Skip to content
BLACKMESA.CA Security Feed

Security Feed

Cybersecurity news & advisories

500 articles 44 of 44 sources updated RSS ↗

Latest

News CyberScoop

OpenAI reveals ‘novel’ encryption bypass used in distillation attack

OpenAI said it disrupted a “coordinated campaign” to distill and extract reasoning capabilities from its AI models, pointing the finger at a Chinese rival. On Wednesday, OpenAI said it first spotted low-level activity…

↗ Open article
News The Register Security

Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else

OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being involved in a "distillation attack" that began July 1. The house of…

↗ Open article
Trending News 404 Media

Someone ‘Torturing’ LLMs in a Robot Prison Has Triggered the Dumbest Debate in AI Yet

One of the most heated discussions occurring on X at the moment is about the ethics of a GitHub project in which a person is running Saw-like “torture” and “pain” experiments on a series of locally hosted large language…

↗ Open article
Trending Media Ars Technica Security

Attackers have been exploiting critical Zimbra flaw to steal emails

Vuln

Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned . The…

↗ Open article
Threat Intel Microsoft Security Blog

​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026

In the agentic era, the stakes are higher: AI agents now act with real access to your identities, your data, and your cloud, so every adoption decision is a trust decision. That is why security is a through line at…

↗ Open article
Trending News The Register Security

16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows

Research

A 16-year-old security researcher named Faav found an authentication flaw in Microsoft’s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials…

↗ Open article
News 404 Media

Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder Appeal

A lawyer used ChatGPT to generate briefs that included completely made-up witnesses and testimony while representing a man accused of shooting his wife. When he was caught by the judges, the lawyer blamed it on his own…

↗ Open article
Trending News Cyber Security News

Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS

Cloudflare is building a certificate authority to make post-quantum website authentication practical without burdening TLS connections with oversized signatures. The company plans to issue conventional certificates…

↗ Open article
Trending News Cyber Security News

Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux

Vuln

Google released a Chrome Stable update fixing 32 security vulnerabilities across Windows, macOS, and Linux, including one critical and multiple high-severity flaws in V8, ANGLE, GPU, WebGPU, Bluetooth, Passwords, and UI…

↗ Open article
Trending News Cyber Security News

Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells

Vuln

Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy web shells, and move into victim networks. The activity has…

↗ Open article
Trending News The Hacker News

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Vuln Research

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack…

↗ Open article
Trending News The Hacker News

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Phishing

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and…

↗ Open article
News Cyber Security News

Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack

Phishing

Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations. The campaign replaces an obvious malicious attachment with a conversation…

↗ Open article
News 404 Media

USPS To Put Cameras in Trucks That Scan Roads for ‘Community Safety’

The United States Postal Service is running a pilot program to put cameras in its mail carrier trucks that continuously scan roads and signs, map roadways and sidewalks, and improve “community safety,” according to a…

↗ Open article
Trending News Cyber Security News

Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster

Phishing

Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic…

↗ Open article
News Cyber Security News

PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries

PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single obvious source. Instead, it spreads activity across thousands of…

↗ Open article
News 404 Media

Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds

Abusive, sexually explicit deepfakes have only become easier to make and more widespread in the last nine years. Since we first covered deepfakes when they appeared in 2017 , they’ve never been the stuff of dark web…

↗ Open article
Advisory Cisco Security Advisories

Cisco Advance Notification for Publication of October 7, 2026, Security Advisories

Vuln

On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products…

↗ Open article
Threat Intel Malwarebytes Labs

Hackers steal protective order and foster care records from Arizona courts

“Arizona’s court system was targeted by a cyber attack from criminal hackers or their bots.” This is how the Arizona Supreme Court announced that hackers had attacked the state’s court system and stolen the personal…

↗ Open article
Trending News The Hacker News

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Vuln

Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw…

↗ Open article
Trending Research Rapid7 Blog

Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

CVE-2026-76504 ↗ Vuln

Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score…

↗ Open article ↗ CVE feed
News Cyber Security News

Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches

Malware Breach

A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers…

↗ Open article
Trending News The Hacker News

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Malware

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed…

↗ Open article
News 404 Media

How the Feds Get Your Data

Privacy

Surveillance isn’t just about who is collecting the data. Surveillance is, of course, also about who that data ends up with. A great story from Jason today looks at that with Flock and other automatic license plate…

↗ Open article
News Cyber Security News

Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device…

↗ Open article
News 404 Media

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program

Privacy

The Trump administration is using an anti-drug trafficking grant program from the 1980s to force cities around the country to funnel their ongoing collection of automated license plate reader data into large federal…

↗ Open article
Research Rapid7 Blog

Higher education is under siege, and fragmented security is making it harder to respond

Research

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure…

↗ Open article
Trending News Cyber Security News

AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub

Research

AI coding agents exposed more than 13,000 internal screenshots from over 300 organizations by publishing them in publicly accessible GitHub repositories, according to “PixelLeak” research from Glow Labs. The material…

↗ Open article
News Bleeping Computer

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.