Latest news

  1. Vulnerabilities via CISA

    Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

    Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with…

  2. Vulnerabilities via CISA

    Siemens Teamcenter

    View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to…

  3. Threat Intel via NCSC UK

    Iranian cyber targeting of dissidents, activists and journalists

    Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.

  4. Threat Intel via NCSC UK

    UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

    UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.

  5. Threat Intel via Malwarebytes Labs

    HBO Max’s verified Reddit account hijacked to spread malware

    Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used…

  6. AI Security via Schneier on Security

    25 Years of Mass Surveillance Is Enough

    This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift…

  7. Vulnerabilities via Trail of Bits

    1Password's AI patching benchmark is misleading

    1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of…

  8. Threat Intel via Schneier on Security

    On the NSA’s Supercomputer from the 1960s

    Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.

  9. AI Security via GuidePoint Security

    The Next Evolution of Identity: Extending IAM Across People, Machines, and AI

    The Next Evolution of Identity: Extending IAM Across People, Machines and AI September 15, 2026 Elizabeth Strickland Contributions by: Randall Gamby, James Hauswirth and…

  10. AI Security via SOCRadar

    Agentic Ransomware: From Human-Operated to AI-Operated Attacks

    Agentic Ransomware: From Human-Operated to AI-Operated Attacks Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at…

  11. AI Security via Malwarebytes Labs

    Meta AI builds detailed profiles of children from years of family posts

    If you’re still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did…

  12. via Graham Cluley

    Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

    44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be…

  13. Threat Intel via Malwarebytes Labs

    Search results are sending people to fake Bitrefill checkouts

    Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and…

  14. Vulnerabilities via Infosecurity Magazine

    Microsoft Releases Emergency Patch to Fix RDS Vulnerability

    Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday

  15. Threat Intel via SOCRadar

    Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace

    Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace Your security team has already made the case for external threat intelligence. The…

  16. AI Security via The Register

    The latest AI doomsayer is China’s intelligence boss

    China’s minister for State Security has decided AI might be bad for the nation’s ruling Communist Party. Party secretary and minister Chen Yixin’s views appeared in…

  17. Threat Intel via SANS Internet Storm Center

    ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

  18. Threat Intel via JFrog Security Research

    ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell

    Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access.

  19. AI Security via JFrog Security Research

    New packages identified in GemStuffer 'OpenAI Swarm' malicious RubyGems campaign

    JFrog Security Research is actively monitoring the recent GemStuffer incident, and using our extensive Catalog of RubyGems artifacts, managed to identify **3,022…

  20. Threat Intel via Recorded Future

    Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group

    Executive Summary This report provides insights and analysis to better understand the role of third-party vendors and guarantee marketplaces from the perspective of…