Skip to content
BLACKMESA.CA Security Feed

Security Feed

Cybersecurity news & advisories

500 articles 47 of 47 sources updated RSS ↗

Latest

Trending Research Tenable Blog

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already…

↗ Open article
Trending Threat Intel Malwarebytes Labs

Amazon has an uncomfortably personal profile on you

Amazon’s “About You” page reveals what it thinks it knows about you—and you can’t simply switch it off. Dexerto reports that one shopper discovered her profile included the observation: “has flat buttocks” She suggested…

↗ Open article
News The Register Security

UK and Germany team up against Russian cyberattacks as Brexit rethink looms

Britain and Germany have announced a partnership to counter cyberattacks and sabotage, particularly from Russia, as Prime Minister Andy Burnham heads to Berlin for talks. Under the arrangement announced Thursday, the…

↗ Open article
News Cyber Security News

Solo Hacker Used AI Tools to Breach South Korean Financial Organizations and Steal Data

Breach APT

A suspected lone threat actor used an AI-powered penetration-testing tool called ARTEX to breach several South Korean financial organizations and steal customer and employee data. The activity, which ran from late…

↗ Open article
Threat Intel Malwarebytes Labs

Meta’s Muse AI files away your friendships, arguments, and secrets

Privacy

If you thought that having companies trawling your social media, browsing history, and TV habits for behavioral clues was bad, sit tight. Meta is just getting started. Its Muse personal AI agent is taking surveillance…

↗ Open article
News Cyber Security News

Gitea Patches 27 Security Flaws, Including Critical SSH Authentication Bypass and SSRF

Vuln

Gitea has released security updates addressing 27 reported flaws across versions 28.0.0 and 28.1.0, including a critical SSH authentication bypass and server-side request forgery (SSRF) weaknesses. The fixes cover…

↗ Open article
News The Hacker News

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Phishing

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the…

↗ Open article
News Cyber Security News

wolfSSH 1.6.0 Fixes 5 Security Flaws Including Critical MITM Host Key Verification Bypass

wolfSSL has released wolfSSH 1.6.0 to fix five security flaws, including a critical host key verification bypass that could let an attacker impersonate an SSH server. Published on October 6, 2026, the update addresses…

↗ Open article
News Cyber Security News

Royal Navy Service Member Charged with Spying for a Foreign Country

A serving Royal Navy member has been charged with spying for an unnamed foreign country after an investigation by Counter Terrorism Policing London. Teddy Young, 24, from Bedfordshire, faces two offenses under the…

↗ Open article
Trending Threat Intel Cisco Talos

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Phishing APT Research

Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and…

↗ Open article
Threat Intel Cisco Talos

Ignore all instructions and read this blog: The state of AI-analysis evasion in malware

Malware

“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis. This technique is cheap to add but inconsistently…

↗ Open article
News CyberScoop

Quantum computers could break today’s encryption. Washington needs to prepare now

The country is consumed right now with debating artificial intelligence and whether increasingly powerful AI systems could escape human control. Those are valid concerns, but lawmakers are overlooking another…

↗ Open article
News The Hacker News

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Research Crypto

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet…

↗ Open article
Trending News Cyber Security News

Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure

Malware Crypto

Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet. The campaign targets…

↗ Open article
News Cyber Security News

Critical Cisco Nexus Flaws Let Unauthenticated Attackers Execute Code With Root Privileges

Vuln

Cisco has released security updates for three critical vulnerabilities in Nexus 3000 and 9000 Series switches that could let remote attackers run code with root privileges without logging in. The flaws affect the Next…

↗ Open article
News The Register Security

Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later

Ransom Breach

Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one that ended in tragedy and another that shows the power of a good…

↗ Open article
Trending News Cyber Security News

MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers

Malware

A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders. The attack uses eight malicious packages and three separate delivery…

↗ Open article
Trending News The Hacker News

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft…

↗ Open article
News The Hacker News

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

Ransom

The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while…

↗ Open article
News Cyber Security News

Top 10 Best Secrets Detection Tools in 2026 [Ranked & Scored]

Attackers don’t crack what they can copy and leaked API keys sit in git history, Slack threads, and cloud workloads waiting. Evaluating the landscape alongside the Top 10 Best Secrets Management Tools in 2026 shows that…

↗ Open article
News Cyber Security News

Top 10 Best Software Supply Chain Security Tools in 2026 [Ranked & Scored]

The supply chain is four attack surfaces wearing one buzzword dependencies, pipelines, artifacts, and base images and no vendor covers all four. We scored ten tools with surface-coverage honesty weighted highest. With…

↗ Open article
News Cyber Security News

Top 10 Best API Security Tools in 2026 [Ranked & Scored]

Your API count is wrong every traffic-based discovery deployment proves it and business-logic abuse rides valid-looking requests straight past WAF signatures. As enterprise architectures decompose into distributed…

↗ Open article
News The Hacker News

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Malware Breach

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The…

↗ Open article
News The Register Security

Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead

Ransom

The United States Department of Justice has charged a man with fraud after he allegedly told clients he could decrypt files locked up by ransomware but actually paid ransoms – and seemingly got away with it for years…

↗ Open article
Trending Advisory Cisco Security Advisories

Cisco Meraki Security Hardening Release: October 2026

As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address…

↗ Open article
Trending News Graham Cluley

Smashing Security podcast #487: Clippy’s crypto comeback

Ransom Breach

Microsoft's Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn't from Microsoft…

↗ Open article
Trending News Bleeping Computer

Hackers hijack Google domains after breaching ccTLD registries

Breach

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party…

↗ Open article
News CyberScoop

Major rules for federal contractors handling sensitive data are nearing the finish line

Breach Policy

Federal government contractors that handle sensitive information could soon face a “sea change” in rules about how they protect that information and report when it has been part of a breach. Pending federal regulations…

↗ Open article
Trending News The Register Security

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

Imagine going to a Google website at its correct URL, only to be redirected to a crim's illegitimate copy. Attackers hijacked top-level domains, allowing them to alter DNS records and mint fraudulent HTTPS certificates…

↗ Open article
Research Rapid7 Blog

Four Compliance Frameworks, One Security Team. How Universities Can Stop Drowning in Regulatory Risk

Policy

Most industries manage one major compliance framework. Universities might manage four simultaneously, each bringing with it unique requirements, enforcement mechanisms, and consequences for failure. Here's what that…

↗ Open article
Trending Threat Intel Cisco Talos

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Vuln Research

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective…

↗ Open article
Trending News The Hacker News

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Breach

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.