Security intelligence
All coverage
Security signals, without the noise.
Current reporting from security alerts, threat intelligence, incident response, fraud, practitioner blogs, community feeds, and watch-and-listen sources.
[Virtual Event] Cybersecurity Outlook 2027
darkreading · 1h ago ↗sources
Attackers have been exploiting critical Zimbra flaw to steal emails
Russian state hackers use new RedFlick technique to push malwareBleepingComputer · All coverage / Incidents
↗
Automakers routinely share personally identifiable connected-car data with third parties, report saysThe Record from Recorded Future News · All coverage / Incidents
↗
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication SecretsThe Hacker News · All coverage / Incidents
↗
Showing 180 of 885 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.
Complete index
Recent stories
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Z…
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data.
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause…
Automakers routinely share personally identifiable connected-car data with third parties, report says
After reports on suicide deaths, Pentagon puts Cyber Command on notice
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Cisco Advance Notification for Publication of October 7, 2026, Security Advisories
On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software rele…
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system wi…
Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obt…
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability
Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defe…
CVE-2026-49800 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
CVE-2026-61938 Windows Installer Elevation of Privilege Vulnerability
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance.
Phishing Abuses RMM Tools for Persistent Access
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity
Beyond source code: A path to the keys to the kingdom
New cyberattack report from Microsoft Defender Experts Cybersecurity Incident Response explores actions organizations can take to defend their identities, pipelines, and cloud inf…
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of…
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
Advanced threat actor exploited CVE-2026-88772, one of the two recently disclosed NetScaler zero-day flaws, for weeks.
AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
In a leak affecting 300+ orgs, AI coding agents posted 13,000+ internal screenshots, including billing records, to public GitHub.
OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
Attackers have compromised a self-hosted JFrog Artifactory instance (https://artifactory.nordix.org/) operated by OpenInfra Europe.
Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore
With Signal for iOS 8.30, backup updates reach all platforms. Users can restore encrypted backups on Android, iOS, Linux, macOS and Windows.
SHARED INTEL Q&A: AI finds flaws faster — defenders still need to fix what attackers exploit
Security teams are being told they have hours to patch. Related: AI agents have a Lord of the Flies problem The warning has a real basis. In June, Anthropic’s frontier red team…
News alert: Archipelo launches Salmon to create verifiable audit trails for AI agent activity
SAN FRANSICO, Sept. 25, 2026, CyberNewswire тАФ Archipelo today announced Salmon, Execution Verification Infrastructure (EVI) for AI agents and autonomous systems, powered by a cr…
Guest Essay: Before AI agents takes hold, define who can challenge them and who owns the outcome
Early in my military career, I learned a simple lesson: when you give people a task, you also have to give them room to think. Related: AI agents take initiative, unchecked As a y…
News alert: SCOUTz gives MSPs security evidence to help turn prospects into customers
PHOENIX, Sept. 24, 2026, CyberNewswire — SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The pla…
Our AI-driven tabletop exercise accidentally went live and triggered a company-wide incident response
Madiant releaed Netcaler IOC and Methods they have seen in wild.
Verdachte aangehouden in onderzoek naar hackersgroep ShinyHunters - Suspect arrested in investigation into hacker group ShinyHunters
Introducing the nDPI TCP Fingerprint: A Stable, Patent-Free Way to Fingerprint TCP Stacks – ntop
Recorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats
Recorded Future just revealed autonomous defense capabilities. The platform hunts, investigates, and stops threats on its own, acting on real intelligence.
Social Engineering in the Age of Synthetic Media
How AI Changes Phishing, Impersonation, and Identity Verification
Recorded Future Launches MCP, the Intelligence Layer for Agentic Security Operations
Recorded Future launches Model Context Protocol (MCP), providing AI agents and LLM workflows direct access to the Intelligence Graph® for accurate, automated decision-making.
Introducing the new Copilot with Home, Code and Autopilot
Building the system for AI at work
There's no shortage of sound and fury in AI right now.
Introducing Microsoft 365 G7: Intelligence + Trust for the mission ahead
Microsoft 365 G7 brings AI, Copilot, agent governance, security, and compliance together to help government agencies modernize securely.
MacSync under the microscope: new delivery methods and a new payload
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managi…
The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the Solana blockchain to hide…
Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industry’s First Unified Agentic System
A single system for intent and access to empower organizations to adopt AI without losing data control or missing emerging risks across employees and AI agents Point security tools
Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era
Intent-based detection and multi-stage AI reasoning identify and stop sophisticated attacks before, during and after they reach people. Stops sophisticated attacks in one connected
Proofpoint Recognizes 2026 Global Partner Award Winners at Flagship Event
The awards presented at Proofpoint Protect 2026 celebrate partners driving customer impact, growth and secure AI adoption worldwide.
Slow is a design principle, not a delay
AI labs are pacing their capability growth. Attackers won't. Here's what that asymmetry means for cybersecurity teams and AI-enabled defense.
AI adoption that pays off is built around keeping humans in the driver’s seat
I’ve spent enough time around AI adoption now to notice a pattern. Ask a business how AI is going for them and the honest answer is, lately, “we’ve got Copilot, and it’s not great…
Phishing in 2026. Latest statistics and analysis
Recent phishing statistics from around the world show that phishing is the most common kind of cybercrime in 2026.
Ransomware: A Continuing Threat for Small Businesses
Ransomware remains one of the most damaging cybersecurity threats facing small businesses. Here are some ways to prevent risk.
AI in Tax Season: Risks, Scams, and How to Protect Your Data
Tax Season Scams to Watch For This Year
Tax season is a busy time for taxpayers and, unfortunately, a busy time for scammers as well. Each year, the Internal Revenue Service continues to warn individuals and businesses…
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
A Tale of Two SOCs: Insights From Two Red Team Assessments
Same tactics, very different results. This advisory compares defensive outcomes from two red team assessments. Learn what drove detection and implement key
Defending Against an Active Threat to Siemens S7 Series PLCs
This advisory warns of threat actors targeting Siemens S7 Series programmable logic controllers (PLCs) and includes mitigations to be understood and applied
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, Author: Johannes Ullrich
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
No matching sources found.
Showing 180 of 885 loaded entries. Search and all-headlines view include all available entries in this section. Browse the feed archive.