What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,926 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 4h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 8h ago
-
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cyber deception has long been the domain of well-resourced security teams, but CISA s latest guidance, titled Using Cyber Decoys to Strengthen Detection and Response , is an attempt to try and change that. Why decoys, and why now …
-
CISA Releases Guidance on Deploying Cyber Decoys
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek .
-
CISA promotes a fresh way to deter cyberattackers: Lie to them
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. The post CISA promotes a fresh way to deter cyberattackers: Lie to them app…
-
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a la…
-
How the Meta Settlement Silences Youth Activism
Since its integration into our digital world, social media has played a pivotal role in youth organizing and social mobilization. Yet, people’s access to these platforms is increasingly coming under threat from courts and legislat…
-
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
I need people that can pivot from day to day, the agency s acting chief told reporters.
-
NIST and CISA finalize playbook to stop token theft and forgery
NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, T…
-
MSPs say nearly half their customers rely on them for CISO services
MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the work across several too…
-
Norway announces investigations into telecom Telenor’s work with Myanmar junta
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
-
What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA s CDM program that gives cybersecurity tools to federal agencies appeared first …
-
Members of ‘Black Axe’ cybercriminal group extradited from South Africa
Prosecutors unsealed a 2021 indictment accusing the five men of conducting lucrative romance scams that stole thousands of dollars from more than 100 people.
-
Hey due to upcoming EU regulation I just wanna clarify that when I talk about catgirls I am specifically talki…
Hey due to upcoming EU regulation I just wanna clarify that when I talk about catgirls I am specifically talking about Cat Women who are 21+ in human years
-
Karavshin – (an overcast) day two: clambering up to Jalgychy – and “surfing” back.
Salam elim! On the Karavshin trek across the Pamir-Alay mountain system, summer weather is normally glorious. Mornings bring guaranteed blue skies, by midday a few insignificant little clouds might swell up (or possibly rather mor…
-
CISA is on the verge of filling hundreds of critical vacancies
Meanwhile, the agency is finalizing an incident-reporting regulation and setting up a new industry coordination structure.
-
Democratic Senators Ron Wyden and Sheldon Whitehouse as well as GOP congressman Pat Harrigan of North Carolina…
Democratic Senators Ron Wyden and Sheldon Whitehouse as well as GOP congressman Pat Harrigan of North Carolina sent a letter to U.S. Secretary of Commerce Howard Lutnick, urging him to add three Indian companies to the department’…
-
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is th…
-
NIS2 compliance: Fixing IAM and access control before the 2026 audit
The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member…
-
ShinyHunters claims it stole 284 million patient records from McKesson
Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and o…
-
CISA identifies security hurdles that led to very different results in two red-team engagements
The agency said its recent simulated cyberattacks offered several key lessons for many organizations.
-
Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns. The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek .
-
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure ap…
-
Medical device firm Boston Scientific says cyberattack has disrupted shipment processes
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
-
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as simil…
-
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWe…
-
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching …
-
Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simul…
-
Cybersecurity jobs available right now: August 25, 2026
Specialist Compliance Security AT T USA On-site View job details As a Specialist Compliance Security, you will serve as AT T s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24 7 to emer…
-
US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
-
SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules
The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one…
-
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on Cybe…
-
House Democrats ask GAO to study CISA workforce cuts
The five lawmakers, who serve on the Homeland Security Committee, said Congress didn t know enough about the Trump administration s changes to the cybersecurity agency.
-
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspension…
-
CISA’s logging guidance works beyond government
The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you ve collected to catch it and rec…
-
Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the …
-
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, th…
-
Lawmakers call for investigation into impact of CISA staffing cuts
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
-
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others. The post Eight years later, federal authorities re-up charges ag…
-
Hackers target Ukrainian agency managing assets seized from sanctioned Russians
The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.
-
IAM Compliance Requirements and Best Practices
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM com…
-
Weak IAM affects up to 98% of cloud environments
Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now m…
-
Arctera enhances Unified Platform for evidence-driven compliance workflows
Arctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and response workflows across the compliance lifecycle. These …
-
Dismiss Church’s Trademark Lawsuit Against “Mormon Stories” Podcast, EFF Urges Court
Imagine if McDonald’s could use trademark law to control how you use the term “fast food.” Or if the Canadian government could stop you from using the word “Canada” in the title of a book about the country and its people. That wou…
-
New Zealand sanctions Russian hackers, propaganda groups over Ukraine war
New Zealand announced new sanctions on Russian hackers, technology companies and Kremlin-linked organizations over their roles in supporting Moscow’s war against Ukraine.
-
Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addr…
-
Military device manufacturer discloses cyber incident to SEC
IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.
-
DHS Wants Protesters’ Signal Group Chats
A lawsuit accuses Homeland Security of violating protesters’ free-speech rights—but the agency is using it to try to get access to the plaintiffs’ encrypted communications.
-
CISA is prioritizing work with critical infrastructure as it begins to recover from cuts
The agency has been focused on helping secure systems at drinking and wastewater utilities in recent weeks.
-
37% of IT Security Teams Hit Burnout From Audit Demands
A Huntress survey of 504 IT leaders found that compliance demands caused burnout at 37% of orgs, delayed security initiatives at 34%, and cost 21% a contract.
-
Fake IRS letters target cryptocurrency holders
Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sounds like someone is trying to scam you…
-
Foreign Hackers Hit America's Water. Trump Blamed a Democratic Governor. CISA Is Cutting Its Experts' Pay.
"We know these changes may result in financial hardship for some," Acting Director Nick Andersen wrote to staff, weeks after DHS told Congress the agency needs 600 more people.
Last fetch 13m ago · 1 new · 2 source error(s)