Security intelligence
All coverage
Security signals, without the noise.
Current reporting from security alerts, threat intelligence, incident response, fraud, practitioner blogs, community feeds, and watch-and-listen sources.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
darkreading Ā· 1h ago āsources
ChatGPT Astra is now rolling out to $20 Plus subscription
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationThe Hacker News Ā· All coverage / Incidents
ā
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecastHelp Net Security Ā· All coverage
ā
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesSecurityWeek Ā· All coverage / Incidents
ā
Showing 180 of 789 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.
Complete index
Recent stories
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
ChatGPT Astra is now rolling out to $20 Plus subscription
OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access..
Attackers conceal phishing lures using invisible Unicode characters
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters.
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSCā¦
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treatedā¦
DEF CON SG1 - CSIT Village - Ernest Ang - From Chrome Renderer, To Mouse To System
DEF CON SG1 - CSIT Village - James Tan - Uncovering Hidden Threats: CSIT Qpproach
DEF CON SG1 - CSIT Village - Liu Wen Kai, Martin Koh - Your Next Forensic Analyst is AI Agents
DEF CON SG1 - CSIT Village - Anton Chua - Cyber Physical: The Soft Underbelly?
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
Hereās an overview of some of last weekās most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers
Synology ActiveProtect Manager 2.0 improves AI-driven security
Synology ActiveProtect Manager 2.0 extends protection to Amazon EC2, Azure VM, Proxmox VE, Nutanix AHV, and Google Workspace.
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild.
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new Teams feature to help users stay safe from QR code phishing, with rollout set for October 2026.
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
In Other News: Microsoftās Cloud Patches, Hacked Dropbox Accounts, Guardioās $1.1B Valuation
HPE Patches Critical RCE Vulnerabilities in AOS-CX
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
How to secure edge AI in customer-owned environments
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, aā¦
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deā¦
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Expertsā¦
Angry Birds: Toy Ghoulsā new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the oā¦
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
Threat landscape for industrial automation systems. Q2 2026
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systā¦
Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization
Recorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits.
H1 2026 Malware Vulnerability Trends
Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security.
The Agentic SOC ā From AI Theater to Real Defense
Experts from Recorded Future and Accenture offer perspectives on navigating the path to becoming an agentic SOC. Find out how to plan moving beyond āAI theaterā by prioritizing meā¦
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe
PPCC 2026: Bringing AI and your business processes together
Learn how Microsoft 365 Copilot, AI agents, and Power Platform can transform business processes at PPCC 2026.
The next measure of AI momentum is work transformed
New data from Microsoft 365 Copilot telemetry signals, along with examples from our customers around the world, demonstrate AI transformation in action.
Copilot in Excel: Built for the era of Frontier Finance
- Discover how Copilot in Excel transforms finance workflows with skills, data connectors, and capabilities for traceability.
Copilot Cowork is now generally available
Copilot Cowork is now generally available worldwide, bringing secure, AI-powered automation for complex enterprise tasks in Microsoft 365.
Shift Browser is signed adware that fingerprints your endpoint before it drops payload
Heimdal SOC flagged Shift Browser adware across 50+ client environments. See how the signed installer fingerprints endpoints before dropping its payload, plus IOCs and MITRE mappiā¦
6 ThreatLocker alternatives that should make your shortlist
6 handpicked ThreatLocker alternatives. Some are direct ThreatLocker competitors, others let you manage clientsā environments differently.
50+ insider threat statistics for 2026
In 2026, insider threats are probably a bigger risk than you think. In fact, they could cost your organization $19.5 million a year. But itās not really a problem with hackers, spā¦
The Planting Seeds philosophy. Selling into schools takes years, not quarters
Itās tempting for MSPs to write off event sponsorship in education as a waste of money. You sponsor an event, hand out flyers, follow up with an email, and hear nothing back. Rickā¦
Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster
New Proofpoint SOC Analyst Agent combines Proofpoint security expertise with OpenAI Daybreak models to help analysts investigate threats, connect security signals and determine neā¦
Cybercriminals Turn to Indirect Prompt Injection Attacks
Cybercriminals are developing indirect prompt injection tools to target AI agents.
Russian hackers can steal emails without a click
Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Todayās Most Sophisticated Threats
Recognition highlights Proofpoint's deep technical integration with Google Cloud Security solutions and commitment to helping organizations protect people, data and AI Helps
Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attackeā¦
Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.ā¦
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnā¦
FBI Probes Service Selling 153M+ Drivers Licenses
Two Alleged āTeamPCPā Hackers Arrested in Australia
Whoās Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is alrā¦
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, Author: Johannes Ullrich
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
News alert: Airlock Digital IRAP assessment bolsters trust for sensitive Australian deployments
ADELAIDE, Australia, August 19th, 2026, CyberNewswire Ć¢ā¬ā Airlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completā¦
News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week
Melbourne, Fla., August 17, 2026, CyberNewswire Ć¢ā¬ā Continuing its effort to build global awareness of the need to move computing from assumption-based trust to cryptographic prooā¦
MY TAKE: Black Hat 2026 Part 3 ā Agentic AI can do the work, but somebody has to prove it
Security work used to leave a trail without anyone trying. A developer who wanted an open source library went and got it, and the license came along. An analyst who closed a caseā¦
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
Learn how Microsoft Azure Integrated HSM delivers hardwareāenforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and openāsource collaboration.
Defending Against China-Nexus Covert Networks of Compromised Devices
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
U.S. organizations should review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the
AI in Tax Season: Risks, Scams, and How to Protect Your Data
Tax Season Scams to Watch For This Year
Beware of Misleading Tax Advice on Social Media
Each year the IRS educates taxpayers on the most trending fraud schemes that could deceive individuals and businesses during tax season. In late 2024, The IRS took to warning theā¦
Student Loan Breach Exposes 2.5M Records
2.5 million people were affected, in a breach that could spell more trouble down the line.
Watering Hole Attacks Push ScanBox Keylogger
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tentacles of ā0ktapusā Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
No matching sources found.
Showing 180 of 789 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.