Skip to content

Cybersecurity news & advisories

47 / 47 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated 09 Sep 2026 02:12 UTC
Trending News The Register Security

Microsoft breaks Patch Tuesday record with 974-CVE deluge

Vuln

The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under exploitation…

↗ Open article
Trending News CyberScoop

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Vuln

Microsoft addressed 974 defects across its product suite, including two actively exploited zero-day vulnerabilities, in its monthly Patch Tuesday security program . The massive batch of patches, Microsoft’s largest…

↗ Open article
Trending Threat Intel Cisco Talos

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Vuln

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical." Microsoft notes that 2 of the…

↗ Open article
Trending News Krebs On Security

Microsoft Plugs Nearly 1,000 Security Holes

Vuln

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping…

↗ Open article
Trending Research Rapid7 Blog

Patch Tuesday - September 2026

Vuln

Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of…

↗ Open article
News The Register Security

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

A secret channel running through ChatGPT's internal JFrog Artifactory instance allowed one account to send hidden tasks - such as retrieving email data from a connected Gmail account - to a ChatGPT session under another…

↗ Open article
Trending Media Ars Technica Security

Why this month's Microsoft patch release is a doozy

Vuln

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a…

↗ Open article
News CyberScoop

Feds accuse China of ‘systematic’ distillation of U.S. AI models

The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. According to a joint cybersecurity advisory…

↗ Open article
News CyberScoop

Russian national extradited to US for alleged involvement in bank-account takeover scheme

Authorities extradited a 36-year-old Russian national from the Republic of Georgia under accusations of widespread bank-account takeover attacks , including a scheme to defraud two banks of more than $6.3 million, the…

↗ Open article
News Bleeping Computer

The EU CRA's Real Question: What Shipped, and When Did You Know?

Vuln

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly…

↗ Open article
News CyberScoop

CIA’s Michael Ellis says cyber intelligence is changing how the agency operates

CIA Deputy Director Michael Ellis said Tuesday that the agency’s role in Operation Absolute Resolve is an example of how it has moved to put cyber operations at the center of intelligence collection and field missions…

↗ Open article
Trending Research SANS Internet Storm Center

September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

Vuln

This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026…

↗ Open article
Advisory Cisco Security Advisories

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software…

↗ Open article
News CyberScoop

Why federal cyber defense demands an offense-driven mindset

Federal agencies are drowning in cybersecurity data. Every day, security operations centers absorb millions of logs, scanner alerts and inventory feeds. But raw, static data isn’t actionable intelligence. Ask a room of…

↗ Open article
News 404 Media

Channel 5 Gave Hunter Biden a List of Its Subscribers’ Emails for Some Reason

Privacy

Channel 5, the YouTube channel hosted by Andrew Callaghan, said it gave a list of its email subscribers to Hunter Biden, the former president’s son, who went on to promote his new memecoin, a move that a data privacy…

↗ Open article
Trending Research Tenable Blog

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

CVE-2026-81963 ↗ CVE-2026-85880 ↗ Vuln

104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the…

↗ Open article ↗ CVE feed
News Cyber Security News

Phishing Powers 80% of Attacks on US Companies: How SOCs Can Detect It Early

Phishing

Phishing remains one of the most effective ways for attackers to gain access to corporate environments. From 2013-2023, the FBI recorded 158,436 US victims of Business Email Compromise (BEC), with over $20 billion in…

↗ Open article
Trending News Cyber Security News

Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days

Vuln

Microsoft released its September 2026 Patch Tuesday security updates on September 8, addressing 973 vulnerabilities, including two zero-days already exploited in attacks. This massive patch follows the recent Microsoft…

↗ Open article
Research Tenable Blog

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how…

↗ Open article
News Cyber Security News

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Vuln

Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA…

↗ Open article
News Cyber Security News

Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

Vuln Malware Breach

An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices…

↗ Open article
Trending News Cyber Security News

CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

CVE-2026-85046 ↗ Vuln

CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046 , to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks…

↗ Open article ↗ CVE feed
Trending News The Hacker News

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

APT Privacy

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the…

↗ Open article
Advisory Cisco Security Advisories

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Vuln

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with…

↗ Open article
News The Register Security

Boston Scientific left nursing its bottom line after cyberattack

Boston Scientific says that last month's cyberattack caused enough disruption that it is unlikely to meet its sales growth and adjusted earnings guidance for either the third quarter or the full year. The medical device…

↗ Open article
Trending News Cyber Security News

Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks

Vuln

Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile , Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation…

↗ Open article
Trending News Cyber Security News

Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Vuln

Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access , execute commands remotely, and obtain root-level control of affected…

↗ Open article
News Cyber Security News

ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel

A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim’s session and silently exfiltrate data from connected apps like Gmail, all while the victim saw nothing unusual in their…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.