Latest news

  1. AI Security via Dark Reading

    AI Security Spending Jumps as Fear Outpaces Proof of Value

    CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?

  2. via Ars Technica

    Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack

    The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomena, said its infrastructure…

  3. Vulnerabilities via The Register

    CISA decides weekly vulnerability bulletin isn't necessary anymore

    If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have bad news. It’s…

  4. Breaches via CyberScoop

    CISA promotes a fresh way to deter cyberattackers: Lie to them

    For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems…

  5. AI Security via Cloudflare

    When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

    A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with…

  6. Vulnerabilities via Canadian Centre for Cyber Security

    ISC BIND security advisory (AV26-931)

    Serial Number: AV26-931 Date: September 16, 2026 As of September 16, 2026, ISC is affected by vulnerabilities in the following product: ISC BIND 9 Prior to or equal to…

  7. Vulnerabilities via Canadian Centre for Cyber Security

    Apple security advisory (AV26-930)

    Serial Number: AV26-930 Date: September 16, 2026 As of September 14, 2026, Apple is affected by vulnerabilities in the following products: iOS and iPadOS Prior to 27…

  8. Vulnerabilities via Canadian Centre for Cyber Security

    Oracle Corporation security advisory (AV26-929)

    Serial number: AV26-929 Date: September 16, 2026 As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Helidon Oracle…

  9. Breaches via SANS Internet Storm Center

    Scans Targeting Hospitality Applications, (Wed, Sep 16th)

    Earlier today, I noted an odd request showing up in our "First Seen" report: GET /PIAF-HMS/ HTTP/1.1 Host: [redacted] User-Agent: Farez-Sorter/1.0 Accept-Encoding: gzip…

  10. Vulnerabilities via Canadian Centre for Cyber Security

    HPE security advisory (AV26-928)

    Serial number: AV26-928 Date: September 16, 2026 As of September 15, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE…

  11. Vulnerabilities via Chrome Releases

    Chrome Beta for Android Update

    Hi everyone! We've just released Chrome Beta 155 (155.0.8059.4) for Android. It's now available on Google Play.

  12. Threat Intel via Krebs on Security

    Data Broker Radaris Loses Domains in Privacy Fight

    The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services…

  13. AI Security via Simon Willison

    Claude Cowork and chat are now one Claude

    Claude Cowork and chat are now one Claude In hopefully good news for anyone who, like me, was increasingly confused at Cowork v.s. Claude v.s. Claude Code: Starting…

  14. via Dark Reading

    Fighting Your Dragons Through Tough Tech Times

    Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech…

  15. Breaches via TechCrunch

    Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

    The ShinyHunters gang leaked the files online after saying the Florida state agency did not pay their ransom demand.

  16. Vulnerabilities via Canadian Centre for Cyber Security

    [Control Systems] Phoenix Contact security advisory (AV26-927)

    Serial number: AV26-927 Date: September 16, 2026 As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products: ICE2-8IOL-G65L-V1D…

  17. Vulnerabilities via The Register

    Google Pixel phones pwned in zero-click attacks

    Both Google and Uncle Sam warned that attackers have exploited a zero-day improper authorization bug in Pixel phones' cellular modems that can bypass permission checks…

  18. Vulnerabilities via Chrome Releases

    Chrome for Android Update

    Hello Everyone! We've just released Chrome 154 (154.0.8037.49) for Android to a small percentage of users. It'll become available on Google Play over the next few days.

  19. Vulnerabilities via Canadian Centre for Cyber Security

    Google security advisory (AV26-926)

    Serial number: AV26-926 Date: September 16, 2026 As of September 15, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.48…

  20. Vulnerabilities via CERT/CC

    VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

    Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the…