Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.
The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.
The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek.
Static checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation.
The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions.
The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek.
Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix.
The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek.
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]
The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud.
The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data.
The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. [...]
After a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
Grindr settled UK claims over alleged unlawful processing of sensitive user data
The scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons.
The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek.
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
THost9 hides its payload and uses ADB to spread across exposed Android devices and containers
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.
The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.
Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.
The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek.
Administrators are advised to check their deployments for newly created user accounts they don’t recognize.
The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.
July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for.
The post In most cities, nobody owns the whole network appeared first on CyberScoop.
CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]