Latest news
-
Vulnerabilities via Rapid7
CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco…
-
AI Security via TechCrunch
New Italian unicorn Exein rides the physical AI wave
Italian startup Exein has raised a $270 million round of funding led by Headline at a $1.7 billion valuation.
-
Vulnerabilities via CISA
Siemens Reyrolle 7SR5
View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to…
-
Vulnerabilities via CISA
mySCADA myPRO Manager
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages…
-
Vulnerabilities via CISA
Schneider Electric SCADAPack x70 Products
View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and…
-
Vulnerabilities via CISA
Siemens Mendix SAML
View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations…
-
Vulnerabilities via CISA
Wärtsilä FOS-Onboard
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to…
-
Vulnerabilities via CISA
Digital Watchdog VMAX DVR and NVR Product Lineups
View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded…
-
Vulnerabilities via CISA
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with…
-
Vulnerabilities via CISA
Siemens Teamcenter
View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to…
-
Threat Intel via NCSC UK
Iranian cyber targeting of dissidents, activists and journalists
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
-
Threat Intel via NCSC UK
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
-
Threat Intel via Malwarebytes Labs
HBO Max’s verified Reddit account hijacked to spread malware
Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used…
-
AI Security via Schneier on Security
25 Years of Mass Surveillance Is Enough
This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift…
-
Vulnerabilities via Trail of Bits
1Password's AI patching benchmark is misleading
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of…
-
Threat Intel via Schneier on Security
On the NSA’s Supercomputer from the 1960s
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
-
AI Security via GuidePoint Security
The Next Evolution of Identity: Extending IAM Across People, Machines, and AI
The Next Evolution of Identity: Extending IAM Across People, Machines and AI September 15, 2026 Elizabeth Strickland Contributions by: Randall Gamby, James Hauswirth and…
-
AI Security via SOCRadar
Agentic Ransomware: From Human-Operated to AI-Operated Attacks
Agentic Ransomware: From Human-Operated to AI-Operated Attacks Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at…
-
AI Security via Malwarebytes Labs
Meta AI builds detailed profiles of children from years of family posts
If you’re still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did…
-
via Graham Cluley
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be…
