What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,942 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 10h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 14h ago
-
AIs Compress Exploit Timeline
Give an AI agent a mere rumor of an exploit, and it s enough for them to find it. What s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it w…
-
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executiv…
-
Scytale expands vendor risk management with AI-powered TPRM tools
Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a conti…
-
WordPress adds automated security checks to block risky plugin releases
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be…
-
Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek .
-
The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIF…
-
Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online
InquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview.
-
Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their…
-
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [..…
-
Apple is building photo verification for the people who need it most
Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. Apple Reference Image provides users with an unalterable reference photo, visually confir…
-
Microsoft fixes bug that wiped Windows desktop settings
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]
-
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts…
-
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security ris…
-
EU Cyber Resilience Act to Enforce New Reporting Requirements
Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.
-
Trezor warns users of email provider breach, phishing attacks
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]
-
The Boring Way to Get to AI Taking Over Everything
A charcoal sketch of a faceless purple robot working the levers of a dense industrial machine, beside an empty office chair with a worker's cap left hanging on it/images/slow-path-to-ai-takeover.webp/images/slow-path-to-ai-takeove…
-
McKesson: 6,404,340 accounts breached
Data exposed: Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses. In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay …
-
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential paths. The families active now cast a much wider net. Shai-H…
-
Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of deliveri…
-
AI adoption brings new security headaches for already stretched CISOs
CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the C…
-
AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key
An AD RMS Service Group account exports the AD RMS Server Licensor Certificate private key. That 1172-byte key decrypts every document the deployment ever protected, offline, and keeps doing so after the deployment is rebuilt.
-
At least one in three roles eliminated by AI will be restored by 2029 at a higher cost: Gartner
Gartner on Wednesday said that it expects 30 per cent of the positions eliminated by AI-related layoffs to be refilled by 2029, suggesting that the initial terminations were ill-advised and excessive. “When business and IT executi…
-
Quoting Calif Research
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...] The victim does not need to answer the call, or interact with their phone at all. Even if they do answ…
-
First Focus boosts NZ presence through Resolve Technology buy
Australian-founded First Focus has further boosted its New Zealand presence by acquiring Wellington-based managed IT services provider Resolve Technology. This is First Focus’ fourth New Zealand acquisition this year, bringing its…
-
Spark launches dedicated data centre interconnect service with Ciena
Spark Wholesale has launched a dedicated data centre interconnect (DCI) service between regional data centres in Auckland to meet growing demand for secure, high-capacity data transmission. The company is using NYSE-listed high-sp…
-
CVE-2026-86060: MikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
-
CVE-2026-67277: MikroTik RouterOS — MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
-
.blend URL Viewer
Tool: .blend URL Viewer I'm continuing to have a lot of fun with GPT-6 Astra and Blender (see my TIL ). As a big fan of the Imperial Fabergé Easter eggs , I've always thought it would be fun to make some new ones that celebrate po…
-
Smartsheet promotes Jarrod Kinchington to head up APAC
Enterprise work management platform Smartsheet has promoted its Australia and New Zealand (A/NZ) vice president Jarrod Kinchington to lead the Asia Pacific (APAC) region. As vice president and general manager of APAC, Kinchington’…
-
Smashing Security podcast #484: How websites are tracking you with silence
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. An…
-
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
-
AdaptHealth confirms 4.1 million people exposed in July cyberattack
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]
-
Threat matrix: Mapping threats across cloud web applications
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat m…
-
Mythos Vulnerability Firehose Hits a Human Bottleneck
An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.
-
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. The post Chinese espionage groups swarm to exploit triple-link ch…
-
San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads
The City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction.
-
Four groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors.
-
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology s next evolution.
-
Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR
Law enforcement agencies across the country are increasingly relying on spying technologies— automated license plate readers (ALPR), cell-site simulators , and facial recognition , to name a few--causing an outcry in many communit…
-
US Government Accuses Chinese AI Firms of Distilling Frontier Models
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
-
FTC rescinds policy requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. The post FTC rescinds policy requiring health apps to …
-
Apple Doesn’t Want You to Worry About the New Apple Watch’s Listening Features
The new Apple Watch includes several “intelligent” listening features that have privacy and security baked in. But the protections can’t change the facts of what the tools do.
-
Democratic Senators Ron Wyden and Sheldon Whitehouse as well as GOP congressman Pat Harrigan of North Carolina…
Democratic Senators Ron Wyden and Sheldon Whitehouse as well as GOP congressman Pat Harrigan of North Carolina sent a letter to U.S. Secretary of Commerce Howard Lutnick, urging him to add three Indian companies to the department’…
-
Lawmakers call on Commerce to sanction hackers-for-hire
The groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race. The post Lawmakers call on Commerce to sanction …
-
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service,…
-
Digital Sovereignty: What It Is, What It Could Be
The term “digital sovereignty” has become ubiquitous. European officials invoke it in debates about cloud infrastructure, AI , semiconductors , and platform regulation. Governments throughout the global majority use it to argue fo…
-
A Pentagon Memo Called It an "Arms Race." That Was the Point.
Nobody outside the AI labs can measure who is winning, so the numbers come from those who profit from them. Call it an arms race and the claim you cannot verify becomes an order you cannot question.
-
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDriv…
-
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first …
-
You Can Now Destroy Flock Cameras for Cash in GTA V
A new GTA mod lets you smash and shoot Flock’s automatic license plate readers around the fictional Los Santos.
Last fetch 9m ago · 0 new · 2 source error(s)