Security intelligence
All coverage
Security signals, without the noise.
Current reporting from security alerts, threat intelligence, incident response, fraud, practitioner blogs, community feeds, and watch-and-listen sources.
[Virtual Event] Cybersecurity Outlook 2027
darkreading Ā· 1h ago āsources
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training dealThe Record from Recorded Future News Ā· All coverage / Incidents
ā
Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027Security - Ars Technica Ā· All coverage
ā
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen EmailsThe Hacker News Ā· All coverage / Incidents
ā
Showing 180 of 908 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.
Complete index
Recent stories
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoftās PQC TLS Pilot Program helps advance future readiness.
3 lessons from frontier AI vulnerability research
Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel.
CISO perspectives on managing vulnerability risks in the age of AI
Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management.
Preparing governments for an era of interconnected cyber risk
Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal
International coalition seizes tools used by cyber firm behind Flax Typhoon
DOJ charges ransomware recovery CEO for secretly paying hackers
ASOS: Hackers tricked way into employee account before sending rogue push notification
Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027
Hackers obtain counterfeit TLS certificates for Google and other large services
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privā¦
OAuth grants pile up faster than you can review them. Here's how to keep up.
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breachā¦
Uranium crypto exchange hacker convicted for stealing $53 million
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021.
A Single POST Freezes Any Next.js Server
I found yet another way to invoke JavaScript functions without parentheses
CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE
You Wonāt Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
bpfjailer: eBPF LSM based Mandatory Access Control and jailer
Built a Production-Style SOC Home Lab Over 4 Months (Splunk, Suricata, Zeek, AD, Detection Engineering)
Turning IDN edge cases into typosquats
stackd: a local AWS emulator with Go control planes, AWS-compatible HTTP APIs, optional SQLite persistence, and real runtime/engine backends for supported compute and database workflows.
Cisco NX-OS Software NX-API Remote Code Execution Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of sā¦
Cisco Meraki Security Hardening Release: October 2026
As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in softā¦
Cisco Advance Notification for Publication of October 7, 2026, Security Advisories
On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releā¦
Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability
A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypassā¦
CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-58528 Windows USB Audio Class Driver Information Disclosure Vulnerability
CVE-2026-69270 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
CVE-2026-69581 Windows Device Association Service Elevation of Privilege Vulnerability
6 alternatives to Blackpoint for your shortlist
Get your Blackpoint alternatives shortlist if you're looking to switch for another MDR solution or a more comprehensible platform.
Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month
Heimdal's new weekly "Cyber in 60" series has ex-detective Adam Pilton decode one term in under a minute.
Innovation wins. Why smaller beats bigger
Benedict Jones spent years working for McAfee and Sophos. While doing threat research at Sophos, he spotted a problem in mobile threat defence that nobody had actually fixed. Heāsā¦
Heimdal partners with Elovade to bring unified cybersecurity platform to the DACH region
Heimdal and Elovade partner to bring a unified cybersecurity platform to MSPs across Germany, Austria, and Switzerland, simplifying prevention, detection, and response.
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls
The FBI and French police seized two NudeLeaksTeens websites that sold hacked intimate images of more than 17,000 women and girls.
YouTubers targeted with fake sponsorships and āchannel verificationā phishing
Scammers are going after YouTube creators' Google accounts by posing as a brand looking for sponsorship partners.
Anthropicās new budget model gets much better at ignoring hidden commands
Anthropic launches Claude Haiku 5.5 with lower prices, faster performance, improved safety and API credits for Max and Team users.
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
PoeLLM malware reads a GitHub poem to find its C2 servers and has hit more than 3,400 servers, mostly AI tools like LiteLLM and Ollama.
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Provides detection and mitigation guidance to defend against Integrity Technology Group-enabled threat actors using botnets, virtual private network
Red Lion Controls N-Tron 700 Series
Grid Protection Alliance openPDC and openHistorian
Satel Netco Design
Japan Adopts Proactive Cyber Defense Strategy
Learn about Japan's Active Cyber Defense (ACD) strategy, mandatory reporting rules, and key impacts on critical infrastructure.
Recorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats
Recorded Future just revealed autonomous defense capabilities. The platform hunts, investigates, and stops threats on its own, acting on real intelligence.
Social Engineering in the Age of Synthetic Media
How AI Changes Phishing, Impersonation, and Identity Verification
News alert: Aembit gives enterprises new controls over personal AI agents accessing sensitive systems
SILVER SPRING, Md., Oct. 6, 2026, CyberNewswire Ć¢ā¬ā Aembit, the identity control plane for AI agents, today announced support for securing personal agentsĆ¢ā¬ā¢ access to enterpriseā¦
SHARED INTEL Q&A: AI finds flaws faster ā defenders still need to fix what attackers exploit
Security teams are being told they have hours to patch. Related: AI agents have a Lord of the Flies problem The warning has a real basis. In June, AnthropicĆ¢ā¬ā¢s frontier red teamā¦
News alert: Archipelo launches Salmon to create verifiable audit trails for AI agent activity
SAN FRANSICO, Sept. 25, 2026, CyberNewswire ŃŠŠ¤ Archipelo today announced Salmon, Execution Verification Infrastructure (EVI) for AI agents and autonomous systems, powered by a crā¦
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Provides detection and mitigation guidance to defend against Integrity Technology Group-enabled threat actors using botnets, virtual private network
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
A Tale of Two SOCs: Insights From Two Red Team Assessments
Same tactics, very different results. This advisory compares defensive outcomes from two red team assessments. Learn what drove detection and implement key
Introducing the new Copilot with Home, Code and Autopilot
Building the system for AI at work
There's no shortage of sound and fury in AI right now.
Introducing Microsoft 365 G7: Intelligence + Trust for the mission ahead
Microsoft 365 G7 brings AI, Copilot, agent governance, security, and compliance together to help government agencies modernize securely.
MacSync under the microscope: new delivery methods and a new payload
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managiā¦
The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as āThe Odyssey,ā and uses the Solana blockchain to hideā¦
Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industryās First Unified Agentic System
A single system for intent and access to empower organizations to adopt AI without losing data control or missing emerging risks across employees and AI agents Point security tools
Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era
Intent-based detection and multi-stage AI reasoning identify and stop sophisticated attacks before, during and after they reach people. Stops sophisticated attacks in one connected
Proofpoint Recognizes 2026 Global Partner Award Winners at Flagship Event
The awards presented at Proofpoint Protect 2026 celebrate partners driving customer impact, growth and secure AI adoption worldwide.
Ransomware: A Continuing Threat for Small Businesses
Ransomware remains one of the most damaging cybersecurity threats facing small businesses. Here are some ways to prevent risk.
AI in Tax Season: Risks, Scams, and How to Protect Your Data
Protect yourself this tax season while using AI. Learn how to safely leverage AI tools, avoid tax scams, and ensure your filings are accurate with guidance from Alloy Silversteinā¦
Tax Season Scams to Watch For This Year
Tax season is a busy time for taxpayers and, unfortunately, a busy time for scammers as well. Each year, the Internal Revenue Service continues to warn individuals and businessesā¦
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, Author: Johannes Ullrich
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
Learn how Microsoft Azure Integrated HSM delivers hardwareāenforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and openāsource collaboration.
No matching sources found.
Showing 180 of 908 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.