Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Outsider phishing kit generated 700 new pages after a Google-led disruption
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
CREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providers
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents.
The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek.
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.
The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek.
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.
The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on SecurityWeek.
The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
US-led action sinkholes machines caught up in Sality botnet
Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime.
The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop.
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.
The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
The agency also booted 14 phone service providers from U.S. networks for violating existing robocalling regulations.
The post The FCC wants consumers to rate their telecom’s anti-robocall protections appeared first on CyberScoop.
Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.
The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop.
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.
The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on CyberScoop.
it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs.
The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.
Russian man extradited to US over malware campaign that targeted 80,000 freelance users
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]
Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud