Skip to content
BLACKMESA.CA Security Feed

Security Feed

Cybersecurity news & advisories

500 articles 48 of 48 sources updated RSS ↗

Latest

Trending Research Rapid7 Blog

CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products

CVE-2026-21589 ↗ Vuln

Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira…

↗ Open article ↗ CVE feed
News Cyber Security News

Hackers Steal Rockstar Source Code, 78.6 Million Records and Playable GTA VI Build

Research

Rockstar Games has faced separate intrusions involving proprietary source code, 78.6 million business records, and what researchers describe as a playable GTA VI development build. The incidents span several years…

↗ Open article
News The Hacker News

The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually…

↗ Open article
Trending News The Hacker News

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate…

↗ Open article
Trending News The Hacker News

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Vuln

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw…

↗ Open article
News The Hacker News

What Is Agentic Pentesting? What It Proves, and Where It Stops

Vuln

If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a…

↗ Open article
Threat Intel Malwarebytes Labs

AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes

Phishing Research

In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the…

↗ Open article
Trending News The Register Security

FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks

The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday…

↗ Open article
News Cyber Security News

Anthropic Mythos AI Finds Rejetto HFS Flaw That Lets Attackers Forge Admin Sessions and Execute Code

Vuln

Anthropic’s Mythos AI has identified a critical vulnerability in Rejetto HTTP File Server that could allow remote attackers to forge administrator sessions and execute arbitrary code. The issue, tracked as…

↗ Open article
News Cyber Security News

Critical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands

CVE-2026-91140 ↗

Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious OpenAPI or Swagger documents to execute arbitrary OS commands . The…

↗ Open article ↗ CVE feed
Research Rapid7 Blog

The ASOS incident: When attackers use the channels customers trust

Breach

ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage…

↗ Open article
News Cyber Security News

OpenAI Sandbox Escape Flaw Allowed Free Access to Paid AI Models Without an API Key

Research

Security researcher Oliver Fish says he found an OpenAI sandbox escape that let him request paid AI models without an API key or an account. A screenshot shared online shows OpenAI awarding $300 for a report titled…

↗ Open article
Trending Threat Intel Malwarebytes Labs

Update Chrome and ChromeOS to fix critical security issues

Google has released updates for the Chrome browser and the ChromeOS operating system. On October 6, Google released a Stable Channel Update for Desktop . This is the most important one for desktop users. It brings…

↗ Open article
News Cyber Security News

Cybersecurity Awareness Month 2026 – Don’t Make It Easy for Them

Cybersecurity Awareness Month 2026 arrives as online attacks become easier to launch, harder to spot, and more focused on people. Observed every October, the campaign helps individuals and businesses build safer digital…

↗ Open article
Threat Intel Malwarebytes Labs

Another ShinyHunters suspect arrested

The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member. On Saturday, Reuters said that 16 year-old Saif al-Din Khader had been arrested in Jordan and was in FBI…

↗ Open article
Threat Intel Cisco Talos

One breach, please, and make no mistakes

Breach

For some time now, the cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure (to name a few, Hugging Face , DSEWiki , and RubyGems ). Of course, frontier…

↗ Open article
News Cyber Security News

Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes

Malware

Hackers are impersonating ChatGPT, Claude and Gemini with fake advertising products that steal passwords and multifactor authentication codes. Instead of delivering a conventional malware download, the campaign uses…

↗ Open article
Trending News Cyber Security News

Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks

Vuln

WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting , SQL injection, information disclosure, and other security weaknesses. The project recommends immediate…

↗ Open article
News Cyber Security News

Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks

Vuln

OpenSSH 10.6, released on October 6, 2026, fixes security flaws that could expose secrets, write files outside intended folders, or enable shell injection under specific conditions. The update covers both client and…

↗ Open article
News Cyber Security News

32 Unique 0-Days Exploited in Samsung S26, Pixel 10, OpenAI Codex and Other Devices in Pwn2Own 2026

Vuln Research

Security researchers reportedly exploited 32 unique zero-day vulnerabilities and earned $388,500 on the opening day of Pwn2Own Ireland 2026. Samsung Galaxy S26, OpenAI Codex , smart home devices and AI services fell to…

↗ Open article
Trending News Cyber Security News

Google Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution Flaws

Vuln

Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws , across Windows, Mac, and Linux. The patched versions are 155.0.8059.39/.40 for…

↗ Open article
Trending News The Hacker News

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company…

↗ Open article
Trending News The Hacker News

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

Malware Breach

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer…

↗ Open article
News The Register Security

South Korean president calls for creation of tools that stop all cyber-attacks

South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. “Recently, a series of personal information leak incidents have…

↗ Open article
News The Register Security

Anthropic reconfigures its cool kids security program

Only a week after warning about the perils of competitor Z.ai's GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it. "For…

↗ Open article
Trending News CyberScoop

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

Ransom

FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret…

↗ Open article
News CyberScoop

Wiretapping change sparks big privacy fight in the Golden State

Privacy

A bipartisan update to a California wiretapping law will eliminate the right to sue over internet-based surveillance, ending a key provision of a 57-year-old wiretapping law. Advocates say it is an overdue correction…

↗ Open article
News 404 Media

Her AI-Generated Video Swayed the Judge. The Court Said it Carried 'Undue Emotional Weight'

A man convicted of manslaughter in Arizona will be resentenced because an AI-generated video of his victim speaking from beyond the grave was ruled to have carried “undue emotional weight” as an impact statement. An…

↗ Open article
Trending Media Ars Technica Security

Hackers obtain counterfeit TLS certificates for Google and other large services

Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the…

↗ Open article
Trending News The Hacker News

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Phishing Research

Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI…

↗ Open article
Trending News The Hacker News

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors…

↗ Open article
News CyberScoop

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Former National Security Agency Director Paul Nakasone said a reported broad reorganization of the agency is “probably necessary” as it confronts faster-moving cyberthreats, artificial intelligence and competition with…

↗ Open article
News The Register Security

Trump Mobile customers' data dumped - and some never even received their gold device

Ransom

If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people…

↗ Open article
Trending Research watchTowr Labs

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)

CVE-2026-21589 ↗

Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching…

↗ Open article ↗ CVE feed
Threat Intel Microsoft Security Blog

CISO perspectives on managing vulnerability risks in the age of AI

Vuln

Most of what has been written about AI and vulnerability management focuses on speed: how much faster frontier AI models can scan code, find weaknesses, design patches, and build exploits than any human team. That part…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.