Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.
The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop.
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization.
The post FTC rescinds policy requiring health apps to notify customers after a breach appeared first on CyberScoop.
The groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race.
The post Lawmakers call on Treasury to sanction hackers-for-hire appeared first on CyberScoop.
The company will increase its US market presence and will expand its engineering and go-to-market teams.
The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek.
Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.
The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek.
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.
Major chipmakers announced patches for vulnerabilities recently discovered in their products.
The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike.
The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared first on CyberScoop.
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy.
The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.
SpyCloud claims non-human identities are the most likely route into the enterprise
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.
The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.
The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.
The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.
The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.
The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]