Security intelligence
All coverage
Security signals, without the noise.
Current reporting from security alerts, threat intelligence, incident response, fraud, practitioner blogs, community feeds, and watch-and-listen sources.
[Virtual Event] Cybersecurity Outlook 2027
darkreading · 1h ago ↗sources
CISA alerts of active exploitation of three Linux kernel flaws
EU data regulator fines Google more than $460 million for location data violationsThe Record from Recorded Future News · All coverage / Incidents
↗
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDRThe Hacker News · All coverage / Incidents
↗
Google Hit With $463 Million Fine for EU Location Data Rule BreachSecurityWeek · All coverage / Incidents
↗
Showing 180 of 881 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.
Complete index
Recent stories
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the plat…
Microsoft to retire Microsoft 365 Companion apps in December
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices.
Google fined €403 million over location data privacy violations
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data.
EU data regulator fines Google more than $460 million for location data violations
Belgian table tennis, gymnastics federations hit by cyberattacks
Cyberattack hits University of Munich, potentially exposing student financial data
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
Implant Encryption via the Dump Encoding Library
ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553
Three memory-safety bugs in Godot's untrusted-file parsers
Silent packet loss in PcapSplitter: a file collision bug on TCP session reuse
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
Google Fined €403 Million Over GDPR Violations Tied to Location Data
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
Droid ASC: A Super FAST Android Decompiler, 41 to 269 Times Faster Than JADX
Inside BambooToken’s Linux implant: shell and file control over MQTT
Reverse Engineering ZTE SmartHome App Led to an Account Takeover Affecting the Entire Account Backend. 4 CVEs
Beyond MCP: A Workspace for Reverse Engineering
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
The TASK#STOMP backdoor steals office documents on Windows PCs, grabs new files as they're saved, and can rebuild itself if partly removed.
Fastly gives enterprises real-time control over AI models and agents
Fastly adds runtime controls, an AI firewall, and API security to help enterprises govern models, applications, agents, and costs.
North Korea’s job interview scam runs both ways
How North Korea's Contagious Interview scam targets developers and infiltrates companies - plus defenses for both.
Google hit with €403 million GDPR fine over location tracking
Ireland’s DPC hits Google with a €403 million fine over location-data practices, ordering compliance with EU GDPR within 6 months.
BLACK HAT FIRESIDE CHAT: Nobody picked the web browser to run work — now pick a boundary
Nobody picked the browser to run the workplace. It just happened. Related: The year of the enterprise browser HTML5 matured. SaaS spread. One business application after another mo…
MY TAKE: AI agents show uncanny initiative nobody designed — and carry no values at all
Give a person a goal, and they bring a lifetime of restraint to the job. DonŌĆÖt lie. DonŌĆÖt steal. Stop when something looks wrong. Give an AI agent a goal, and it finds a short…
News alert: Axoflow introduces AxoDetect to identify threats and reduce security data costs
STAMFORD, Conn.,Sept. 16, 2026, CyberNewswire — Now in early access, AxoDetect runs Sigma rules in stream - alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a…
MY TAKE: OpenAI, Anthropic admit they can’t control AI — for now, the machines are running free
The two companies racing hardest to build AI machines smarter than people spent the week of Sept. 7 conceding they cannot control what they are building. Then each proposed to sup…
Anyone looking into TikTok / ByteDance request signing?
Inside BambooToken’s Linux implant: shell and file control over MQTT
Recovering the password of an encrypted .docx with office2john + hashcat (student lab walkthrough)
antidbg: A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managi…
The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the Solana blockchain to hide…
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerab…
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the o…
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat…
Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat…
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software…
From guidance to action: Security fundamentals that materially reduce risk
Learn how Secure Now helps security leaders prioritize controls and reduce exposure across identities, endpoints, and AI systems.
Improving email security outcomes with real-world Microsoft Defender insights
See how Microsoft Defender uses real-world email security benchmarks to improve customer protection.
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud.
Our View on What It Takes To Be Named an Industry-Recognized Threat Intelligence Leader
A behind-the-scenes look at how Recorded Future earned its spot as a threat intelligence leader in the latest Forrester Wave.
The New Rules of Machine Speed Defense
Experts from Recorded Future and Mastercard explore how security organizations can shift to proactive, machine-speed defense by leveraging high-quality threat intelligence and adh…
Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.
Slow is a design principle, not a delay
AI labs are pacing their capability growth. Attackers won't. Here's what that asymmetry means for cybersecurity teams and AI-enabled defense.
AI adoption that pays off is built around keeping humans in the driver’s seat
I’ve spent enough time around AI adoption now to notice a pattern. Ask a business how AI is going for them and the honest answer is, lately, “we’ve got Copilot, and it’s not great…
Phishing in 2026. Latest statistics and analysis
Recent phishing statistics from around the world show that phishing is the most common kind of cybercrime in 2026.
Introducing Microsoft 365 G7: Intelligence + Trust for the mission ahead
Microsoft 365 G7 brings AI, Copilot, agent governance, security, and compliance together to help government agencies modernize securely.
ESPC 2026 is coming to Amsterdam: Bringing Microsoft and the community together
Join Microsoft at ESPC 2026 in Amsterdam to explore Microsoft 365 Copilot, agents, AI, and digital transformation.
Build apps in Copilot Cowork and Copilot Studio
Build full-stack business apps through conversation in Copilot Cowork and Copilot Studio, grounded in enterprise data.
Proofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI Activity
New Proofpoint Prism Investigator and Human Communications Intelligence capabilities help organizations investigate risk faster and understand intent across human and AI interacti…
Four groups caught using the same Chrome and Windows exploit kit
CISOs are feeling the security burden of accelerated AI use
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
A Tale of Two SOCs: Insights From Two Red Team Assessments
Same tactics, very different results. This advisory compares defensive outcomes from two red team assessments. Learn what drove detection and implement key
Defending Against an Active Threat to Siemens S7 Series PLCs
This advisory warns of threat actors targeting Siemens S7 Series programmable logic controllers (PLCs) and includes mitigations to be understood and applied
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, Author: Johannes Ullrich
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
No matching sources found.
Showing 180 of 881 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.