AI blog APT blog Attack blog BigBrother blog BotNet blog CyberCrime blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blog
2026 January(89) February(123) March(106) April(119) May(126) June(97) July(101) August(348) September(454) October(109) November(0) December(0)
DATE |
NAME |
Info |
CATEG. |
WEB |
|
6.10.26 |
47-Day TLS Certificates: 5 Steps to Prepare | Somewhere in your organization is a spreadsheet of certificate expiry dates, and someone who owns it. That is not a caricature. DigiCert’s 2026 research with Omdia surveyed more than 400 senior IT leaders and found that 47% still rely on manual tracking methods such as spreadsheets, and only 34% have a complete, current view of what they hold. | Security blog | Imperva |
|
6.10.26 |
Harvest Now, Decrypt Later: End-to-End PQC TLS | Somewhere, an attacker is recording your encrypted traffic. Not breaking it. Recording it. The bet is patient and simple: store ciphertext today, wait for quantum computers to mature, decrypt at leisure. The industry calls it harvest now, decrypt later (HNDL), and it is the rare security threat with a believable deadline attached: data with a ten-year shelf life, encrypted with algorithms on a countdown. | Security blog | Imperva |
|
6.10.26 |
New Remote DoS Attacks Against GraphQL Java | Imperva Threat Research identified a series of remote denial‑of‑service vulnerabilities in GraphQL Java, one of the most widely used libraries for GraphQL in the Java ecosystem. | Attack blog | Imperva |
|
6.10.26 |
The Hidden DoS Vector in SQL Parsers | SQL parsers are critical components of the modern data stack. They validate queries before they reach the database, transpile between dialects, and lint codebases for style violations. Increasingly, they also power AI-driven SQL generation in LLM-integrated data tools. | Attack blog | Imperva |
|
6.10.26 |
Behind the tags: How Elastic SIEM grades 1,781 detection rules on noise, speed, and threat coverage | This article explains how Elastic SIEM uses a monthly automated telemetry pipeline to score prebuilt detection rules across noise, performance, threat, and profile dimensions, helping security teams decide which rules to enable first. | Spam blog | Elastic Security Labs |
|
6.10.26 |
Machine-speed attacks require machine-speed prevention and detection | Artificial intelligence (AI) is transforming the way cyberattacks are handled. Reconnaissance has become faster, phishing is more convincing, and vulnerabilities are identified and exploited sooner, and after initial access, automation can accelerate privilege escalation, lateral movement, and data theft. | Hacking blog | Threatlocker |
|
6.10.26 |
IQUALIF Leak, IUT Breach, SMTP Dump and Struts Exploit | SOCRadar Dark Web Team identified several new underground posts, including an alleged IQUALIF-based French residential data leak, an alleged breach affecting IUT Paris Seine, and an alleged initial access auction for a U.S. manufacturing company. Other posts advertised an alleged 19 million SMTP credential dump and access to servers reportedly compromised through CVE-2017-5638. | Exploit blog | SOCRADAR |
|
6.10.26 |
FortiMail Zero-Day Under Active Exploitation | Fortinet has confirmed that CVE-2026-104286, a critical path traversal flaw in FortiMail, is being exploited in zero-day attacks, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on the same day the advisory went live. | Exploit blog | SOCRADAR |
|
6.10.26 |
CVE-2026-90970: GitLab AI Gateway RCE | GitLab has patched CVE-2026-90970, a critical vulnerability in the Self-Hosted AI Gateway that can allow an authenticated user with Duo Agent Platform access to execute arbitrary commands on the gateway. | Vulnerebility blog | SOCRADAR |
|
6.10.26 |
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure | How ClingSTUN combines vulnerability exploitation, persistence, and STUN-assisted connectivity on Linux devices | Malware blog | FortiGuard Labs |
|
3.10.26 |
AI-Enabled Cyber Attacks: What They Are and How to Defend Against Them | AI-enabled cyber attacks are malicious operations in which adversaries use AI, most often large language models (LLMs), to plan, carry out, or scale any part of an attack. That includes writing phishing lures and deepfake pretexts, developing and debugging malware, discovering and exploiting vulnerabilities, and running intrusions end to end. | AI blog | PICUSSECURITY |
|
3.10.26 |
CrowdSec Bot Detection Uncovers a 75,000-IP Bot Network | On the 31st of August, we released CrowdSec 1.8.0 that included the bot detection feature. Despite the fact that the feature was (is) still tagged as alpha, some mad lads promptly slapped it on their production infrastructure. Thanks for the trust! | BotNet blog | CROWDSEC |
|
3.10.26 |
AI-Agentic attacks Optimized Operations | AI is changing cyberattacks from isolated activities into connected operations that require a new level of speed, context, and understanding. | AI blog | WatchGuard Blog |
|
3.10.26 |
PolinRider is A/B Testing its Way Past Your Detections | We've seen fa-solid-400.woff2 become 500 and 900, change from .woff2 to .llf files, move folders, and drop its whitespace padding. | Malware blog | OpenSource Malware Blog |
|
3.10.26 |
Prompt Forcing: The Scarier Sibling of Prompt Injection | Breaking down a newly discovered prompt attack technique that isn't prompt injection. | AI blog | Forever Security |
|
3.10.26 |
Introducing the SysQL Skill: Ask your security graph anything | Dashboards answer the questions someone already decided to build a screen for. Every other question — the one a new CVE just made urgent, or the one no vendor anticipated — waits until someone writes a report or files a ticket. | Vulnerebility blog | Sysdig |
|
3.10.26 |
Swarming Against Citrix 0-Day Exploitation | GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. | Exploit blog | GREYNOISE |
|
3.10.26 |
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation | GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. | Exploit blog | GREYNOISE |
|
3.10.26 |
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF | GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. | AI blog | GREYNOISE |
|
3.10.26 |
Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets | GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies. These forged automated scanners have been observed requesting files often exposed on misconfigured web servers and by other commonly leaked secret and credential methods. | AI blog | GREYNOISE |
|
3.10.26 |
Separating Signal from Slop: Triaging CVEs in the Age of… | Tools that can read a codebase, identify a vulnerability, and generate a working proof-of-concept have lowered the skill floor for vulnerability research. They also produce a wave of bugs that look terrifying on paper (remote code execution, popular software, no authentication,) yet they often depend on a configuration rarely enabled in real deployments. | Vulnerebility blog | Bishop Fox |
|
3.10.26 |
One Port to Root: Weaponizing Check Point Management… | The Check Point management server is the brain of a Check Point firewall estate: it holds the policy every gateway enforces, the administrator credentials, and the certificate authority the whole deployment trusts. A flaw already used in real attacks lets anyone who can reach that server take it over completely without logging in. | Vulnerebility blog | Bishop Fox |
|
3.10.26 |
AI-Assisted Attacks Still Leave a Behavioral Trace | AI is increasingly being used to accelerate cyber-attacks, but attackers still leave detectable behavioral traces. This blog explores how Darktrace identified suspicious file delivery, command-and-control communications, beaconing activity, and other anomalies linked to AI-assisted campaigns through behavioral analysis. | AI blog | DARKTRACE |
|
3.10.26 |
DirtyBlanket: Fake Express Packages on npm Spread a Linux Worm - Real-time Open Source Software Supply Chain Security | Nine npm packages hide a self-spreading Linux worm. The npm account dirtyblanket published all nine on September 29, 2026, in 33 minutes. Eight of them copy the popular Express framework. One copies React. | Malware blog | SAFEDEP.IO |
|
3.10.26 |
PolinRider Switches to Ethereum C2 in 30+ Repositories - Real-time Open Source Software Supply Chain Security | The PolinRider loader family has a new way to find its command and control (C2) servers. It reads Ethereum mainnet and looks for small transactions from an operator wallet. The recipient address of each transaction holds the IP address of a C2 server. SafeDep found two operator wallets that use this method. One wallet has sent a transaction about every 51 minutes since 2026-06-23. | Cryptocurrency blog | NETCRAFT |
|
3.10.26 |
'Super Intelligence' Executive Order Fuels Nearly Hundredfold Increase in .si Domain Registrations | We previously reported that registrations of Slovenian .si domains overtook .ai in the 25 hours after President Trump told the UN General Assembly on September 22 that the U.S. would call AI “super intelligence” (SI). | AI blog | NETCRAFT |
|
3.10.26 |
FinCEN Moves to Cut the A7 Network's Sub-Agents Off From the US Financial System | FinCEN issued a finding and NPRM today identifying transactions involving any non-US company controlled by the A7 Network, which the agency calls "Sub-Agents," as a class of transactions of primary money laundering concern. The proposed rule would prohibit every covered US financial institution from sending or receiving funds or crypto involving a Sub-Agent. | AI blog | TRM Labs |
|
3.10.26 |
How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail | In 2025, I found an AF_ALG vulnerability in the Linux kernel that allowed an ordinary user to escalate privileges to root. This is a retrospective on how I found CVE-2025-39964 and how we developed the exploit, before Copy Fail drew wider attention to AF_ALG in 2026. | OS Blog | IDNSEC |
|
3.10.26 |
CVE-2026-86950: The Great Glyph Grift | Apple recently released iOS 26.7.1 to fix a bug in CoreGraphics (CVE-2026-86950). The security advisory stated that the vulnerability was reported by Meta Product Security and "may have been exploited in an extremely sophisticated attack against specific targeted individuals." For those who are unfamiliar with Apple’s English dialect, it means that the bug was actually exploited in the wild. | Vulnerebility blog | Calif |
|
3.10.26 |
Crypto Scam Extensions Masquerade as High-Profile Investors | LayerX security researchers (now part of Akamai) uncovered a campaign of nearly 30 malicious browser extensions designed to scam cryptocurrency investors by masquerading as legitimate, high-profile financial and/or cryptocurrency investors such as Warren Buffett, Andy Kreiger, Thomas Bulkowski, and others. | Spam blog | Akamai |
|
3.10.26 |
When Productivity Extensions Become Attack Platforms | LayerX Research (now part of Akamai) discovered a coordinated campaign of 32 malicious browser extensions across the Chrome Web Store and Microsoft Edge Add-ons Store, affecting more than 6,150 users. | Security blog | Akamai |
|
3.10.26 |
Beyond Vendor Assessments: Managing Third-Party Risk | Software supply chain security has a well-defined starting line. It has no finish line, even though most programs are built as if it does. | Cyber blog | JSCRAMBLE |
|
3.10.26 |
Aligning AI Speed with AI Trust: AI Agent Security Insights for CISOs and Security Leaders | AI agent security is the practice of governing two separate things: what an autonomous AI system is allowed to reach, and what it is allowed to do. Most enterprises have built a program for the first one. Almost nobody has built one for the second, and that's where the losses are starting to show up. | AI blog | Morphisec Blog |
|
3.10.26 |
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat | RATHat's Android malware remained largely static from late 2025 to September 2026, while its Command-and-Control (C2) panel was replaced entirely and went through three generations in six months, rebranded from BlackCat to Panda Workshop. | Malware blog | Cleafy |
|
3.10.26 |
TIKTOUK: Tracing a WordPress Credential Collection Toolkit | TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes target tasks and receives collected data and status reports. | Hacking blog | LEVELBLUE |
|
3.10.26 |
Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators | CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments. | Vulnerebility blog | LEVELBLUE |
|
3.10.26 |
Citrix NetScaler Zero-Day Exploited Globally | On Sept 27, Citrix released patches for two critical vulnerabilities being exploited in the wild. Based on current information, we confirm there has been no exposure or impact to LevelBlue or our clients. CISA has already added these vulnerabilities to the Known Exploited Vulnerabilities (KEV) list. | Vulnerebility blog | LEVELBLUE |
|
3.10.26 |
Hackers exploit FortiMail zero-day before a patch exists | Fortinet says attackers are already exploiting a critical flaw in FortiMail, its email security gateway, and the fixed software has not shipped yet. The bug, tracked as CVE-2026-104286 and rated 9.8 on CVSS v3, lets an attacker with no login write arbitrary files to the appliance using crafted HTTP or HTTPS requests. Fortinet rates its impact as executing unauthorized code or commands. | Vulnerebility blog | IntelFusions |
|
3.10.26 |
Introducing Cloudflare Basin: an open, serverless data platform, now generally available | During Birthday Week 2025, we announced the Cloudflare Data Platform, a suite of products that ingest, store, and query your analytical data. Today, we’re announcing that the platform is generally available, and we’re giving it a new name: Cloudflare Basin. | Cyber blog | CLOUDFLARE |
|
3.10.26 |
Introducing Clef: our open-source decision models, and new RL fine-tuning platform | Over the last few weeks, there has been lots of buzz around decision models such as Typesafe AI’s Jev System One model. While classifier models have been around for some time, Jev introduces a new decision model concept into the world of AI — a model that produces bounded structured outputs cheaply, quickly and consistently that can be added into a workflow when a decision is required. | AI blog | CLOUDFLARE |
|
3.10.26 |
One year later: Sovereign AI and the fight for choice | It's Birthday Week, when we traditionally ship presents to the Internet. This year, two of them come from Europe: EuroLLM, which covers all 24 official EU languages, and Apertus, Switzerland's fully open model, trained on more than 1,500 languages. Both were built by public universities and research institutions. Both are coming to Workers AI, and you can request access today. | AI blog | CLOUDFLARE |
|
3.10.26 |
Introducing Workers KV Instant — powered by Quicksilver | Today, we’re introducing Workers KV Instant, a new mode for Workers KV that pushes your changes globally for instant availability without cold read penalties. | Cyber blog | CLOUDFLARE |
|
3.10.26 |
Cloudflare OS: your company’s agent workspace, managed for you | Cloudflare OS gives everyone in your organization an agent workspace that knows how your company works and connects to its data and systems. Today, we're opening the waitlist for fully managed Cloudflare OS deployments. | Cyber blog | CLOUDFLARE |
|
3.10.26 |
Announcing Cloudflare K2: serverless event streams | With traditional Remote Procedure Call (RPC) architectures, there exists a core challenge: producers and consumers must align in scale and in time. If your producers send too much data for your consumers to handle or if your consumers or downstream services become unavailable, events are dropped. | Cyber blog | CLOUDFLARE |
|
3.10.26 |
We want you to build the next Git platform on Cloudflare | GitHub was built for a world where humans write code, organize it into repositories, and collaborate through branches, commits, issues, and pull requests. | Cyber blog | CLOUDFLARE |
|
3.10.26 |
AI Search is now generally available | Cloudflare’s AI Search combines Workers AI, Vectorize, R2, and Browser Run into a fully managed index and retrieval pipeline. Since we launched AI Search over a year ago, we’ve seen developers use it to power a wide range of search use cases, from searching internal documentation to powering search for their websites. We use AI Search ourselves to power search on our own blog and developer docs. | AI blog | CLOUDFLARE |
|
3.10.26 |
Support for modern cryptographic algorithms in Workers | Today, Cloudflare Workers is adding support for post-quantum-resistant algorithms within Web Crypto. These are defined in Modern Algorithms in the Web Cryptography API draft community group report, and include: | Cyber blog | CLOUDFLARE |
|
3.10.26 |
Cloudflare Impact reaches $100 million in donations | This week, Cloudflare's Impact programs will reach $100 million in donated services. It's a significant milestone, and one that we are proud of because it means that thousands of organizations, like journalism outlets, civil society, state and local governments, election management bodies, and public schools are being protected from cyberattacks. | Cyber blog | CLOUDFLARE |
|
3.10.26 |
Cut your AI spend with AI Gateway's Auto Router | From our conversations with companies at every stage of their AI adoption journey, we've seen some common patterns. First, there is an exploration period as you bring on every new tool, dole out API keys freely, and let the tokens flow. Then, you converge on the canonical tools for your organization for agentic coding, for non-technical workflows, for running and deploying agents. | AI blog | CLOUDFLARE |
|
3.10.26 |
Detect and send production issues straight to your agent | As agents help us build more complex applications, both humans and agents need a better way to stay on top of what goes wrong in production. Coding agents can already query observability data, navigate a repository, change code, write tests, and open a pull request. | AI blog | CLOUDFLARE |
|
3.10.26 |
Simplifying domains for people and agents | You just thought of your next great idea, and buying the right domain feels like the easiest way to make that first bit of progress. Naturally, you open a new tab in your browser, only to find yourself face-to-face with an experience that feels like a budget airline peppering you with add-ons at checkout: Want security? How about a website? Do you want email? You’re just a few minutes into building your next idea, and it doesn’t feel fun anymore. | AI blog | CLOUDFLARE |
|
3.10.26 |
Monetization Gateway beta: charge AI agents for consumption with HTTP 402 | Today, we’re making the Cloudflare Monetization Gateway available as part of a closed beta, and showcasing four customer use cases that are in production today. Since we announced the plan three months ago, we have been working closely with our customers to make the Gateway fast, flexible, and easy to use. | AI blog | CLOUDFLARE |
|
3.10.26 |
Pay Per Use: when AI uses your work, you should get paid | AI answer engines read a publisher’s page and hand the reader a summary, so the visit, and the revenue that would come with it, never happens. Most publishers will never sign a licensing deal with the companies that use their work in AI products, and no company can negotiate with millions of sites. The web needs a way to say “yes, if you pay.” Pay Per Use is one way to say it, and it's now in beta. | AI blog | CLOUDFLARE |
|
3.10.26 |
Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem | The Spetsvuzavtomatika leak found on the darknet exposes a broad Russian cyber research and development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supports internal-network access and credential theft. | CyberCrime blog | DomainTools Investigations |
|
3.10.26 |
AI Security Strategy: 6 Steps for CISOs | Security teams are used to vetting technology before it arrives. With AI, it was already everywhere before anyone asked them. | AI blog | Abnormal AI |
|
3.10.26 |
Signatures Are the Floor, Not the Ceiling | See why signature-based detection struggles against AI-generated attacks and how behavioral AI uses embeddings to detect novel threats without relying on known indicators. | AI blog | Abnormal AI |
|
3.10.26 |
How Behavioral AI Detects Threats That Look Normal | Attackers are no longer breaking in but blending in, mimicking normal behavior to breach organizations. A founding Abnormal AI engineer explains why we bet on behavioral AI to stop attackers walking through the front door. | AI blog | Abnormal AI |
|
3.10.26 |
XCTDH Adopts Hash Hiding | A blockchain-based C2 technique discovered in the XCTDH campaign's September 2026 evolution, where C2 addresses are steganographically encoded in Ethereum transaction destination addresses. | Cryptocurrency blog | Ransom-ISAC |
|
3.10.26 |
September 2026 Security Release | An attacker-controlled, allow-listed remote URL can lead to Server-Side Request Forgery (for example to private IP ranges) during Image Optimization. If no images.remotePatterns are configured, your application is not affected. | Security blog | Next.js |
|
3.10.26 |
Beyond Model Alignment: Securing Every Layer of the AI Agent | Alignment makes a model well-intentioned, but it can’t secure the harness, tools, and data an agent touches in production. Real agent security means governing every layer with enforcement the agent itself can’t switch off. | AI blog | Trend Micro |
|
3.10.26 |
ShinyHunters Returns to PeopleSoft With a One-Character WAF Bypass | ShinyHunters is once again exploiting a previously patched vulnerability in PeopleSoft, which we analyzed in June 2026. | Incident blog | Trend Micro |
|
3.10.26 |
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes | Compromised MemTensor npm releases turn an AI memory plugin into a credential-harvesting entry point, exposing prompts and creating a path to further package compromise. | Malware blog | StepSecurity |
|
3.10.26 |
Managing Agentic AI: Why the Control Plane Problem Is an AI Problem | On one hand, it’s somewhat befuddling how often people may need that reminder. In reality, it is not that they don’t know that happy mantra, it’s that they struggle to gain the requisite visibility into … everything in their IT and OT environments. | AI blog | GUIDESECURITY |
|
3.10.26 |
Cloud Security Assessments: Set the Right Cadence | While cloud practitioners are accustomed to their fast-moving environments, it’s still common practice to move on to the next priority after the cloud assessment report is delivered and the major findings get remediated. | Cyber blog | GUIDESECURITY |
|
3.10.26 |
New Report from Rapid7 Labs: Why Q2 2026 signals the end of traditional patch cycles | The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. | Cyber blog | RAPID7 |
|
3.10.26 |
Why One-Time Approval Fails for AI Agent Skills | A review answers one question, once: is this skill, MCP server or plugin allowed in? It never asks again, whether it took six weeks in a ticket queue or six minutes in a governance tool. | AI blog | Manifold |
|
3.10.26 |
Spanish Carding Tutorial: How Fraudsters Think | A 2,200-word tutorial titled “Complete Guide to Carding in Spain (2026)” appeared on the Carder Market forum in April 2026. It is exactly what it sounds like: a beginner’s playbook for credit card fraud targeting the Spanish market, complete with entry fees, expected returns, and step-by-step operational workflows (we are holding back specific names and techniques to execute attacks to prevent these from falling into those with malicious intentions). | CyberCrime blog | FLARE.IO |
|
3.10.26 |
Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) | On Wednesday, September 30, Cisco dropped an out-of-band security advisory highlighting CVE-2026-76504, a brand new critical authentication bypass in the SD-WAN vManage line of products that was disclosed as an exploited zero-day vulnerability. | Vulnerebility blog | VULNCHECK |
|
3.10.26 |
JCTables for Joomla: When "Already Escaped" Means Injectable | Today VulnCheck is disclosing CVE-2026-76570, an unauthenticated arbitrary SQL read and write in JCTables, the Joomla data-table component published by JoomCode, that chains to remote code execution as the web user. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy. | Vulnerebility blog | VULNCHECK |
|
3.10.26 |
CVE-2026-86950: Apple CoreGraphics Zero-Day | Apple has issued an urgent security patch for CVE-2026-86950, a critical zero-day out-of-bounds write vulnerability in CoreGraphics that enables arbitrary code execution via malicious files. Exploited in targeted, highly sophisticated attacks against specific individuals, this flaw presents an immediate threat across affected Apple platforms. | Vulnerebility blog | SOCRADAR |
|
3.10.26 |
CVE-2026-76504: Cisco SD-WAN Flaw Exploited | Cisco has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Catalyst SD-WAN Manager, formerly known as vManage. The flaw allows an unauthenticated remote attacker to access the management API with administrator privileges. | Vulnerebility blog | SOCRADAR |
|
3.10.26 |
TeamViewer Fixes Five Remote Access Flaws | TeamViewer has patched five high-severity vulnerabilities in its Full Client and Host applications for Windows, Linux, and macOS. The flaws include local privilege escalation, potential code execution, and remote session access control bypass. The company strongly recommends that all users update to the latest available version as soon as possible. | Vulnerebility blog | SOCRADAR |
|
3.10.26 |
Gotta Breach 'Em All! The Journey Of ShinyHunters | ShinyHunters has outlasted forum takedowns, multiple arrests, and its own founders' convictions. This report traces six years of activity and tactical evolution. From stolen S3 buckets to zero-day exploits, we attempted to explain why the brand keeps surviving what should have ended it. | Cyber blog | SEKOIA |
|
3.10.26 |
The New Rules of Patching: When a Fix Becomes a Blueprint for Attackers | TL;DR: Frontier AI has collapsed the vulnerability exploit window from weeks to mere hours. Attackers now use advanced AI models to reverse-engineer published fixes and generate working exploits faster than human security teams can deploy updates. In the AI era, publishing a patch creates a blueprint for attackers. Surviving this threat requires vendors to tier sensitive disclosures and customers to treat patch application speed as a critical security metric. | AI blog | JFROG |
|
3.10.26 |
ANY.RUN's Threat Coverage Digest: September 2026 | September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. | Cyber blog | ANYRUN BLOG |
|
3.10.26 |
Copilot has the largest AI attack surface of any tool we tracked | Microsoft Copilot accounts for a disproportionate share of the AI footprint we track, and it’s barely being used. It’s a massive attack surface featuring a minuscule rate of activity. | AI blog | ThreatDown |
|
3.10.26 |
Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy | Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements. | Phishing blog | GROUP-IB |
|
3.10.26 |
Anatomía de BraZetsu: Cómo los cibercriminales abastecen el ecosistema clandestino | Group-IB descubre BraZetsu, un nuevo malware para Windows basado en Python que funciona como un toolkit maestro para Initial Access Brokers y potencia un marketplace clandestino único, mejorado con IA, para comercializar objetivos comprometidos en Iberoamérica y Latinoamérica. | Malware blog | GROUP-IB |
|
3.10.26 |
Your State’s Scam Reality: What New Research Reveals Across All 50 States | A package notification arrives, and we stop to check whether we actually ordered something. A recruiter reaches out about a job, but before replying, we research the person and the company. A bank alert appears, and instead of tapping the link, we open the banking app ourselves. | Spam blog | McAfee Blog |
|
3.10.26 |
ClickFix Attacks: How They Work and How CrowdStrike Stops Them | Consider this hypothetical scenario: An employee tries to join what looks like a routine video meeting. The page loads, but instead of the meeting, they see an error message along with a helpful fix: Copy the provided command, open the Windows Run dialog, paste it, and press Enter. | Hacking blog | CROWDSTRIKE |
|
3.10.26 |
CrowdStrike Expands Federal SOC Modernization via CISA-Funded SIEMaaS | Falcon Next-Gen SIEM is now part of CISA’s SIEMaaS technology stack, which gives eligible agencies a funded path to modernize security through the CDM DEFEND F shared service. | Cyber blog | CROWDSTRIKE |
|
3.10.26 |
CrowdStrike and NVIDIA Extend Security Across the AI Stack | CrowdStrike and NVIDIA are collaborating on the NVIDIA Open Agent Safety Platform, an open reference design to extend security deeper into the agentic stack and establish stronger boundaries for autonomous AI. | AI blog | CROWDSTRIKE |
|
3.10.26 |
Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation | On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated remote attacker to execute code: | Vulnerebility blog | SOPHOS |
|
3.10.26 |
TerminalFix and Lorem Ipsum Loader enable covert tunneling | The activity is linked to a broader campaign that previously used a different delivery mechanism | CyberCrime blog | SOPHOS |
|
3.10.26 |
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI | Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. | AI blog | Google Cloud Blog |
|
3.10.26 |
NVIDIA and Eclypsium Partner for Trusted AI Infrastructure | AI agents are moving from answering questions to taking action. They can read sensitive data, call APIs, write and execute code, use external tools, and coordinate with other agents. In some environments, their decisions may affect physical systems. | AI blog | Trend Micro |
|
3.10.26 |
Inside DragonForce: How a Ransomware Cartel's Payload Actually Runs | DragonForce is a Ransomware-as-a-Service (RaaS) operation that first surfaced in mid-to-late 2023. It initially presented itself as a hacktivist collective before shifting to a profit-driven model. Early payloads were built on leaked LockBit 3.0 source code and later supplemented with code derived from the leaked Conti builder. | Ransom blog | Seqrite |
|
3.10.26 |
Telecom Attack Surface: SS7, BGP & Nation-State Intrusions | SS7 and BGP were built on trust. Here's how nation-state actors exploit that trust, and telecom routers, to stay inside carrier networks for years. | Hacking blog | Cyble |
|
3.10.26 |
Attack Surface Management 2026: Why Point-in-Time Scans Fail | Quarterly scans leave cloud exposures hidden for months. Learn why CISA and FBI data now make continuous attack surface management essential in 2026. | Cyber blog | Cyble |
|
3.10.26 |
Your IP, Their Traffic | You install an app that offers a reward, a premium feature or perhaps a little money in exchange for sharing some of your unused internet bandwidth. It sounds harmless enough. Your connection is idle most of the time anyway. | Cyber blog | GENDIGITAL |
|
3.10.26 |
Warlock Ransomware Attackers Hit Water and Telecom Operators | China-nexus group behind Warlock is still exploiting SharePoint vulnerabilities, attacking organizations in Portuguese and Spanish-speaking countries, hitting critical infrastructure, government, and education organizations. | Ransom blog | SECURITY.COM |
|
3.10.26 |
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 | Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled, without requiring authentication or user interaction. | Vulnerebility blog | Microsoft blog |
|
3.10.26 |
Phishing Abuses RMM Tools for Persistent Access | In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. | Phishing blog | Microsoft blog |
|
3.10.26 |
Safely Securing AI Agents | Learn of the benefits of safely securing AI agents. | AI blog | Trend Micro |
|
3.10.26 |
IBM Langflow OSS Unauthenticated RCE - CVE-2026-9198 | The SonicWall Capture Labs threat research team became aware of an Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation in Langflow AI, assessed its impact and developed mitigation measures. Langflow AI is a Python-based web application that provides a visual interface to build AI-driven agents and workflows. | Vulnerebility blog | SonicWall |
|
3.10.26 |
SmokeLoader Malware: A Modular Threat with Advanced Evasion and Persistence | This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of SmokeLoader malware. This is a modular program used by a variety of criminal and APT groups to gain a foothold on a system. It has vigorous anti-VM, anti-AV, and anti-analysis checks and capabilities. SmokeLoader can be used with RATs, ransomware, backdoors or botnets and uses both file and fileless methods of persistence. | Malware blog | SonicWall |
|
3.10.26 |
VioletRAT v6.5: From .NET Loader to In-Memory RAT — A Deep Dive into the Infection Chain | Recently, the SonicWall Capture Labs Threat Research Team discovered a sophisticated multi-stage .NET malware campaign that delivers VioletRAT v6.5 through a heavily obfuscated infection chain. The malware uses multiple .NET loader stages, an obfuscated batch script, in-memory assembly loading, and process injection into Msbuild.exe before executing the final VioletRAT payload. | Malware blog | SonicWall |
|
3.10.26 |
OperTraitors: How Kubernetes Operators Betray Your Security Posture | Kubernetes operators are coded to drastically reduce operational toil by acting as automated site reliability engineers. However, their reliance on highly privileged service accounts introduces a severe, often overlooked security weak spot. | Hacking blog | Palo Alto |
|
3.10.26 |
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) | Unit 42 is aware of possible zero-day activity against NetScaler devices. In a Citrix report that details several CVEs, they noted that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild. The threat actors exploited these vulnerabilities to deliver web shells and establish their initial access and persistence into organizations. Analysis is ongoing to determine any post-compromise activity. | Vulnerebility blog | Palo Alto |
|
3.10.26 |
The Fine Art of Frustrating the Adversary | For Cybersecurity Awareness Month, eight Cisco Talos researchers share practical ways defenders can frustrate adversaries at different stages of an operation. | Cyber blog | CISCO TALOS |
|
3.10.26 |
Give yourself room to be human | Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook. | Cyber blog | CISCO TALOS |
|
3.10.26 |
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor | Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. | APT blog | CISCO TALOS |
|
3.10.26 |
Securing the keys to the kingdom: Announcing Executive Threat Detection | Attackers are using greater sophistication to gain access to high-yield targets like executives, and company-wide security measures can easily miss these subtle, personal attacks. | Cyber blog | CISCO TALOS |
|
3.10.26 |
Trust and the enticing consultancy offer | In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors. | Vulnerebility blog | CISCO TALOS |
|
3.10.26 |
The Closed Quorum: Inside the first reported autonomous AI C2 implant | CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025. | AI blog | CISCO TALOS |
|
3.10.26 |
This month in security with Tony Anscombe – September 2026 edition | Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep pace | Cyber blog | Eset |
|
3.10.26 |
Timeshare exit scams: From fake buyers to recovery scams | Con artists are targeting timeshare owners who want out – and some victims are hit twice | Spam blog | Eset |
|
3.10.26 |
The devil is still in the email – but wearing a new mask | When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack | Spam blog | Eset |
|
3.10.26 |
Is that new (vibe coded) app safe? 5 questions to ask first | As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data | Cyber blog | Eset |