Latest news

  1. Threat Intel via Malwarebytes Labs

    Search results are sending people to fake Bitrefill checkouts

    Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and…

  2. Vulnerabilities via Infosecurity Magazine

    Microsoft Releases Emergency Patch to Fix RDS Vulnerability

    Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday

  3. Threat Intel via SOCRadar

    Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace

    Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace Your security team has already made the case for external threat intelligence. The…

  4. AI Security via The Register

    The latest AI doomsayer is China’s intelligence boss

    China’s minister for State Security has decided AI might be bad for the nation’s ruling Communist Party. Party secretary and minister Chen Yixin’s views appeared in…

  5. Threat Intel via SANS Internet Storm Center

    ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

  6. Threat Intel via JFrog Security Research

    ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell

    Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access.

  7. AI Security via JFrog Security Research

    New packages identified in GemStuffer 'OpenAI Swarm' malicious RubyGems campaign

    JFrog Security Research is actively monitoring the recent GemStuffer incident, and using our extensive Catalog of RubyGems artifacts, managed to identify **3,022…

  8. Threat Intel via Recorded Future

    Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group

    Executive Summary This report provides insights and analysis to better understand the role of third-party vendors and guarantee marketplaces from the perspective of…

  9. Vulnerabilities via Debian Security

    DSA-6499-1 cjose - security update

    https://security-tracker.debian.org/tracker/DSA-6499-1

  10. Vulnerabilities via Dark Reading

    'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

    The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

  11. AI Security via Simon Willison

    The contagion of fear

    The contagion of fear Bryan Cantrill responds to the tweet by former Anthropic employee Jacob Coxon confirming that many Anthropic researchers believe AI "could kill us…

  12. AI Security via Simon Willison

    What blog posts influenced your thinking the most?

    My comment on What blog posts influenced your thinking the most? — Lobste.rs. An early Joel Spolsky one for me was The Law of Leaky Abstractions. I read that near the…

  13. Vulnerabilities via Dark Reading

    Maximum Severity GitLab Flaw Puts Supply Chains at Risk

    CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

  14. Vulnerabilities via Canadian Centre for Cyber Security

    Cisco security advisory (AV26-921)

    Serial Number: AV26-921 Date: September 14, 2026 As of September 14, 2026, Cisco is affected by vulnerabilities in the following products: Cisco AsyncOS for Cisco Secure…

  15. Threat Intel via Schneier on Security

    Upcoming Speaking Engagements

    This is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM…

  16. Vulnerabilities via Wordfence

    Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

    On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress…

  17. Vulnerabilities via SANS Internet Storm Center

    Apple Updates Everything, (Mon, Sep 14th)

    Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities…

  18. Vulnerabilities via NCSC-NL

    NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

    Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Email Gateway. De kwetsbaarheid bevindt zich in de verwerking van e-mailberichten binnen Cisco AsyncOS Software…

  19. via TechCrunch

    ClickFix attacks are tricking Mac and Windows users into hacking themselves

    If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.

  20. Vulnerabilities via Chrome Releases

    Chrome Dev for Android Update

    Hi everyone! We've just released Chrome Dev 155 (155.0.8056.0) for Android. It's now available on Google Play.