Latest news

  1. Vulnerabilities via Wordfence

    Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin

    On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The…

  2. AI Security via Wired

    New York Seizes a Dozen Celebrity Deepfake Websites

    In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200…

  3. AI Security via Dark Reading

    Anthropic CEO: Time to Shift From Improving to Controlling AI

    Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?

  4. AI Security via Schneier on Security

    Using AI for Weapons Development

    Last week, Anthropic released a long and detailed document describing current misuses of their Claude models.

  5. Vulnerabilities via Canadian Centre for Cyber Security

    Samsung mobile security advisory (AV26-919)

    Serial number: AV26-919 Date: September 14, 2026 As of September 8, 2026, Samsung published a security update to address vulnerabilities in the following product…

  6. via Infosecurity Magazine

    Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

    Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service

  7. Threat Intel via Hornetsecurity

    How Attackers Abuse Legitimate RMM Tools

    In September 2026, a Chase-themed campaign delivered more than 80,000 messages in a few hours. The email presented a secure account statement and directed recipients to…

  8. Breaches via Rapid7

    Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR

    The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and…

  9. Breaches via Hudson Rock

    HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

    HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation In September 2026, the cybersecurity community uncovered a massive, highly…

  10. AI Security via Simon Willison

    Quoting Laurie Voss

    The cost of writing code collapsed, and the cost of reviewing, fixing and operating it is following, and I'm assuming it gets there. What's left of making software is…

  11. via Malwarebytes Labs

    Google’s new search redirects make links harder to check before you click

    Google is changing how some links in its search results work. Instead of linking directly to the destination, Google has started routing some search result links through…

  12. Vulnerabilities via Infosecurity Magazine

    Human Attacker Hits Machine-Speed Exploitation of Marimo RCE

    A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds

  13. Vulnerabilities via Wordfence

    Wordfence Bug Bounty Program Monthly Report – May 2026

    In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working to improve the overall…

  14. AI Security via Sonar

    Your AI agent doesn't know your codebase's context or constraints, and that's costing you

    An AI coding agent working in your repository has never seen your architecture. It has not read your intended module boundaries, your team's conventions, the incident…

  15. AI Security via Sonar

    AGENTS.md is a workaround, not a solution

    AGENTS.md has won the fight to become the standard place to brief a coding agent, and deservedly so.

  16. AI Security via Sonar

    Sonar Supports OpenAI’s Call for Collective Action on Cyber Defense

    The window to strengthen cyber defense is narrowing, as advanced AI models compress the time between vulnerability disclosure and exploitation from months to minutes…

  17. Ransomware via Huntress

    How Attackers Abuse VSS, and How Huntress Detects It

    Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.

  18. Threat Intel via SOCRadar

    VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch

    VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built…

  19. via Infosecurity Magazine

    Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

    MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military

  20. Breaches via Check Point Research

    14th September – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US…