Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.
<p>Windows takes 718 fixes… but what if it was actually a slow month?</p>Categories: Threat ResearchTags: Patch Tuesday, x-ops, Threat Research
ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.
Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.
<p>This article was first published <a href="https://www.linkedin.com/pulse/messageboards-all-you-need-nash-borges-iav6c" target="_blank">on LinkedIn.</a></p>Categories: AI Research, Threat ResearchTags: AI, AI Cybersecurity, Threat Research
Categories: Threat ResearchTags: advisory, vulnerability, Cisco
Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.
Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.
The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
A list of topics we covered in the week of September 7 to September 13 of 2026
Uncensored refers to a lack of typical guardrails or ethical restrictions, lowering the technical barrier of entry into cybercrimeCategories: Threat ResearchTags: AI, Luciferus, underground
Move from reactive defense to a proactive security mindset. Learn how proactive threat intelligence identifies and neutralizes threats.
A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
Upgraded modular malware observed in attacks on Cisco Firewall Management Center (FMC) devicesCategories: Threat ResearchTags: Cyclops Blink, Cisco, Linux
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.
AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
Scammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
AI agents don't fail from weak reasoning. They fail due to the disconnected and untrustworthy operational world in which they act. Find out why the world representation you give an agent matters more than the model you pick.
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.
AI scams are now hyper-realistic. But there’s one simple way to see through them.