Sources
Malware Bytes Security
- A week in security (September 28 – October 4) 1 hour 46 min old
- Fake xStocks, Pendle, and other sites bait crypto users with rewards votes 3 days 15 hours old
- Shadow AI explained: The work shortcut that could leak your company’s secrets 3 days 18 hours old
- Convincing Free Mobile phishing emails appear after data breach 3 days 21 hours old
- Malwarebytes earns another Top Product award in independent testing 3 days 21 hours old
- Pentagon breach exposes Social Security numbers and military records of millions 3 days 21 hours old
- Losing gamblers pushed to bet more by DraftKings’ AI, report says 3 days 23 hours old
- Hackers steal protective order and foster care records from Arizona courts 4 days 17 hours old
- Your car’s app could be telling Big Tech who you are and where you go 4 days 21 hours old
- Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home 5 days 19 hours old
Security Week
- Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier 3 hours 32 min old
- Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force 17 hours 50 min old
- doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures 1 day 21 hours old
- Fortra Patches Critical Vulnerabilities in BoKS 1 day 21 hours old
- In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats 2 days 18 hours old
- macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor 2 days 19 hours old
- Crypto Scammers Hijack Microsoft’s Official X Account 2 days 21 hours old
- In Rare Move, Alleged Iranian State Hacker Extradited to US 2 days 21 hours old
- Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks 2 days 23 hours old
- AI Agents Aimed SQL Injection at US and Canadian Government Sites 3 days 8 min old
SlashDot
- FBI Detains Teenager Linked to Group That Stole Data on 5,000 FBI Employees 3 hours 34 min old
- OpenAI's GPT-6 Astra Gets Frustrated Losing At StarCraft And Decides To Cheat Instead 6 hours 38 min old
- Researcher At Russian Plague Laboratory Dies of 'Unknown' Infection 6 hours 38 min old
- How Python Will Test Adding Rust Into CPython 9 hours 40 min old
- Disney/Marvel's 'Avengers: Endgame' Beats 'Avatar' as Top-Grossing Film, 'Coyote vs Acme' #1 on Apple TV 11 hours 41 min old
- Radio Broadcasters Support America's 'AM Radio for Every Vehicle Act' 11 hours 41 min old
- Particle Collider Experiment Recreates the Big Bang's Primordial Soup - and Finds Unexpected Pattern 13 hours 42 min old
- FSF Sponsors 'GNU Boot', a Libre, Ethical Replacement for Nonfree BIOS Or UEFI 14 hours 56 min old
- San Francisco's Car Crime Has Plunged. How Much Credit Does Flock Deserve? 14 hours 56 min old
- US Bank Regulator Sued Over Crypto Firm Charters by Community Bank Advocates 17 hours 58 min old
Hacker News
- RedIWM – Wayland Compositor in Zig 3 hours 42 min old
- Storage orchestration layer presents many S3/blob providers as one S3 endpoint 3 hours 44 min old
- Cement-based supercapacitors could power next-generation 'smart' buildings 3 hours 45 min old
- Service-Area Businesses: How to Rank on Google Maps Without a Shopfront 3 hours 45 min old
- Show HN: Tip Tool – dodge spam and phishing 3 hours 46 min old
- YalaRide 3 hours 48 min old
- Safety is a product liability Issue 3 hours 55 min old
- The Problem with AV Data Isn't Size 3 hours 55 min old
- The Temporary Democratization of Software Reverse Engineering 3 hours 57 min old
- Musk says he will rename SpaceXAI to SpaceXSI 3 hours 58 min old
Guardian Security
- OpenAI safety leader quits, warning AI company’s culture is ‘broken’ 1 day 13 hours old
- As AI models go rogue, do you still trust OpenAI and Anthropic to stop them? I don’t and neither should you | Chris Stokel-Walker 6 days 3 hours old
- Nick Clegg plays down fears ‘godlike’ AI could exterminate humanity 1 week 3 days old
- Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors 2 weeks 2 days old
- OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot 2 weeks 2 days old
- OpenAI reveals cases of ‘concerning’ AI behaviour as it announces new disclosure system 2 weeks 4 days old
- OpenAI not on track to reduce risk of ‘catastrophic’ loss of control, says board member 3 weeks 3 days old
Wired Security
- Muse Creates Detailed Profiles of All Your Friends and Family 1 day 20 hours old
- ICE Has Been Dumping Protester Photos Into a Palantir Database 2 days 12 hours old
- A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data 2 days 23 hours old
- Experience What It’s Like to Travel in the Occupied West Bank 3 days 14 hours old
- The Secrets of the US Spyware King 3 days 23 hours old
- How Israeli Checkpoints Choke Palestinian Life in the Occupied West Bank 4 days 22 hours old
- OpenAI Gets Sued Over the Hugging Face Hack 5 days 13 hours old
- OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government 6 days 21 hours old
- Old-School Credit Card Scams Are Far From Dead 1 week 1 day old
- An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later 1 week 3 days old
Security Wire Daily News
- OpenAI pledged $1B to cyber defenders the same day it released Astra -- its most powerful offensive model yet. Some experts warn that defense is getting left behind. 1 day 23 hours old
- A cybersecurity technology proof of concept can validate a good purchasing decision -- or waste months of your team's time. Look out for these five common PoC missteps. 1 week 3 days old
- Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems as AI tests their limits. 1 week 3 days old
- Deepfake phishing simulation software uses AI to probe organizational resistance to state-of-the-art social engineering attacks. Learn why they should be on CISOs' radar. 1 week 4 days old
- AI accelerates exploit timelines from months to hours. Organizations must shift from patch-all to risk-based prioritization using exploitability metrics. 1 week 4 days old
- With so many services requiring access to sensitive data, encryption alone is not enough. Data obfuscation has evolved into a core element of modern cybersecurity architecture. 1 week 5 days old
- A security data lake gives organizations a centralized repository of security information, but it can pose governance and operational risks. 1 week 6 days old
- IAM is more crucial than ever in the AI era. To better control who -- and what -- is accessing systems and data, security teams need to move beyond standing access privileges. 2 weeks 2 days old
- In an unprecedented -- and unintended -- cyberattack, frontier AI models autonomously escaped their contained testing environment and breached another company's systems. 2 weeks 3 days old
- The Revolut data breach showed what can happen when organizations over-trust and under-verify. Experts warn that countless companies are currently at risk. 2 weeks 3 days old
Graham Cluely Security Blog
- N0n ransomware: what you need to know 2 days 17 min old
- FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader 3 days 21 hours old
- ShinyHunters suspect arrested, and is now investigated over alleged murder plots 3 days 21 hours old
- Pentagon personnel database breach exposes personal data of millions 4 days 22 hours old
- Ukrainian ransomware developer jailed for nearly 13 years 1 week 3 days old
- Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras 1 week 4 days old
- US Coast Guard and FBI board oil tanker to investigate cyber attack 2 weeks 3 days old
- Smashing Security podcast #485: These researchers got drunk to hack an LG TV 2 weeks 4 days old
- Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man 2 weeks 5 days old
- ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars 3 weeks 3 days old
Cisco Security Advisories
- Cisco IOS XE Software Security Hardening Release: August 2026 2 days 9 hours old
- Cisco Advance Notification for Publication of October 7, 2026, Security Advisories 4 days 12 hours old
- Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability 4 days 15 hours old
- Cisco IOS XR Software Security Hardening Release: September 2026 2 weeks 3 days old
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability 2 weeks 4 days old
- Cisco Secure Firewall Management Center Software Static Credential Vulnerability 2 weeks 4 days old
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability 2 weeks 4 days old
- Cisco Identity Services Engine Information Disclosure Vulnerability 2 weeks 4 days old
- Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability 2 weeks 4 days old
- Cisco Identity Services Engine SQL Injection Vulnerabilities 2 weeks 4 days old
Computer Weekly Feed
- Computer Weekly has investigated the Post Office Horizon scandal since 2008 and is, in fact, part of the story. This guide contains essential information about the scandal 2 days 15 hours old
- Build a clear plan, invest in your technical skills and work on your leadership capabilities and your personal brand 2 days 15 hours old
- The retail jobs of the future are oft-debated, but the industry looks to be entering an era primed for the arrival of the chief AI officer 2 days 15 hours old
- Former subpostmasters could apply for judicial review over unfair redress of financial losses 2 days 15 hours old
- A reimagined structure for the UK data regulator raises questions about the effectiveness of its oversight, as staff continue to express concern over a toxic workplace culture that has taken hold under the organisation’s leadership 2 days 15 hours old
- NRF Europe 2026 saw some key themes across the retail space, including AI, SaaS and ongoing technology transformation for even the biggest of retailers 2 days 15 hours old
- Although the UK and Europe have laws to restrict Chinese technology from critical infrastructure, implementation is patchy 2 days 15 hours old
- Government department moves nearly 3,000 staff from supplier as it insources work in effort to make savings 2 days 19 hours old
- The UK’s Teachers’ Pension scheme administration is set to transfer from Capita to Tata Consultancy Services 2 days 19 hours old
- A tech entrepreneur reflects on Britain’s shortage of visible business and technology founder role models 2 days 19 hours old
Security Wire Weekly
- CISO as a service, or CISOaaS, is the outsourcing of CISO (chief information security officer) and information security leadership responsibilities to a third-party provider. 3 days 9 hours old
- Admins will want to focus on issuing corrections for the large number of flaws, some of which require no user interaction, in Windows RRAS and Microsoft Office. 3 days 13 hours old
- When assessing cybersecurity risk, be sure to consider the scope of the project, your organization's specific assets and leadership's tolerance for risk. 3 days 13 hours old
- Identity is long past the days of logging into systems. Security teams must now manage SaaS apps, AI agents and machine-to-machine interactions across distributed environments. 5 days 8 hours old
- IT automation uses instructions to create clear, consistent and repeatable processes that replace an IT professional's manual work in data centers and cloud deployments. 1 week 3 days old
- Create a security compliance plan for the data center that includes various standards, audit schedules, and 2026 AI governance and sustainability reporting requirements. 1 week 4 days old
- A time-based one-time password (TOTP) is a temporary passcode generated by an algorithm that uses the current time of day as one of its authentication factors. 1 week 5 days old
- Red teams can harness the power of LLMs for penetration testing. From session analysis to payload crafting, discover five ways AI transforms security testing. 1 week 5 days old
- Security for information technology (IT) refers to the methods, tools and personnel used to defend an organization's digital assets. 2 weeks 1 day old
- Know thine enemy -- and the common security threats that can bring an unprepared organization to its knees. Learn what these threats are and how to prevent them. 2 weeks 2 days old
Microsoft Malware Protection Center
- Insights from the 2026 Microsoft Digital Defense Report 3 days 18 hours old
- Preparing governments for an era of interconnected cyber risk 3 days 18 hours old
- Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 4 days 13 hours old
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 4 days 18 hours old
- Phishing Abuses RMM Tools for Persistent Access 5 days 11 hours old
- Beyond source code: A path to the keys to the kingdom 5 days 16 hours old
- Star Blizzard refines phishing and malware delivery with the RedFlick technique 5 days 17 hours old
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operations 6 days 17 hours old
- Storm-3168: Agentic-driven cloud attacks using compromised service principals 1 week 2 days old
- What’s new in Microsoft Security: September 2026 1 week 3 days old
Security Now
- SN 1098: How worried should we be? - Unpredictable Agents 5 days 6 hours old
- SN 1098: How worried should we be? - Unpredictable Agents 5 days 6 hours old
- SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers 1 week 5 days old
- SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers 1 week 5 days old
- SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked 2 weeks 5 days old
- SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked 2 weeks 5 days old
- SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked 2 weeks 5 days old
- SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race 3 weeks 5 days old
- SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race 3 weeks 5 days old
- SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race 3 weeks 5 days old
KrebsOnSecurity
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation 6 days 17 hours old
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions 1 week 2 days old
- Data Broker Radaris Loses Domains in Privacy Fight 2 weeks 4 days old
- Microsoft Plugs Nearly 1,000 Security Holes 3 weeks 5 days old
Cloud Security Briefing: News and Advice
- Frameworks provide the structure for an effective incident response program. Here's where to turn for guidance on what to include. 1 week 2 days old
- Threats from cyberattacks continue to grow in frequency and severity. Considering the potential disruptions from such events, an organization needs an incident response plan. 1 week 5 days old
- Containers are an integral part of a growing number of production environments. But they can become security risks if not managed correctly. 2 weeks 1 day old
- While prevention is key, it's not enough to protect a company's systems from ransomware. Learn how early detection with these four methods helps reduce damage from attacks. 2 weeks 2 days old
- Know thine enemy -- and the common security threats that can bring an unprepared organization to its knees. Learn what these threats are and how to prevent them. 2 weeks 2 days old
- The Cloud Security Alliance (CSA) is a nonprofit organization that promotes research into best practices for securing cloud computing and the use of cloud technologies to secure other forms of computing. 2 weeks 3 days old
- What are the necessary components of a cloud security policy, and why should an organization go to the trouble to create one? Download a template to get the process started. 2 weeks 3 days old
- This cloud security guide explains challenges enterprises face today; best practices for securing and managing SaaS, IaaS and PaaS; and comparisons of cloud-native security tools. 2 weeks 3 days old
- Automating security in the cloud can be invaluable for threat detection and mitigation. Explore key areas where security professionals should implement automation. 2 weeks 3 days old
- With so many apps and data residing in cloud, employing a security framework to help protect cloud infrastructure is an essential move for an organization. 2 weeks 3 days old
EFF
- How the Meta Settlement Silences Youth Activism 2 weeks 4 days old
- California: Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety 2 weeks 5 days old
- The High Crime of “LMAO”: How Cops Are Treating Flock's Mass Surveillance As a Joke 2 weeks 6 days old
- Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans 3 weeks 2 days old
- Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy 3 weeks 2 days old
- We All Deserve a Better Internet, Not A Smaller One 3 weeks 3 days old
- Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR 3 weeks 4 days old
- Digital Sovereignty: What It Is, What It Could Be 3 weeks 4 days old
- 2026 EFF Award Winners: Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights 3 weeks 4 days old
- New Records Reveal Problems with Medicare’s AI Prior Authorization Experiment 3 weeks 5 days old
Google Security Blog
- Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android 6 months 1 week old
- Cultivating a robust and efficient quantum-safe HTTPS 7 months 1 week old
- Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection 7 months 1 week old
- Keeping Google Play & Android app ecosystems safe in 2025 7 months 2 weeks old
- New Android Theft Protection Feature Updates: Smarter, Stronger 8 months 1 week old
- HTTPS certificate industry phasing out less secure domain validation methods 9 months 4 weeks old
- Further Hardening Android GPUs 9 months 4 weeks old
- Architecting Security for Agentic Capabilities in Chrome 10 months 14 hours old
- Android expands pilot for in-call scam protection for financial apps 10 months 5 days old
- Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing 10 months 2 weeks old
