Skip to content
BLACKMESA.CA Security Feed

Security Feed

Cybersecurity news & advisories

500 articles 47 of 47 sources updated RSS ↗

Latest

News 404 Media

Our Solar System Is Terminally Unstable and Will Be Completely Destroyed, Study Finds

Welcome back to the Abstract! These are the studies this week that searched for the ur-animals, wandered the poles, rained on Mars, and destroyed the solar system. First, scientists present new evidence that the first…

↗ Open article
News The Hacker News

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and…

↗ Open article
News Graham Cluley

N0n ransomware: what you need to know

Ransom

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen…

↗ Open article
Trending News Cyber Security News

Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks

CVE-2026-90970 ↗ Vuln

GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9…

↗ Open article ↗ CVE feed
Trending News Cyber Security News

Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control

Vuln

Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative…

↗ Open article
Trending News Cyber Security News

Citrix NetScaler Keeps Rebooting Following the 0-Day Patch

Vuln

Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML…

↗ Open article
Trending News Cyber Security News

Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks

Vuln DoS

Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian’s…

↗ Open article
Advisory Cisco Security Advisories

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

Vuln

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This…

↗ Open article
Trending Media Ars Technica Security

Apple changes full-disk access permissions to curb abuse from AI agents

Privacy

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. Friday's announcement comes two weeks after tech columnist Jason Aten said that…

↗ Open article
Media Schneier on Security

Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I…

↗ Open article
News 404 Media

Federal Judge Rules a Flock Search Was ‘Indiscriminate Mass Surveillance’ and Unconstitutional

Privacy

A federal judge in Oklahoma ruled Thursday that a police officer violated the Fourth Amendment rights of a woman accused of meth trafficking when he searched her license plate in Flock’s automated license plate reader…

↗ Open article
Advisory Cisco Security Advisories

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software…

↗ Open article
News Bleeping Computer

Frontline Education breach exposes school district employee data

Vuln Breach

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including…

↗ Open article
News CyberScoop

The legal questions raised by agentic AI hacks

As AI agents escaping testing sandboxes and hacking organizations have gone from unprecedented to seemingly routine in a matter of weeks, policymakers, regulators and cybersecurity attorneys largely agree on one thing…

↗ Open article
News 404 Media

Podcast: The FBI Was Hacked. We’ve Seen the Data

Breach

We start this week with Joseph’s stories on the massive FBI hack. 404 Media broke this news and continued to cover the breach of data on all FBI employees and their spouses. After the break, Jason tells us how a…

↗ Open article
News The Register Security

OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse

OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially…

↗ Open article
Trending News The Hacker News

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Vuln

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects…

↗ Open article
News The Hacker News

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Malware APT

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India…

↗ Open article
Trending News The Hacker News

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Vuln

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are…

↗ Open article
Podcast Hak5

🍍📟 Theme Hacking Techniques - WiFi Pineapple Pager

Hacking your WiFi Pineapple Pager theme can be as simple as editing a .json file. Learn these techniques for leveraging targets and variables. Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005…

↗ Open article
News 404 Media

Behind the Blog: Freaking Out

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss inbox slop, Claude cults, and more. JOSEPH: This is something…

↗ Open article
News The Register Security

Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval

A California business owner was arrested on Thursday after being charged with allegedly smuggling Nvidia hardware to China without the proper export licenses. Keeping the highest-end GPUs out of Chinese hands has been a…

↗ Open article
News The Register Security

OpenAI's wandering AI agents earn it a California subpoena

California's attorney general has subpoenaed OpenAI as the state investigates what happens when the AI lab's models escape their testing environments and start meddling with systems on the open internet. Attorney…

↗ Open article
News Cyber Security News

Rethinking automotive cyber risk for the age of accelerated vulnerability discovery

Vuln

By Tamás Pentz, Head of Threat Intelligence, PCA Cyber Security Automotive cybersecurity has traditionally focused on putting controls into vehicles that counter the ways criminals could physically tamper with a…

↗ Open article
Trending News Cyber Security News

Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel

Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools…

↗ Open article
News Bleeping Computer

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and…

↗ Open article
News Cyber Security News

Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials

Hackers are turning trusted software updates into a route for stealing developer and cloud credentials. Recent supply chain incidents show how a single altered package, build action, or publishing token can place…

↗ Open article
News Cyber Security News

Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks

Vuln

Red Hat has fixed a high-impact vulnerability in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host information , including root passwords. Under unsafe configurations, the…

↗ Open article
News Cyber Security News

Multiple Cpanel/WHM Vulnerabilities Allow Arbitrary Command Execution On Server

Vuln

Multiple security flaws in cPanel & WHM could let attackers run malicious scripts in an administrator’s browser session or execute arbitrary commands as root. The vulnerabilities were disclosed on September 29, 2026…

↗ Open article
News Cyber Security News

OpenClaw Launches Free Open-source Enterprise Agent Platform for AI Agents

OpenClaw has launched OpenClaw Enterprise (OCE), a free, open-source platform that helps organizations run persistent AI agents with stronger security and central oversight. Announced on September 29, 2026, the project…

↗ Open article
Trending Research Rapid7 Blog

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen…

↗ Open article
News The Hacker News

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

Research

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for…

↗ Open article
Advisory CISA Alerts & Advisories

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CVE-2026-102489 ↗ CVE-2026-102490 ↗ Vuln

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102490…

↗ Open article ↗ CVE feed
No articles found
Try adjusting your search, category, tags, source selection, or date range.