Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Major chipmakers announced patches for vulnerabilities recently discovered in their products.
The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike.
The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared first on CyberScoop.
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy.
The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.
SpyCloud claims non-human identities are the most likely route into the enterprise
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.
The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.
The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.
The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.
The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.
The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure.
The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared first on CyberScoop.
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
A joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms.
The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop.
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
Authorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks.
The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop.
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]
The deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions.
The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop.