Latest news
-
Vulnerabilities via CISA
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with…
-
Vulnerabilities via CISA
Siemens Teamcenter
View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to…
-
Threat Intel via NCSC UK
Iranian cyber targeting of dissidents, activists and journalists
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
-
Threat Intel via NCSC UK
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
-
Threat Intel via Malwarebytes Labs
HBO Max’s verified Reddit account hijacked to spread malware
Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used…
-
AI Security via Schneier on Security
25 Years of Mass Surveillance Is Enough
This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift…
-
Vulnerabilities via Trail of Bits
1Password's AI patching benchmark is misleading
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of…
-
Threat Intel via Schneier on Security
On the NSA’s Supercomputer from the 1960s
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
-
AI Security via GuidePoint Security
The Next Evolution of Identity: Extending IAM Across People, Machines, and AI
The Next Evolution of Identity: Extending IAM Across People, Machines and AI September 15, 2026 Elizabeth Strickland Contributions by: Randall Gamby, James Hauswirth and…
-
AI Security via SOCRadar
Agentic Ransomware: From Human-Operated to AI-Operated Attacks
Agentic Ransomware: From Human-Operated to AI-Operated Attacks Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at…
-
AI Security via Malwarebytes Labs
Meta AI builds detailed profiles of children from years of family posts
If you’re still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did…
-
via Graham Cluley
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be…
-
Threat Intel via Malwarebytes Labs
Search results are sending people to fake Bitrefill checkouts
Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and…
-
Vulnerabilities via Infosecurity Magazine
Microsoft Releases Emergency Patch to Fix RDS Vulnerability
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday
-
Threat Intel via SOCRadar
Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace
Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace Your security team has already made the case for external threat intelligence. The…
-
AI Security via The Register
The latest AI doomsayer is China’s intelligence boss
China’s minister for State Security has decided AI might be bad for the nation’s ruling Communist Party. Party secretary and minister Chen Yixin’s views appeared in…
-
Threat Intel via SANS Internet Storm Center
ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
Threat Intel via JFrog Security Research
ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell
Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access.
-
AI Security via JFrog Security Research
New packages identified in GemStuffer 'OpenAI Swarm' malicious RubyGems campaign
JFrog Security Research is actively monitoring the recent GemStuffer incident, and using our extensive Catalog of RubyGems artifacts, managed to identify **3,022…
-
Threat Intel via Recorded Future
Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Executive Summary This report provides insights and analysis to better understand the role of third-party vendors and guarantee marketplaces from the perspective of…
