Security intelligence
All coverage
Security signals, without the noise.
Current reporting from security alerts, threat intelligence, incident response, fraud, practitioner blogs, community feeds, and watch-and-listen sources.
[Virtual Event] Cybersecurity Outlook 2027
darkreading · 1h ago ↗sources
Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
ICE Has Been Dumping Protester Photos Into a Palantir DatabaseSecurity Latest · All coverage / Incidents
↗
Cisco IOS XE Software Security Hardening Release: August 2026Cisco Security Advisory · All coverage / Alerts
↗
Frontline Education breach exposes school district employee dataBleepingComputer · All coverage / Incidents
↗
Showing 180 of 895 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.
Complete index
Recent stories
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
Bipartisan backlash to ALPRs grows as two high-profile bills are introduced
Mississippi mayor says ransomware incident led city to shut down systems
'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
Cisco IOS XE Software Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.…
Cisco Advance Notification for Publication of October 7, 2026, Security Advisories
On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software rele…
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system wi…
Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obt…
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and…
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to ga…
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks…
Black Hat Stories | Tony Lee, Black Hat Review Board Member
Black Hat Stories | Tony Lee, VP of Operations at HackerOne
Black Hat Stories | Tony Lee, Black Hat Review Board Member and VP of Operations at HackerOne
Black Hat Stories | Tony Lee, Black Hat Review Board Member and VP of Operations at HackerOne
The legal questions raised by agentic AI hacks
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
AI policy circles targeted in China-linked phishing operation
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
NativePe: libpeconv ported to Delphi (PE loader, dumper, import rebuild, Win32/Win64)
IDA Pro 9.5 Beta (with Dalvik, TriCore, Hexagon decompilers)
Silent Hill (PS1, US v1.1) decompilation fork: 100% of code matched, nearly all data moved into C
I built an MCP server that lets AI agents debug and inspect running Windows programs (memory scan, breakpoints, disassembly) – Cortex 1.0, open source
security.txt on the Czech web: Scanning 1k popular .cz domains
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
8 out of 10 Banks HATE This One Weird 3SKey RCE
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
Favebook’s market place is just getting weirder especially with AI in the mix. #ai #meta #facebook
Google built PageBreak and it found 500 XSS on Google’s own application. That kinda hurts 😭
This WordPress Core Bug Can Lead to Remote Code Execution (CVE-2026-87902)
Ask and you shall receive. This is how a hacker got access to Meta’s Muse file system.
CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-49800 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
CVE-2026-61938 Windows Installer Elevation of Privilege Vulnerability
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
AI is giving attackers a head start, Microsoft warns
Microsoft warns AI is accelerating cyberattacks, from vulnerability discovery and phishing to malware and autonomous intrusions.
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
Chinese hackers posed as a former White House official and an economist in phishing campaigns aimed at cloud accounts of US AI policy experts.
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail.
Criminal recruiters want people on your payroll
Insider threat recruitment opens a market for employee access, enabling fraud, account takeovers and shipment manipulation online.
Preparing governments for an era of interconnected cyber risk
Insights from the 2026 Microsoft Digital Defense Report
Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected.
Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
Explore Microsoft Security at Ignite 2026: AI security sessions, hands-on labs, certifications, expert events, and networking.
Innovation wins. Why smaller beats bigger
Benedict Jones spent years working for McAfee and Sophos. While doing threat research at Sophos, he spotted a problem in mobile threat defence that nobody had actually fixed. He’s…
Heimdal partners with Elovade to bring unified cybersecurity platform to the DACH region
Heimdal and Elovade partner to bring a unified cybersecurity platform to MSPs across Germany, Austria, and Switzerland, simplifying prevention, detection, and response.
Slow is a design principle, not a delay
AI labs are pacing their capability growth. Attackers won't. Here's what that asymmetry means for cybersecurity teams and AI-enabled defense.
SHARED INTEL Q&A: AI finds flaws faster — defenders still need to fix what attackers exploit
Security teams are being told they have hours to patch. Related: AI agents have a Lord of the Flies problem The warning has a real basis. In June, Anthropic’s frontier red team…
News alert: Archipelo launches Salmon to create verifiable audit trails for AI agent activity
SAN FRANSICO, Sept. 25, 2026, CyberNewswire тАФ Archipelo today announced Salmon, Execution Verification Infrastructure (EVI) for AI agents and autonomous systems, powered by a cr…
Guest Essay: Before AI agents takes hold, define who can challenge them and who owns the outcome
Early in my military career, I learned a simple lesson: when you give people a task, you also have to give them room to think. Related: AI agents take initiative, unchecked As a y…
Recorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats
Recorded Future just revealed autonomous defense capabilities. The platform hunts, investigates, and stops threats on its own, acting on real intelligence.
Social Engineering in the Age of Synthetic Media
How AI Changes Phishing, Impersonation, and Identity Verification
Recorded Future Launches MCP, the Intelligence Layer for Agentic Security Operations
Recorded Future launches Model Context Protocol (MCP), providing AI agents and LLM workflows direct access to the Intelligence Graph® for accurate, automated decision-making.
Introducing the new Copilot with Home, Code and Autopilot
Building the system for AI at work
There's no shortage of sound and fury in AI right now.
Introducing Microsoft 365 G7: Intelligence + Trust for the mission ahead
Microsoft 365 G7 brings AI, Copilot, agent governance, security, and compliance together to help government agencies modernize securely.
MacSync under the microscope: new delivery methods and a new payload
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managi…
The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the Solana blockchain to hide…
Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industry’s First Unified Agentic System
A single system for intent and access to empower organizations to adopt AI without losing data control or missing emerging risks across employees and AI agents Point security tools
Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era
Intent-based detection and multi-stage AI reasoning identify and stop sophisticated attacks before, during and after they reach people. Stops sophisticated attacks in one connected
Proofpoint Recognizes 2026 Global Partner Award Winners at Flagship Event
The awards presented at Proofpoint Protect 2026 celebrate partners driving customer impact, growth and secure AI adoption worldwide.
Ransomware: A Continuing Threat for Small Businesses
Ransomware remains one of the most damaging cybersecurity threats facing small businesses. Here are some ways to prevent risk.
AI in Tax Season: Risks, Scams, and How to Protect Your Data
Protect yourself this tax season while using AI. Learn how to safely leverage AI tools, avoid tax scams, and ensure your filings are accurate with guidance from Alloy Silverstein…
Tax Season Scams to Watch For This Year
Tax season is a busy time for taxpayers and, unfortunately, a busy time for scammers as well. Each year, the Internal Revenue Service continues to warn individuals and businesses…
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
A Tale of Two SOCs: Insights From Two Red Team Assessments
Same tactics, very different results. This advisory compares defensive outcomes from two red team assessments. Learn what drove detection and implement key
Defending Against an Active Threat to Siemens S7 Series PLCs
This advisory warns of threat actors targeting Siemens S7 Series programmable logic controllers (PLCs) and includes mitigations to be understood and applied
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, Author: Johannes Ullrich
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
No matching sources found.
Showing 180 of 895 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.