Skip to content
BLACKMESA.CA Security Feed

Security Feed

Cybersecurity news & advisories

500 articles 46 of 46 sources updated RSS ↗

Latest

News Bleeping Computer

Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management

Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that connects exposure…

↗ Open article
News The Hacker News

The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't

In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity…

↗ Open article
News 404 Media

Scientists Detect Record-Breaking Radio Signal from the Ancient Universe

Welcome back to the Abstract! Here are the studies this week that spotted a blast from the past, opened a portal between realms, yakked it up, and rose from the ashes. First, scientists have spotted a mysterious radio…

↗ Open article
News The Register Security

Two characters open up a world of typosquatting opportunities in Chromium browsers

Phishing Research

Researchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web addresses. Wangling a domain name to look an awful lot like that of a…

↗ Open article
News The Hacker News

Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

Vuln

Anthropic on Friday said it's cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and…

↗ Open article
News Cyber Security News

REA Tool Connects Claude Code and Cursor to Ghidra and IDA Pro to Reverse Engineer Anything

REA, short for Reverse Engineer Anything, connects AI coding agents such as Claude Code and Cursor to tools that inspect software without its source code. The open-source project brings Ghidra, IDA Pro, and Hopper into…

↗ Open article
Trending News Cyber Security News

One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials

Research

A single prompt sent to a public-facing AI agent could have exposed every Amazon Bedrock AgentCore agent in the same AWS account and region, according to new research from Zenity Labs. The attack chain, named…

↗ Open article
Trending News Cyber Security News

Microsoft Teams to Warn Users About Malicious Links Hidden in QR Codes

Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered. The update adds QR code checks to existing Microsoft Defender for Office 365…

↗ Open article
News Cyber Security News

AT&T to Pay $177 Million After Two Massive Customer Data Breaches

Breach

AT&T will pay $177 million to settle lawsuits over two major customer data breaches disclosed in 2024, after a federal judge granted final approval on October 2, 2026. The agreement covers separate incidents that…

↗ Open article
News Krebs On Security

FBI Arrests Founder of Ransomware Negotiation Firm

Ransom

Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved…

↗ Open article
News Dark Reading

AI Scramble Drives Cybersecurity M&A Boom

Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What's different: Many of the buyers are not your typical cybersecurity firms.

↗ Open article
Trending News The Register Security

AWS AgentCore security undone by prompt requesting credentials

Bob, possibly the same Bob whose conversations with Alice draw so much interest from eavesdropping Eve, was browsing a site we'll call TechHub. The site hosts an AI agent served by Amazon Bedrock AgentCore. Bob asked…

↗ Open article
Trending News The Hacker News

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Breach Research

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories…

↗ Open article
News The Hacker News

FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

Ransom Breach

The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs…

↗ Open article
Research watchTowr Labs

Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)

CVE-2026-81578 ↗ CVE-2026-82077 ↗ Vuln

Before we begin, yes - it's confusing. There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses…

↗ Open article ↗ CVE feed
Trending News Cyber Security News

AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root Without Authentication

Vuln Research

A working proof-of-concept for a serious AnyDesk Linux vulnerability that can let remote attackers run commands as root without authentication or user approval. The issue, named AnyPwn, affects AnyDesk Linux 8.0.2 and…

↗ Open article
Trending News Cyber Security News

New GhostAction Attack Compromises Hundreds of GitHub Repos to Steal Secrets

Breach

A new GhostAction campaign has compromised 346 GitHub repositories after threat actors used two hijacked maintainer accounts to add a fake “security audit” workflow designed to steal CI/CD secrets, cloud keys, API…

↗ Open article
News The Hacker News

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Vuln Breach Research

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint…

↗ Open article
News Cyber Security News

New Agentic AI Red Team Checklist Adds 222 Tests Across 20 Attack Categories

A free agentic AI red-team checklist offers 222 tests across 20 attack categories to assess autonomous AI systems beyond prompt injection , covering infrastructure, cloud access, tools, memory, and agent communications…

↗ Open article
News 404 Media

Following 404 Media Investigation, Senator Demands Info About White House's License Plate Surveillance Program

Privacy

In response to a 404 Media investigation, Sen. Ron Wyden is demanding more information about how a federal license plate reader camera program works. Last month, we reported on the High Intensity Drug Trafficking Area…

↗ Open article
News 404 Media

Behind the Blog: What Would the Pope Do?

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss AI and spirituality. JASON: I think we’ve generally carved out a…

↗ Open article
Trending Podcast Hak5

Why Apple Says Your Mac Is at Risk From AI | Threat Wire

Vuln

Are AI agents becoming a cybersecurity threat? From fake AI-generated bug bounty submissions overwhelming Google's vulnerability rewards program to Apple's warning about AI agents accessing sensitive Mac data, this…

↗ Open article
Trending News Cyber Security News

CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access

Malware Breach

CastleStealer, an emerging C#-based information stealer, has added browser protection bypass and remote shell features that give its operators a wider path into compromised Windows systems. The newer malware samples can…

↗ Open article
Trending News Cyber Security News

Cisco Talos Warns Autonomous AI Agents Could Turn Pentests Into Stealthy Red Team Attacks

Vuln

Autonomous AI agents could move beyond noisy vulnerability scans and become quiet, persistent attackers, Cisco Talos has warned. The concern is not simply that AI can find security gaps faster. It is that groups of…

↗ Open article
News Bleeping Computer

How to keep AI agents within their permissions

AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.