Latest news
-
AI Security via Dark Reading
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
-
via Ars Technica
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomena, said its infrastructure…
-
Vulnerabilities via The Register
CISA decides weekly vulnerability bulletin isn't necessary anymore
If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have bad news. It’s…
-
Breaches via CyberScoop
CISA promotes a fresh way to deter cyberattackers: Lie to them
For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems…
-
AI Security via Cloudflare
When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with…
-
Vulnerabilities via Canadian Centre for Cyber Security
ISC BIND security advisory (AV26-931)
Serial Number: AV26-931 Date: September 16, 2026 As of September 16, 2026, ISC is affected by vulnerabilities in the following product: ISC BIND 9 Prior to or equal to…
-
Vulnerabilities via Canadian Centre for Cyber Security
Apple security advisory (AV26-930)
Serial Number: AV26-930 Date: September 16, 2026 As of September 14, 2026, Apple is affected by vulnerabilities in the following products: iOS and iPadOS Prior to 27…
-
Vulnerabilities via Canadian Centre for Cyber Security
Oracle Corporation security advisory (AV26-929)
Serial number: AV26-929 Date: September 16, 2026 As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Helidon Oracle…
-
Breaches via SANS Internet Storm Center
Scans Targeting Hospitality Applications, (Wed, Sep 16th)
Earlier today, I noted an odd request showing up in our "First Seen" report: GET /PIAF-HMS/ HTTP/1.1 Host: [redacted] User-Agent: Farez-Sorter/1.0 Accept-Encoding: gzip…
-
Vulnerabilities via Canadian Centre for Cyber Security
HPE security advisory (AV26-928)
Serial number: AV26-928 Date: September 16, 2026 As of September 15, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE…
-
Vulnerabilities via Chrome Releases
Chrome Beta for Android Update
Hi everyone! We've just released Chrome Beta 155 (155.0.8059.4) for Android. It's now available on Google Play.
-
Threat Intel via Krebs on Security
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services…
-
AI Security via Simon Willison
Claude Cowork and chat are now one Claude
Claude Cowork and chat are now one Claude In hopefully good news for anyone who, like me, was increasingly confused at Cowork v.s. Claude v.s. Claude Code: Starting…
-
via Dark Reading
Fighting Your Dragons Through Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech…
-
Breaches via TechCrunch
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
The ShinyHunters gang leaked the files online after saying the Florida state agency did not pay their ransom demand.
-
Vulnerabilities via Canadian Centre for Cyber Security
[Control Systems] Phoenix Contact security advisory (AV26-927)
Serial number: AV26-927 Date: September 16, 2026 As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products: ICE2-8IOL-G65L-V1D…
-
Vulnerabilities via The Register
Google Pixel phones pwned in zero-click attacks
Both Google and Uncle Sam warned that attackers have exploited a zero-day improper authorization bug in Pixel phones' cellular modems that can bypass permission checks…
-
Vulnerabilities via Chrome Releases
Chrome for Android Update
Hello Everyone! We've just released Chrome 154 (154.0.8037.49) for Android to a small percentage of users. It'll become available on Google Play over the next few days.
-
Vulnerabilities via Canadian Centre for Cyber Security
Google security advisory (AV26-926)
Serial number: AV26-926 Date: September 16, 2026 As of September 15, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.48…
-
Vulnerabilities via CERT/CC
VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control
Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the…
