Latest news

  1. AI Security via Simon Willison

    The contagion of fear

    The contagion of fear Bryan Cantrill responds to the tweet by former Anthropic employee Jacob Coxon confirming that many Anthropic researchers believe AI "could kill us…

  2. AI Security via Simon Willison

    What blog posts influenced your thinking the most?

    My comment on What blog posts influenced your thinking the most? — Lobste.rs. An early Joel Spolsky one for me was The Law of Leaky Abstractions. I read that near the…

  3. Vulnerabilities via Dark Reading

    Maximum Severity GitLab Flaw Puts Supply Chains at Risk

    CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

  4. Vulnerabilities via Canadian Centre for Cyber Security

    Cisco security advisory (AV26-921)

    Serial Number: AV26-921 Date: September 14, 2026 As of September 14, 2026, Cisco is affected by vulnerabilities in the following products: Cisco AsyncOS for Cisco Secure…

  5. Threat Intel via Schneier on Security

    Upcoming Speaking Engagements

    This is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM…

  6. Vulnerabilities via Wordfence

    Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

    On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress…

  7. Vulnerabilities via SANS Internet Storm Center

    Apple Updates Everything, (Mon, Sep 14th)

    Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities…

  8. Vulnerabilities via NCSC-NL

    NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

    Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Email Gateway. De kwetsbaarheid bevindt zich in de verwerking van e-mailberichten binnen Cisco AsyncOS Software…

  9. via TechCrunch

    ClickFix attacks are tricking Mac and Windows users into hacking themselves

    If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.

  10. Vulnerabilities via Chrome Releases

    Chrome Dev for Android Update

    Hi everyone! We've just released Chrome Dev 155 (155.0.8056.0) for Android. It's now available on Google Play.

  11. Vulnerabilities via Wordfence

    Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin

    On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The…

  12. AI Security via Wired

    New York Seizes a Dozen Celebrity Deepfake Websites

    In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200…

  13. AI Security via Dark Reading

    Anthropic CEO: Time to Shift From Improving to Controlling AI

    Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?

  14. AI Security via Schneier on Security

    Using AI for Weapons Development

    Last week, Anthropic released a long and detailed document describing current misuses of their Claude models.

  15. Vulnerabilities via Canadian Centre for Cyber Security

    Samsung mobile security advisory (AV26-919)

    Serial number: AV26-919 Date: September 14, 2026 As of September 8, 2026, Samsung published a security update to address vulnerabilities in the following product…

  16. via Infosecurity Magazine

    Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

    Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service

  17. Threat Intel via Hornetsecurity

    How Attackers Abuse Legitimate RMM Tools

    In September 2026, a Chase-themed campaign delivered more than 80,000 messages in a few hours. The email presented a secure account statement and directed recipients to…

  18. Breaches via Rapid7

    Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR

    The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and…

  19. Breaches via Hudson Rock

    HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

    HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation In September 2026, the cybersecurity community uncovered a massive, highly…

  20. AI Security via Simon Willison

    Quoting Laurie Voss

    The cost of writing code collapsed, and the cost of reviewing, fixing and operating it is following, and I'm assuming it gets there. What's left of making software is…