security teams increasingly outflanked by AI agents
A report warns that non-human identities are growing beyond the ability of existing systems to track.
-
Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR
The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and r…
-
Quoting Laurie Voss
The cost of writing code collapsed, and the cost of reviewing, fixing and operating it is following, and I'm assuming it gets there. What's left of making software is finding out what people actually want, defining it precisely, a…
-
Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared fir…
-
Entrust turns cryptographic inventory data into security action
Entrust has unveiled new capabilities for its Cryptographic Security Platform (CSP) that help organizations turn Cryptographic Bill of Materials (CBOMs) data into action. Government agencies, financial institutions, healthcare org…
-
Bitsight connects threat intelligence and exposure monitoring across the supply chain
Bitsight access to a broad risk dataset, combining threat intelligence and continuous exposure monitoring to help teams mitigate risk across the supply chain. The surge in third-party-originating cybersecurity breaches demands a f…
-
New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity …
-
Dataminr uses agentic AI to predict and verify security threats
Dataminr has announced Dataminr Advanced for Corporate Security, delivering agentic AI capabilities that give corporate security teams the confidence to protect their people, sites, and operations before risk escalates. With Agent…
-
The Race to Control AI and Protect What Makes Us Human
As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared firs…
-
The CISO Gap Is A Huge SMB Cybersecurity Opportunity For MSSPs
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 14, 2026 – Read the Full Story in Forbes AI has fundamentally changed what a cyberattack looks like. A Forbes article reports that tools, …
-
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow s is a new record : Microsoft s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the …
-
Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe
An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.
-
Airrived adds Agentic Observability to track AI agent actions and risks
Airrived will reveal Agentic Observability, a major expansion of its enterprise Agentic OS built to give organizations end-to-end visibility into how AI agents behave, from the moment enterprise data enters the platform, through a…
-
CISOs Race to Control AI Agents Without Destroying Their Value
Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek .
-
Security teams are adopting AI faster than they trust it
New survey data reveals a widening gap between AI adoption and AI trust.
-
Demand for self-service AI fuelling growth for Snowflake
Snowflake has enjoyed another bumper year in New Zealand with demand “skyrocketing” and a boost in headcount. “The past year has been unbelievable,” Snowflake NZ country manager Tony Shaw told Reseller News at the vendor’s Snowfla…
-
Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI
The largest electronic spy agency in the world is reorganizing. And fast.
-
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to…
-
Generating running routes with GPT-6 Astra and ChatGPT Work
Here's a neat thing I had ChatGPT Work with GPT-6 Astra (Max) do this morning: I live at my address . Figure out 5K and 10K running routes from me that loop from my house. Use OSM data. It worked for 27 minutes and produced exactl…
-
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
Plus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse.
Last fetch 1m ago · 11 new · 2 source error(s)