Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
Recorded Future just launched Digital Risk Protection, a unified solution covering five external threat surfaces, so security teams can detect, triage, and take down brand and identity threats from one workflow.
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.
Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.
In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month.
This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
Personalized replies and voice notes make it increasingly difficult to tell whether you’re talking to a human, chatbot, or AI agent.
Last week on Malwarebytes Labs: Stay safe!
<p>Sophos X-Ops takes a deep dive into an insidious piece of malware</p>Categories: Threat ResearchTags: rootkit, php, webshell
Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.
As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
Recorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits.
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.
California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.
Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security.
Tech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.
New Malwarebytes research reveals how different scams are tailored to different platforms.
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
The FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.
What you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.
Categories: Threat ResearchTags: advisory, vulnerability, SonicWall
A fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.
The familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network.