Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.”
The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.
Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces.
The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek.
Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children.
The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek.
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.”
The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop.
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions.
The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek.
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.
The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
The company will use the new capital to expand its vulnerability operations platform and support international growth.
The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek.
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.
The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek.
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox.
The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek.
OPSWAT researchers find two zero-days in TP-Link cameras
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.
The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned.
The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.
The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.
The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.