Skip to content
BLACKMESA.CA Security Feed

Security Feed

Cybersecurity news & advisories

500 articles 46 of 46 sources updated RSS ↗

Latest

News The Register Security

OpenAI's wandering AI agents earn it a California subpoena

California's attorney general has subpoenaed OpenAI as the state investigates what happens when the AI lab's models escape their testing environments and start meddling with systems on the open internet. Attorney…

↗ Open article
Trending News Cyber Security News

Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel

Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools…

↗ Open article
News Bleeping Computer

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and…

↗ Open article
News Cyber Security News

Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials

Hackers are turning trusted software updates into a route for stealing developer and cloud credentials. Recent supply chain incidents show how a single altered package, build action, or publishing token can place…

↗ Open article
News Cyber Security News

Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks

Vuln

Red Hat has fixed a high-impact vulnerability in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host information , including root passwords. Under unsafe configurations, the…

↗ Open article
News Cyber Security News

Multiple Cpanel/WHM Vulnerabilities Allow Arbitrary Command Execution On Server

Vuln

Multiple security flaws in cPanel & WHM could let attackers run malicious scripts in an administrator’s browser session or execute arbitrary commands as root. The vulnerabilities were disclosed on September 29, 2026…

↗ Open article
News Cyber Security News

OpenClaw Launches Free Open-source Enterprise Agent Platform for AI Agents

OpenClaw has launched OpenClaw Enterprise (OCE), a free, open-source platform that helps organizations run persistent AI agents with stronger security and central oversight. Announced on September 29, 2026, the project…

↗ Open article
Trending Research Rapid7 Blog

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen…

↗ Open article
Trending News Cyber Security News

Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive…

↗ Open article
News The Hacker News

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

Research

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for…

↗ Open article
News Cyber Security News

Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access

Vuln

Two critical Zammad zero-day flaws , reportedly exploited against the Dutch Institute for Vulnerability Disclosure (DIVD), could allow session hijacking, remote command execution as the Zammad service user, and…

↗ Open article
News Cyber Security News

Free iCloud Account Could Let Attackers Spoof Any @icloud.com Address and Pass Email Security Checks

Vuln Policy Research

Security researcher Timo Longin, working with the SEC Consult Vulnerability Lab, disclosed two email spoofing flaws in Apple’s iCloud mail infrastructure that could have let someone with a free iCloud account send…

↗ Open article
News Cyber Security News

Sony Rolls Out PS5 Security Update Following the Release of Relapse Jailbreak

Sony has moved to protect PlayStation 5 consoles with its latest system software update, as the newly released Relapse jailbreak draws attention to a broad set of older PS5 firmware versions. The update matters for…

↗ Open article
News The Hacker News

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

Vuln

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a…

↗ Open article
Trending News Cyber Security News

Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users

Vuln

A flaw in a custom session-cookie system allowed an unauthenticated attacker to pose as employees and administrators in a yard management platform. The issue did not break Microsoft Entra ID itself. Instead, it let a…

↗ Open article
Research Trail of Bits

SequenceHash: multihashing for the rest of us

Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes. As part of our goal…

↗ Open article
Trending News The Register Security

Fortinet sounds the alarm over actively exploited FortiMail zero-day

CVE-2026-104286 ↗ Vuln

Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a…

↗ Open article ↗ CVE feed
Trending News The Hacker News

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android…

↗ Open article
Trending News The Hacker News

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of…

↗ Open article
News The Register Security

AI agents hacked the hackers, stealing email addresses from security research org

Vuln Research

AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad…

↗ Open article
Media Ars Technica Security

Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data

The Pentagon is informing more than 2 million current and former military members that their personnel records storing sensitive personal information were stolen over a monthslong compromise of one of its networks. The…

↗ Open article
News CyberScoop

Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members

Ransom Breach

Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024, Europol and the Justice…

↗ Open article
Trending News Bleeping Computer

Microsoft says threat actors are ahead in the early AI race

Vuln Malware

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity…

↗ Open article
News CyberScoop

National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations

Collaboration with industry is key to balancing AI security risks and benefits, as well as staying ahead of China and other adversarial nations, National Cyber Director Sean Cairncross said Thursday. The Trump…

↗ Open article
Advisory Tenable Security Advisories

[R1] Nessus Version 10.12.5 Fixes Multiple Vulnerabilities

Vuln

[R1] Nessus Version 10.12.5 Fixes Multiple Vulnerabilities Arnie Cabral Thu, 10/01/2026 - 14:31 Several vulnerabilities have been identified, reported to Tenable and resolved. Please see the full list of resolved issues…

↗ Open article
Threat Intel Cisco Talos

Give yourself room to be human

Welcome to this week’s edition of the Threat Source newsletter. Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit…

↗ Open article
News The Register Security

EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in…

↗ Open article
Threat Intel Malwarebytes Labs

Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the…

↗ Open article
News The Hacker News

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Ransom

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.