Cybersecurity
1,759 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.
Cybersecurity 3 versions -
Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange regi...
Cybersecurity 2 versions -
Actief misbruik zero-day kwetsbaarheid in Google Chrome V8 - update nu
Er is een zero-day kwetsbaarheid gevonden in de V8 JavaScript engine van Google Chrome. Deze kwetsbaarheid, bekend als CVE-2026-87491, wordt actief misbruikt en kan ernstige schade veroorzaken. Het...
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behin...
-
Microsoft verhelpt ernstige kwetsbaarheden in Windows en Office
Deze Patch Tuesday heeft Microsoft een groot aantal kwetsbaarheden verholpen in verschillende producten. Microsoft meldt dat twee kwetsbaarheden in Windows worden misbruikt. Een aanvaller moet hier...
-
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
Cybersecurity 3 versions -
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.
-
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
-
Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings ...
Cybersecurity 2 versions -
AG Labrador’s ICAC Unit Arrests Three, Including Police Sergeant, in August Child Exploitation Cases
BOISE, ID — Attorney General Raúl Labrador has announced that investigators with his Idaho Internet Crimes Against Children (ICAC) Unit arrested three individuals in August for alleged child s...
Announcement Cybersecurity -
Microsoft patchetirsdag september 2026
Microsoft har offentliggjort sine månedlige sikkerhetsoppdateringer1.
Announcement Cybersecurity -
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security f...
-
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild. Microsoft patched...
Cybersecurity 2 versions -
Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers bet...
Cybersecurity 2 versions -
NSA and Others Warn China-Based AI Companies are Distilling U.S. Frontier AI Models
FORT MEADE, Md. — Today, the National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) released the Cybersecurity ...
Announcement Cybersecurity -
Security Bulletin 9 Sep 2026 [PDF, 2051KB]
Announcement Cybersecurity -
September 2026 Monthly Patch
Microsoft has released security patches to address multiple vulnerabilities in their software and products.
Announcement Cybersecurity -
Active Exploitation of Vulnerability in N-Able N-Central
Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately.
Announcement Cybersecurity -
Active Exploitation of Vulnerability in Adobe Products
Attackers are exploiting a critical vulnerability in Adobe Commerce, Adobe Commerce B2B and Adobe Magento to execute arbitrary code. Patch immediately.
Announcement Cybersecurity -
Critical Vulnerabilities in SAP Products
Attackers can exploit multiple vulnerabilities in SAP Products to execute arbitrary commands, obtain sensitive credentials, replace or delete tenant data and perform unauthorised actions. Patch imm...
Announcement Cybersecurity -
High-Severity Vulnerability in PostgreSQL
Attackers can exploit a high-severity vulnerability in PostgreSQL to execute arbitrary code on the affected system. Patch promptly.
Announcement Cybersecurity -
4 Questions to Ask When Evaluating an Exposure Management Platform
Executive Summary Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself. …
-
VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot pro...
-
Microsoft 製品の脆弱性対策について(2026年9月)
情報処理推進機構(IPA)の「Microsoft 製品の脆弱性対策について(2026年9月)」に関する情報です。
Announcement Cybersecurity -
VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed int...
-
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate ...
-
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed ...
Cybersecurity 2 versions -
Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)
Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, prefe...
-
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional depend...
-
Kwetsbaarheden in MikroTik RouterOS actief misbruikt: update nu
Er zijn meerdere ernstige kwetsbaarheden gevonden in MikroTik RouterOS. Deze kwetsbaarheden worden actief misbruikt en is vooral gericht op routers met publiek toegankelijke SSH-diensten. Het NCSC ...
-
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-centr...
Cybersecurity 2 versions -
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as...
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google S...
-
Adobe: rilevato sfruttamento in rete della CVE-2026-75650
Aggiornamenti di sicurezza Adobe sanano una vulnerabilità con gravità “critica” in Adobe Commerce, Adobe Commerce B2B e Magento Open Source, piattaforme per il commercio elettronico utilizzate per ...
Advisory Cybersecurity -
Kritiska ievainojamība Adobe Commerce un Magento e-komercijas platformās
E-komercijas platformās Adobe Commerce un Magento Open Source ir atklāta kritiska ievainojamība CVE-2026-75650, kas jau tiek aktīvi izmantota uzbrukumos. Tā ļauj neautorizētam uzbrucējam ...
Announcement Cybersecurity -
Ernstige kwetsbaarheid in Adobe Commerce en Magento actief misbruikt: update onmiddellijk
Er is een zeer ernstige kwetsbaarheid, CVE-2026-75650, gevonden in Adobe Commerce en Magento met een maximale CVSS-score van 10.0. Met deze kwetsbaarheid is het mogelijk voor een aanvaller om op af...
-
Kiberlaikapstākļi 2026 | Augusts
Pieejami kiberlaikapstākļi par 2026. gada augustu. Kiberlaikapstākļi ir CERT.LV speciālistu apkopots pārskats īsā un pārskatāmā formā par Latvijas kibertelpā svarīgākajiem notikumiem pagājušajā mēn...
Announcement Cybersecurity -
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
Microsoft has released security updates for 972 vulnerabilities, including two exploited zero-days and 113 critical, in its September 2026 Patch Tuesday rollout.
-
AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance
Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. …
Cybersecurity 3 versions -
Global standard-setting bodies publish a toolkit for cyber resilience at FMIs and a discussion paper on FMIs’ reliance on third-party service providers
CPMI-IOSCO are seeking input from stakeholders on a cyber resilience toolkit for financial market infrastructures (FMIs) and on risks to FMIs from third-party service providers. The Cyber resilienc...
Announcement Cybersecurity -
Research: A study of cybersecurity literature on open-source software and AI
A combined evidence report and systematic review of peer-reviewed academic literature and grey literature.
Announcement Cybersecurity -
7th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and tech...
-
AI SIEM Search
The new Huntress AI SIEM search feature lets you find answers in plain English, with no query language fluency required. Ask questions, get results, and skip the syntax.
Cybersecurity 3 versions -
Microsoft 365 un Azure ierīces koda (Device Code) ļaunprātīga izmantošana
Ierīces koda (Device Code) autentifikācija ir leģitīma funkcionalitāte, kas risina praktisku problēmu - tā ļauj ērti pieteikties ierīcē, kurai nav pārlūkprogrammas vai pilnvērtīgas tastatūras, izma...
Announcement Cybersecurity -
Upozorenj: kritična ranjivosti u MikroTik RouterOS-u. Preporučuje se hitna nadogradnja.
Poljski CERT (CERT Polska) identificirao je i koordinirao objavu šest ranjivosti u sustavu MikroTik RouterOS. Kombinacijom dviju od njih (CVE-2026-67276 i CVE-2026-86060), nazvanom “MikroTrick”, na...
Announcement Cybersecurity