Skip to content
BLACKMESA.CA Security Feed

Security Feed

Cybersecurity news & advisories

500 articles 46 of 46 sources updated RSS ↗

Latest

News The Hacker News

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Vuln APT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as…

↗ Open article
Trending News The Register Security

Citrix gives NetScaler admins another critical reason to patch

CVE-2026-107406 ↗ Vuln

Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to…

↗ Open article ↗ CVE feed
News The Hacker News

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from…

↗ Open article
Threat Intel Malwarebytes Labs

ASOS breach update: Hackers stole customer details and shopping searches

Breach

The customer data stolen from global fashion retailer ASOS includes more than just names and contact details, raising questions about its early reassurances. As we reported earlier this week, ASOS customers received a…

↗ Open article
Trending News Cyber Security News

MATCHBOIL Malware Uses Cloudflare-Hidden C2 Servers to Deliver Backdoor Payloads

Malware

MATCHBOIL, a C# malware downloader linked to UAC-0099, uses command-and-control (C2) servers hidden behind Cloudflare to deliver backdoor payloads. Its changing code shows how the group has moved from a simple…

↗ Open article
News Cyber Security News

PoC Released for Telegram Desktop Flaw Enabling One-Click File Account Takeover

CVE-2026-107181 ↗ Research

A public proof of concept has exposed a flaw in Telegram Desktop that could let attackers steal local files and take over accounts after a user clicks a crafted external link. Tracked as CVE-2026-107181, the…

↗ Open article ↗ CVE feed
News Cyber Security News

Top 10 Best Container Image Scanning Tools in 2026 [Ranked & Scored]

Every image scan returns hundreds of CVEs; the question is which ten your containers actually execute and which base image would zero the list entirely. We scored ten options with context and elimination weighted above…

↗ Open article
News The Hacker News

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address…

↗ Open article
News Cyber Security News

New Anthropic OSS Scanner Tool to Scan Open-source Repositories for Vulnerabilities

Vuln

Anthropic has introduced OSS Scanner, a free service that checks critical open-source repositories for security vulnerabilities and sends findings directly to project maintainers. The opt-in program uses the company’s…

↗ Open article
News Cyber Security News

Top 10 Best Bug Bounty Platforms in 2026 [Ranked & Scored]

Research

Researchers are testing your perimeter tonight whether you invited them or not bounty platforms decide whether that energy reaches your inbox or the dark web. Evaluating the offensive testing market alongside the best…

↗ Open article
Trending News Cyber Security News

Let’s Encrypt Cuts TLS Certificate Lifetimes From 90 to 64 Days Starting February 2027

Let’s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from…

↗ Open article
News Cyber Security News

Top 10 Best IaC Security Tools in 2026 [Ranked & Scored]

Breach

The misconfiguration that breaches you in production was mergeable in review IaC security exists to catch it there. Evaluating the market alongside modern Infrastructure as Code (IaC) scanning tools demonstrates that…

↗ Open article
Trending News The Hacker News

Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Vuln Research

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits…

↗ Open article
Trending News Cyber Security News

Microsoft Says PKI, HSMs and Security Appliances Must Prepare for Post-Quantum Authentication

Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need…

↗ Open article
Trending News The Hacker News

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Vuln DoS

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions…

↗ Open article
Trending News Cyber Security News

VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware Infrastructure

Malware

VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records…

↗ Open article
News The Hacker News

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end…

↗ Open article
News Cyber Security News

Leaked Chat Logs Show Silent Ransomware Extorted Over $200,000,000 in 6 Months Without Encrypting Data

Ransom

Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting victims’ files. The reported earnings point to the power of data…

↗ Open article
News The Register Security

US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group and used by Beijing-backed cyber operatives to scan a South…

↗ Open article
News CyberScoop

Leader of 764 pleads guilty, faces up to 30 years in prison

A 21-year-old from North Carolina who joined and helped establish 764 as an underage teenager and quickly emerged as the leader of the child sextortion group until his arrest last year pleaded guilty in federal court…

↗ Open article
News CyberScoop

Anthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source software

Vuln

Anthropic announced a new program Thursday that will combine its AI tools with outside cybersecurity companies to find and fix cybersecurity vulnerabilities in critical infrastructure and open-source software…

↗ Open article
Threat Intel Microsoft Security Blog

Post-quantum authentication: Why organizations should start testing certificate ecosystems now

Post-quantum cryptography (PQC) planning often focuses on protecting encrypted data, but authentication systems must also evolve. Certificates, trust anchors, PKI services, applications, devices, and hardware security…

↗ Open article
News CyberScoop

DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub

The Justice Department and FBI announced that they had seized two hacking tools connected to the Chinese government-linked group Flax Typhoon and a China-based company that the U.S. government has repeatedly taken…

↗ Open article
Trending Media Ars Technica Security

Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027

Let's Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027. For administrators already implementing modern ACME clients…

↗ Open article
News CyberScoop

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Ransom

Authorities accuse the owner of a so-called ransomware remediation company of swindling clients victimized by ransomware attacks into paying the company inflated fees under false pretenses. Zohar Pinhasi, owner and…

↗ Open article
Trending News Bleeping Computer

Low-cost Android phones ship with residential proxy malware

Malware

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad…

↗ Open article
News The Hacker News

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other…

↗ Open article
News The Register Security

High-severity Nvidia bug could crash GPU monitoring on exposed servers

Research

Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring…

↗ Open article
News 404 Media

'It Is Done. Hail Satan:' City Immediately Regrets New Religious Liberty Law That Allows Prayer at City Council Meeting

An Iowa man has kicked off controversy over religious freedom in the small town of Ottumwa, Iowa by opening a city council meeting with a prayer to Satan, which then kicked off a debate about the proper time in the…

↗ Open article
Threat Intel Cisco Talos

Making sure the checks get printed

Welcome to this week’s edition of the Threat Source newsletter. My name is Pierre Cadieux, and I’ll be helping contribute to these newsletters. A little about me: I’ve been working in the cybersecurity industry in many…

↗ Open article
News The Hacker News

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Ransom Malware

The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently…

↗ Open article
News CyberScoop

OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media

OpenAI disclosed Thursday it shut down two influence operations from Russia and Iran that used ChatGPT and other AI tools to create fake journalist personas and covert think tanks that successfully planted stories and…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.