Skip to content

Cybersecurity news & advisories

47 / 47 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated 13 Sep 2026 02:10 UTC
News The Hacker News

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV)…

↗ Open article
News Cyber Security News

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

CVE-2026-56711 ↗ CVE-2026-73324 ↗ Vuln

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media…

↗ Open article ↗ CVE feed
Trending News Cyber Security News

Containing Machine Speed Cyber Attacks Inside AI Infrastructure

A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response teams time to detect, discuss, and respond. Even severe incidents…

↗ Open article
News Cyber Security News

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

Vuln Ransom Breach

A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May and early June 2026. The ShinyHunters hacking group exploited the…

↗ Open article
News The Hacker News

When the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks…

↗ Open article
News 404 Media

Mercury Is Shrinking Way Faster Than We Thought, Scientists Discover

Welcome back to the Abstract! Here are the studies this week that got dumped, went high, shrank in size, and got the blues. First, you’ve heard of getting a feather in your cap, but what about a feather in some crap?…

↗ Open article
News The Hacker News

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

Vuln Research

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12…

↗ Open article
Trending News Cyber Security News

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

CVE-2026-85706 ↗ Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706 , to its Known Exploited Vulnerabilities catalog, warning that attackers are actively…

↗ Open article ↗ CVE feed
News Cyber Security News

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

Vuln Research

A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and attempted to harvest…

↗ Open article
News CyberScoop

Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

Research

Researchers say they have discovered thousands of malicious software packages uploaded to an online public software repository that were left by a “swarm” of OpenAI agents. According to an incident timeline published…

↗ Open article
News CyberScoop

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

Beginning next month, if a flight is canceled or delayed because of a cyberattack, feds will give airlines clearance not to hand out meal vouchers or hotels. The change is the result of a broader rule the Transportation…

↗ Open article
Trending News CyberScoop

GitLab’s critical flaw is already drawing internet-wide probes

Vuln

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already…

↗ Open article
News Dark Reading

Why AI Is So Good at Scamming Humans

Research

Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.

↗ Open article
Media Schneier on Security

My Talk at DEF CON

Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI…

↗ Open article
News The Register Security

More JFrog Artifactory bugs under attack, and all 3 have patches

Vuln

JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor…

↗ Open article
News 404 Media

Behind the Blog: How to Talk About AI Doom

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss AI doomers, 9/11 posting, and Barbie. JOSEPH: I do always get…

↗ Open article
Trending News Bleeping Computer

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Ransom Phishing Breach

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from…

↗ Open article
News 404 Media

Automattic’s Matt Mullenweg Claims He’s Back 'In Control'

Less than 48 hours after announcing he was forcibly placed on a leave of absence by the Automattic board on Wednesday, Automattic’s Matt Mullenweg posted in a company-wide Slack channel claiming that he’s back “in…

↗ Open article
Trending News The Hacker News

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Vuln

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is…

↗ Open article
News The Hacker News

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax…

↗ Open article
Advisory Cisco Security Advisories

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.