Skip to content
BLACKMESA.CA Security Feed

Cybersecurity news & advisories

47 / 47 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated
News The Register Security

OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

OpenAI has detailed the extent of the dirty deeds its agents indulged in Down Under in a Tuesday blog post titled How we will do better for Australia, which addresses last week’s news that one of its models improperly…

↗ Open article
Trending News CyberScoop

Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings

Vuln

Citrix took most of the weekend to confirm that attackers were actively exploiting the newest round of NetScaler zero-days, leaving network defenders and threat hunters to react without official confirmation. Yet…

↗ Open article
Trending Research SANS Internet Storm Center

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

CVE-2026-86950 ↗ Vuln

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being…

↗ Open article ↗ CVE feed
Trending News The Register Security

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Ransom

The cyber criminal behind JadePuffer, the first known agentic ransomware infection reported over the summer, has also used stolen Azure identities to conduct destructive attacks on cloud storage and other resources…

↗ Open article
Trending News The Hacker News

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

CVE-2026-86950 ↗ Vuln

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers…

↗ Open article ↗ CVE feed
News 404 Media

FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data

Breach

The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including…

↗ Open article
Trending Research GitHub Security Lab

How we found 24 Android vulnerabilities using our open source AI security agent

Vuln Research

With the rise of AI in the security space, our team created the GitHub Security Lab Taskflow Agent as a way for security researchers to easily automate, package, and share the AI prompts and workflows that they find…

↗ Open article
Trending News The Hacker News

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Malware Breach Research

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted…

↗ Open article
News CyberScoop

As AI world debates security, NVIDIA releases open source tools for agents

Amid growing concerns from both the public and policymakers about cyberattacks involving advanced AI systems, NVIDIA has released a new open software security platform for AI agents. The Open Agent Safety Platform…

↗ Open article
News The Hacker News

IAM for AI agents: A Practical Enterprise Framework

What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide…

↗ Open article
Trending News The Hacker News

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Vuln Crypto

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited…

↗ Open article
Trending News The Hacker News

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Malware

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April…

↗ Open article
News Cyber Security News

Florida AG Seeks Emergency Injunction to Restrict OpenAI and ChatGPT Over AI Safety Risks

Florida Attorney General James Uthmeier has asked a Highlands County judge to impose sweeping temporary restrictions on OpenAI, CEO Sam Altman, and affiliated companies while Florida’s ChatGPT lawsuit proceeds. Four…

↗ Open article
Trending News Cyber Security News

Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks

Malware Breach

Microsoft Threat Intelligence has uncovered NeedyMantis, a modular post-compromise malware framework designed to preserve covert access inside already-breached networks. The malware has appeared in a small number of…

↗ Open article
Trending News The Record

US, UK warn of exploited Citrix NetScaler zero-day bugs

Vuln

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming…

↗ Open article
News Krebs On Security

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Ransom

Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters . In the days immediately following the…

↗ Open article
Threat Intel Microsoft Security Blog

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Malware

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical…

↗ Open article
Trending News Cyber Security News

NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities

Vuln

The UK National Cyber Security Center (NCSC) has urged organizations to take immediate action against eight vulnerabilities affecting customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances. Two critical…

↗ Open article
News CyberScoop

ShinyHunters trades financial extortion for a reckless war of ego with the FBI

Ransom Breach Research

Threat hunters and researchers are alarmed by what they’ve seen in data ShinyHunters claims it stole from the FBI . Limited samples of the stolen data contain FBI agents’ personal contact information, details on family…

↗ Open article
Trending News Cyber Security News

New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS

A cross-platform side-channel attack that abuses file-notification services to monitor user activity on Linux, Windows and macOS. The technique turns inotify, ReadDirectoryChangesW, and FSEvents, which alert…

↗ Open article
News Cyber Security News

Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open

A criminal crew linked to Blackhatsect0r and DXQRTXX built an automated system designed to find weaknesses across the internet. Its exposed server revealed a credential vault, source code, chat logs, fraud notes, and a…

↗ Open article
News Cyber Security News

OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code on Developer Machines

Vuln

A critical attack path in OpenCode, an open-source AI coding agent, could let a malicious website execute commands on a developer’s computer. Tracked as GHSA-632h-h47v-g4x4, the remote code execution vulnerability…

↗ Open article
Trending News Cyber Security News

Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves

Vuln Breach Crypto

Cryptocurrency exchange Bitget has begun restoring withdrawals after attackers exploited its backend wallet infrastructure on September 24, stealing approximately $387.5 million from hot and warm wallets. The incident…

↗ Open article
Trending News The Hacker News

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Vuln

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into…

↗ Open article
News Bleeping Computer

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Malware

Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI…

↗ Open article
Threat Intel Check Point Research

28th September – Threat Intelligence Report

Breach Research

For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The FBI has confirmed unauthorized activity affecting FBIjobs.gov…

↗ Open article
Trending News Cyber Security News

ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Vuln

ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The campaign shows how a small change in an attack request can reopen…

↗ Open article
News 404 Media

The End of Privacy Is Here (with Kashmir Hill)

Privacy

Facial recognition is everywhere now. It’s in surveillance cameras; it’s soon going to be in Meta’s RayBan pervert glasses, and some students already did that. You now have massively viral accounts that take clips of…

↗ Open article
Trending News 404 Media

Humans Are Reading Copilot Prompts — And They're Horrified

This piece contains references to eating disorders. If you or someone you know needs help, support is available . Human contractors hired to improve Microsoft’s Copilot AI chatbot are constantly bombarded with lewd or…

↗ Open article
Trending News Cyber Security News

CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks

CVE-2026-65660 ↗ Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Microsoft SharePoint code injection vulnerability, tracked as CVE-2026-65660, to its KEV Catalog after evidence showed the flaw was being…

↗ Open article ↗ CVE feed
News Cyber Security News

Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers

Fake storefronts appeared days after the launch of Jev, an artificial intelligence model that returns decisions rather than written answers. The sites offer access to the service, but they put an unrelated operator…

↗ Open article
Threat Intel Malwarebytes Labs

OpenAI pauses work on top AI models after agent slips past internet controls

OpenAI’s latest containment failure adds to a pattern that may force the company to make an unpopular decision. The company has paused training, evaluation, and tool-enabled inference for its most capable models after…

↗ Open article
News The Register Security

Ex-soldier's telecom hacking spree earns him 70 months

A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies, stealing sensitive records, and trying to extort more than $1 million from his victims. Cameron John Wagenius, 22…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.