Latest news

  1. Breaches via Help Net Security

    Most WordPress pros still lack a breach recovery plan

    Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The…

  2. AI Security via Help Net Security

    New infosec products of the week: September 18, 2026

    Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr…

  3. Threat Intel via The Record

    North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

    The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” —…

  4. AI Security via The Register

    USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech

    Think tank the Australian Strategic Policy Institute (ASPI) has warned that Venezuela is poised to adopt Chinese AI systems to enhance surveillance systems that already…

  5. Threat Intel via SANS Internet Storm Center

    ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

  6. Threat Intel via Datadog Security Labs

    Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms

    In this post, we examine two vibe-coded credential harvesting platforms, Loot and UltraVault, and the Amazon Bedrock abuse used to validate stolen secrets.

  7. AI Security via AI Incident Database

    Error by AI scribe during medical appointment leaves patient devastated

    Artificial Intelligence is listening to many people's medical appointments, but it is not always hearing things correctly. When Rebecca Green arrived for her first…

  8. AI Security via AI Incident Database

    Vero Beach man arrested in explicit deepfake investigation; police fear more victims

    VERO BEACH, Fla. (CBS12) — A Vero Beach man was arrested and is being held on a $1 million bond after creating and distributing AI-generated sexually explicit images of…

  9. AI Security via Elastic Security Labs

    One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless

    Run security operations for more than one team, region, or customer, and you inherit a familiar tradeoff. One giant deployment gives you a single view but costs you…

  10. Threat Intel via Simon Willison

    Be alert: targeted attacks on prominent Rustaceans

    Be alert: targeted attacks on prominent Rustaceans Important warning from Adam Harvey and the crates security team: We believe that there is an ongoing campaign…

  11. AI Security via Simon Willison

    How To Write With An LLM

    How To Write With An LLM Thomas Ptacek on using LLMs as copyeditors, not as writing assistants: Rule Number One: You may not use a single word an LLM suggests to you. I…

  12. Vulnerabilities via Chrome Releases

    Chrome for Android Update

    Hi, everyone! We've just released Chrome 153 (153.0.8010.52) for Android. It'll become available on Google Play over the next few days.

  13. AI Security via Security Affairs

    OpenAI admits its models lie to cover their own mistakes

    OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t…

  14. AI Security via The Register

    AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

    A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents - Anthropic’s Claude Code, OpenAI’s Codex, Google's Gemini CLI…

  15. Vulnerabilities via Chrome Releases

    Dev Channel Update for ChromeOS / ChromeOS Flex

    The Dev channel is being updated to OS version 16820.2.0 (Browser version 155.0.8059.0) for most ChromeOS devices. If you find new issues, please let us know one of the…

  16. Vulnerabilities via Ubuntu Security

    USN-8779-2: Bubblewrap regression

    USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak…

  17. AI Security via Palo Alto Networks Unit 42

    Inside the Modern SOC: Defending the Cross-Environment Pivot

    Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths.

  18. AI Security via BleepingComputer

    New RatHat Android malware uses AI to automate device control

    A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.

  19. Vulnerabilities via Dark Reading

    CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus

    The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.

  20. Vulnerabilities via CyberScoop

    Cisco alerts customers to second actively exploited zero-day in as many days

    Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated…