Security intelligence
All coverage
Security signals, without the noise.
Current reporting from security alerts, threat intelligence, incident response, fraud, practitioner blogs, community feeds, and watch-and-listen sources.
[Virtual Event] Cybersecurity Outlook 2027
darkreading · 1h ago ↗sources
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers obtain counterfeit TLS certificates for Google and other large servicesSecurity - Ars Technica · All coverage
↗
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA CodesThe Hacker News · All coverage / Incidents
↗
Researchers Determine That 2,514 Cybersecurity Events Occur Each SecondCybersecurity News · All coverage
↗
Showing 180 of 896 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.
Complete index
Recent stories
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdo…
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days.
Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products…
ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from…
Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
Teaching network intrusion in the funnest way possible
SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
Hackers obtain counterfeit TLS certificates for Google and other large services
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Apple changes full-disk access permissions to curb abuse from AI agents
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
CISO perspectives on managing vulnerability risks in the age of AI
Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management.
Preparing governments for an era of interconnected cyber risk
Insights from the 2026 Microsoft Digital Defense Report
Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected.
Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
Explore Microsoft Security at Ignite 2026: AI security sessions, hands-on labs, certifications, expert events, and networking.
Alleged ATM malware creator appears in Nebraska court after arrest
South Korean officials believe AI agents were used to hack several banks
Osaka Metropolitan University cancels classes after suspected ransomware attack
ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
I made this javascript deobfuscator for https://github.com/javascript-obfuscator/javascript-obfuscator
Inside the Windows I/O Manager : Deep dive into how read I/O requests are initialized.
Is it possible to decompile the source code of Mario Kart Arcade GP DX with AI?
Autel EVO Nano+: getting a root shell | 0xD34D’s Space
CVE-2026-50387 Windows GDI Elevation of Privilege Vulnerability
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
CVE-2026-61927 Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability
Anaconda combines agent swarms with autonomous security testing
Anaconda has announced new capabilities across the Anaconda Platform that pair agentic development with autonomous security testing.
Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia
Wikimedia says rogue OpenAI agents made unauthorized edits to its wikis and sent millions of automated requests to its public APIs.
AppViewX targets shadow AI risks with agent discovery and runtime enforcement
AppViewX expands Agent Identity Security with shadow AI visibility, runtime controls and quantum-resilient identities for AI agents.
New Relic adds terminal-based investigation and recovery checks with Ground Truth CLI
New Relic Ground Truth CLI brings observability to developers and AI agents, helping teams investigate issues and verify recovery.
When the pentester is a fleet of AI agents: inside an autonomous vuln-hunting rig
SMTP is the key: BPFDoor and AVERAT hitting the network edge
Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem
I'm building OpenDRP – an open-source Digital Risk Protection platform (Early stage MVP).
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system wi…
Cisco IOS XE Software Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.…
Cisco Advance Notification for Publication of October 7, 2026, Security Advisories
On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software rele…
Innovation wins. Why smaller beats bigger
Benedict Jones spent years working for McAfee and Sophos. While doing threat research at Sophos, he spotted a problem in mobile threat defence that nobody had actually fixed. He’s…
Heimdal partners with Elovade to bring unified cybersecurity platform to the DACH region
Heimdal and Elovade partner to bring a unified cybersecurity platform to MSPs across Germany, Austria, and Switzerland, simplifying prevention, detection, and response.
Slow is a design principle, not a delay
AI labs are pacing their capability growth. Attackers won't. Here's what that asymmetry means for cybersecurity teams and AI-enabled defense.
SHARED INTEL Q&A: AI finds flaws faster — defenders still need to fix what attackers exploit
Security teams are being told they have hours to patch. Related: AI agents have a Lord of the Flies problem The warning has a real basis. In June, Anthropic’s frontier red team…
News alert: Archipelo launches Salmon to create verifiable audit trails for AI agent activity
SAN FRANSICO, Sept. 25, 2026, CyberNewswire тАФ Archipelo today announced Salmon, Execution Verification Infrastructure (EVI) for AI agents and autonomous systems, powered by a cr…
Guest Essay: Before AI agents takes hold, define who can challenge them and who owns the outcome
Early in my military career, I learned a simple lesson: when you give people a task, you also have to give them room to think. Related: AI agents take initiative, unchecked As a y…
Recorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats
Recorded Future just revealed autonomous defense capabilities. The platform hunts, investigates, and stops threats on its own, acting on real intelligence.
Social Engineering in the Age of Synthetic Media
How AI Changes Phishing, Impersonation, and Identity Verification
Recorded Future Launches MCP, the Intelligence Layer for Agentic Security Operations
Recorded Future launches Model Context Protocol (MCP), providing AI agents and LLM workflows direct access to the Intelligence Graph® for accurate, automated decision-making.
Introducing the new Copilot with Home, Code and Autopilot
Building the system for AI at work
There's no shortage of sound and fury in AI right now.
Introducing Microsoft 365 G7: Intelligence + Trust for the mission ahead
Microsoft 365 G7 brings AI, Copilot, agent governance, security, and compliance together to help government agencies modernize securely.
MacSync under the microscope: new delivery methods and a new payload
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managi…
The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the Solana blockchain to hide…
Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industry’s First Unified Agentic System
A single system for intent and access to empower organizations to adopt AI without losing data control or missing emerging risks across employees and AI agents Point security tools
Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era
Intent-based detection and multi-stage AI reasoning identify and stop sophisticated attacks before, during and after they reach people. Stops sophisticated attacks in one connected
Proofpoint Recognizes 2026 Global Partner Award Winners at Flagship Event
The awards presented at Proofpoint Protect 2026 celebrate partners driving customer impact, growth and secure AI adoption worldwide.
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
A Tale of Two SOCs: Insights From Two Red Team Assessments
Same tactics, very different results. This advisory compares defensive outcomes from two red team assessments. Learn what drove detection and implement key
Defending Against an Active Threat to Siemens S7 Series PLCs
This advisory warns of threat actors targeting Siemens S7 Series programmable logic controllers (PLCs) and includes mitigations to be understood and applied
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, Author: Johannes Ullrich
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
No matching sources found.
Showing 180 of 896 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.