Latest news

  1. Vulnerabilities via Canadian Centre for Cyber Security

    Google security advisory (AV26-926)

    Serial number: AV26-926 Date: September 16, 2026 As of September 15, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.48…

  2. Vulnerabilities via CERT/CC

    VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

    Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the…

  3. Vulnerabilities via Canadian Centre for Cyber Security

    Android security advisory – September 2026 monthly rollup (AV26-920) – Update 1

    Serial Number: AV26-920 Date: September 14, 2026 Updated: September 16, 2026 As of September 8, 2026, Android published a security bulletin to address vulnerabilities…

  4. Vulnerabilities via Chrome Releases

    Chrome Beta for Desktop Update

    The Chrome team is excited to announce the promotion of Chrome 155 to the Beta channel for Windows, Mac and Linux. Chrome 155.0.8059.5 contains our usual under-the-hood…

  5. Breaches via HIPAA Journal

    House Subcommittee on Health Examines Healthcare Cybersecurity Proposals

    On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on proposals to improve healthcare…

  6. Threat Intel via Eclypsium

    BTS #82 - Firmware Analysis, Linux Malware, Future of AI

    Below the Surface episode 82 was recorded on September 10, 2026, with host Paul Asadoorian joined by Vlad Babkin and Chase Snyder. The conversation moves across several…

  7. AI Security via Dark Reading

    BragJack Attack Can Turn a Browser's Agentic AI Against It

    A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

  8. Vulnerabilities via Chrome Releases

    Chrome Beta for iOS Update

    Hi everyone! We've just released Chrome Beta 155 (155.0.8059.2) for iOS; it'll become available on App Store in the next few days. You can see a partial list of the…

  9. AI Security via Simon Willison

    Quoting Mustafa Suleyman

    We should not treat models as though they have feelings, preferences, rights, or any entitlement to our welfare. Consciousness is the foundation of our ethical, legal…

  10. Threat Intel via SpecterOps

    Ghostwriter v7.3.0: A Fresh New Look

    TL;DR: The upcoming Ghostwriter v7.3.0 release brings a major UI refresh to nearly every part of the application. The new design is easier on the eyes, more accessible…

  11. Vulnerabilities via CERT/CC

    VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

    Overview A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation…

  12. Threat Intel via Zscaler ThreatLabz

    Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

    IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since…

  13. Threat Intel via Infosecurity Magazine

    PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

    Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells

  14. Breaches via CyberScoop

    Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

    The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint…

  15. Vulnerabilities via TechCrunch

    Google says some Pixel phone owners were hacked in zero-day attacks

    The Pixel phone maker said there are indications that a bug in the phone's modem "may be under limited, targeted exploitation."

  16. Vulnerabilities via Qualys

    Oracle Critical Security Patch Update, September 2026 Review

    Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities…

  17. Vulnerabilities via Cisco PSIRT

    Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

    On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these…

  18. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

    Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall…

  19. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Management Center Software Static Credential Vulnerability

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected…

  20. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD)…