Cybersecurity
1,877 publications from 84 organizations filed under Cybersecurity.
Filed by publisher, not by subject — these are everything those organizations published, not everything published about Cybersecurity. See the 1,610 publications Officially classified as Cybersecurity instead.
-
Gemini’s breach of real companies exposes an AI guardrail problem
Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.
-
Česká delegace v Jižní Koreji se zapojila do Cyber Summit Korea a mezinárodního cvičení APEX
Delegace Národního úřadu pro kybernetickou a informační bezpečnost (NÚKIB) vedená prvním náměstkem ředitele NÚKIB Tomášem Krejčím se ve dnech 14.–18. září 2026 zúčastnila mezinárodní konference Cyb...
Announcement Cybersecurity -
The Tale of Two INC Ransom Notes: A Ransomware Timeline | Huntress
Huntress analysts reconstructed a three-week INC ransomware attack from endpoint data, uncovering a 17-day lull despite missing process telemetry.
Cybersecurity 3 versions -
Python Workers are now generally available
Python Workers allow developers to run Python web frameworks and AI orchestration libraries natively in the Cloudflare Workers runtime. You can seamlessly integrate with Cloudflare's ecosystem incl...
-
TerminalFix: PNG Steganography, (Mon, Sep 21st)
Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take ...
Cybersecurity 2 versions -
ShinyHunters hacks rival extortion gang and takes over its dark web site
Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.
-
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Ob...
-
From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neu...
-
Amplifying youth-led innovations for space security
Announcement -
Dos nuevos avisos de seguridad
Synology DSM 7.4, versiones anteriores a 7.4-90075. Synology DSM 7.3, versiones anteriores a 7.3.2-86009-4. Synology DSM 7.2.2, versiones anteriores a 7.2.2-72806-9. Synology DSM 7.2.1, versiones a...
-
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
As AI opens new paths to company data while making familiar attacks faster and cheaper, SMBs need protection designed around the time and expertise available to operate it
-
Nuevas publicaciones: Configuraciones de privacidad y recomendaciones en herramientas de IA y Caso Real del 017
Nuevas publicaciones: Configuraciones de privacidad y recomendaciones en herramientas de IA y Caso Real del 017 Configuraciones de privacidad y recomendaciones en herramientas de IA: cómo proteger ...
Advisory AI -
Guidance: Evidence-led assurance for the software development lifecycle
The case and methodology for continuous assurance.
Cybersecurity 1 document -
A week in security (September 14 – September 20)
A list of topics we covered in the week of September 14 to September 20 of 2026
-
F5 BIG-IP Denial of Service Vulnerability
Announcement -
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable ...
-
Active Exploitation of Vulnerability in Cisco Identity Services Engine
Attackers are exploiting a critical vulnerability in Cisco Identity Services Engine and Cisco Identity Services Engine Passive Identity Connector to bypass authentication and gain unauthorised acce...
Announcement -
HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/3) but it's the first new standard HTTP verb since "PATCH...
2 versions -
[Control systems] ABB security advisory (AV26-942)
Serial number: AV26-942Date: September 18, 2026 As of September 18, 2026, ABB published a security advisory to address vulnerabilities in the following product: Freelance Controller Multiple versio...
-
SolarWinds security advisory (AV26-941)
Serial number: AV26-941Date: September 18, 2026 As of September 17, 2026, SolarWinds is affected by a vulnerability in the following product: SolarWinds Access Rights Manager Prior to 2026.2 The Cy...
-
Arista Networks security advisory (AV26-940)
Serial number: AV26-940Date: September 18, 2026 As of September 9, 2026, Arista Networks is affected by vulnerabilities in the following product: EOS Multiple versions and platforms The Cyber Centr...
-
Saving another 100TB of RAM with math (and Rust)
Cloudflare's global network is immense but not limitless. As we look for small ways to trim our resource usage, we sometimes get lucky and we can cut significantly more. Here’s how we reduced one o...
-
International investigation identifies over 70 potential victims exploited in Indian restaurants
The coordinated action conducted on 18 September 2026 led to two arrests. Allegedly, the traffickers forced their victims to work up to 16 hours per day, underpaid them and impeded them from leavin...
Announcement -
Google security advisory (AV26-939)
Serial number: AV26-939Date: September 18, 2026 As of September 17, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.53 The Cyber Centre encourages u...
-
New Android malware uses AI to steal bank logins and PINs
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
-
[Control Systems] Moxa security advisory (AV26-938)
Serial number: AV26-938Date: September 18, 2026 As of September 18, 2026, Moxa is affected by a vulnerability in the following product: TN-4500B Series Prior to or equal to v2.0 The Cyber Cent...
-
Did an AI really try to break free from human control?
An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.
-
[Control systems] Advantech security advisory (AV26-937)
Serial number: AV26-937Date: September 18, 2026 As of September 4, 2026, Advantech is affected by vulnerabilities in the following products: EKI-1242EIMS Prior to or equal to V2.00.01 EKI-1242...
-
Grafana security advisory (AV26-936)
Serial number: AV26-936Date: September 18, 2026 As of September 17, 2026, Grafana is affected by vulnerabilities in the following product: Grafana OSS Version 12.3.0 to 12.4.10 Version 13.0.0 to 13...
-
Two-week Europol task force identifies 18 sexually abused children worldwide
The Victim Identification Task Force brings together experts from across the globe to combat child sexual exploitation. During the VIDTF, specialists analyse data, images, videos, and intelligence ...
Announcement Cybersecurity -
CERT-SE:s veckobrev v.38
Den här veckan innehåller CERT-SE:s veckobrev bland annat information om att NCSC och AI Sweden med flera bjuder in till seminarium den 22 oktober på temat “Modern sårbarhetshantering i en AI-drive...
-
Kritiska Check Point ievainojamība (CVE-2026-91843)
Check Point ir publicējis brīdinājumu par jaunu kritisku ievainojamību CVE-2026-91843 (CVSS 9.8), kas ietver produktus Multi-Domain Security Management Server un Security Management Serve...
Announcement Cybersecurity -
A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfo...
-
EU CyCLONe v Sloveniji o pripravljenosti na resne kibernetske krize
Urad Vlade Republike Slovenije za informacijsko varnost (URSIV) 17. in 18. septembra 2026 v Sloveniji gosti BlueOLEx26, srečanje mreže EU CyCLONe. V ospredju so izkušnje iz vaje Cyber Europe 2026, ...
Announcement Cybersecurity -
‘Nudify’ apps: What to do if someone makes a fake nude of you
Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images
-
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.
-
ISC BIND Multiple Vulnerabilities
Announcement -
HGiga|OAKlouds - 2 Vulnerabilities
Announcement -
Google Chrome Multiple Vulnerabilities
Announcement -
The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era
AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maint...
-
Inside the Modern SOC: Defending the Cross-Environment Pivot
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending ...
-
Tanium security advisory (AV26-935)
Serial Number: AV26-935Date: September 17, 2026 As of September 16, 2026, Tanium is affected by a vulnerability in the following product: Threat Response Prior to Update 15 (v4.12.317) Prior to Upd...
-
Dell security advisory (AV26-934)
Serial number: AV26-934Date: September 17, 2026 As of September 17, 2026, Dell is affected by vulnerabilities in the following products: Dell Networking OS10 Prior to 10.6.1.3 Dell OpenManage Serve...
-
CVE-2026-92943 - Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/17/2026 12:00 PM PDT Description: AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open s...
-
The Autonomous Engine Behind Remediation, and What Finally Makes It Safe
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. …
-
Flock cameras are tracking people as well as cars
Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.
-
Check Point security advisory (AV26-933)
Serial number: AV26-933Date: September 17, 2026 As of September 16, 2026, Check Point is affected by a vulnerability in the following products: Security Management Server, Multi-Domain Securit...
-
Should you care about an “AI slowdown?”
In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.