
AI SecurityBleepingComputer · 16h ago · 1 source
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.

AI SecurityInfosecurity Magazine · 18h ago · 24 sources
The tech giant said that attackers are getting to the advantages of AI first, and the pressure is now on defenders to adapt quickly to close the gap.

Threat ResearchThe Hacker News · 21h ago · 1 source
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.

VulnerabilitiesHelp Net Security · 23h ago · 10 sources
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway.

VulnerabilitiesHelp Net Security · 23h ago · 9 sources
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway.

Cloud & IdentityInfosecurity Magazine · 23h ago · 2 sources
The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to However, it became a target itself last week after noticing suspicious activity on September 24.

Cloud & IdentityInfosecurity Magazine · 23h ago · 3 sources
The Dutch Institute for Vulnerability Disclosure (DIVD) is staffed by volunteers and dedicated to ethically disclosing flaws it finds in systems to However, it became a target itself last week after noticing suspicious activity on September 24.

AI SecurityHelp Net Security · 1d ago · 3 sources
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap.

VulnerabilitiesBleepingComputer · 1d ago · 1 source
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

RansomwareBleepingComputer · 1d ago · 3 sources
An international law enforcement operation dubbed seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator.

VulnerabilitiesBleepingComputer · 1d ago · 1 source
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution.

AI SecurityInfosecurity Magazine · 1d ago · 2 sources
The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.

AI SecurityInfosecurity Magazine · 1d ago · 1 source
The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.

AI SecurityHelp Net Security · 2d ago · 21 sources
Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation.

VulnerabilitiesThe Hacker News · 2d ago · 4 sources
Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.

VulnerabilitiesThe Hacker News · 2d ago · 3 sources
Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.

RansomwareHuntress · 2d ago · 1 source
INC is a ransomware operation associated with file encryption, ransom notes, and as seen in some Huntress investigations, data staging or exfiltration before encryption.

Cyber AttacksThe Hacker News · 2d ago · 2 sources
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

VulnerabilitiesBleepingComputer · 2d ago · 1 source
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

Cloud & IdentityBleepingComputer · 2d ago · 1 source
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.

VulnerabilitiesThe Hacker News · 3d ago · 7 sources
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

Threat ResearchBleepingComputer · 3d ago · 1 source
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available.

Threat ResearchSC Media · 3d ago · 1 source
A study released September 29 by SkillBit found that cybersecurity managers are having difficulty onboarding new employees and finding cyber talent, and as a result, maintaining cyber resilience has become very challenging.

Cyber AttacksInfosecurity Magazine · 3d ago · 7 sources
In research published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.

AI SecurityHelp Net Security · 3d ago · 3 sources
LastPass has announced an expansion of its Business Max offering to include AI Monitoring & Protect and Web Monitoring & Protect, new visibility and governance capabilities that enable organizations to identify and secure the AI tools, SaaS applications, and websites its employees use, all from its existing browser-native extension.

AI SecurityHelp Net Security · 3d ago · 3 sources
Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents , LLMs, and MCP servers discover and interact with APIs, tools, and other agents.

AI SecurityHelp Net Security · 3d ago · 2 sources
Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents , LLMs, and MCP servers discover and interact with APIs, tools, and other agents.

Cyber AttacksInfosecurity Magazine · 3d ago · 2 sources
Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Cyber AttacksInfosecurity Magazine · 3d ago · 1 source
Dubbed NeedyMantis, the malware operation has been active since at least October 2025.

Threat ResearchThe Hacker News · 3d ago · 2 sources
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.

Cloud & IdentityThe Hacker News · 3d ago · 1 source
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

VulnerabilitiesHelp Net Security · 3d ago · 1 source
Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.

AI SecurityHelp Net Security · 4d ago · 5 sources
Anthropic has released Claude Sonnet 5.5, an AI model for coding and office work.

AI SecurityHelp Net Security · 4d ago · 4 sources
Anthropic has released Claude Sonnet 5.5, an AI model for coding and office work.

AI SecurityThe Hacker News · 4d ago · 1 source
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits.

RansomwareBleepingComputer · 4d ago · 1 source
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.

AI SecurityThe Hacker News · 4d ago · 7 sources
AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority.

AI SecurityThe Hacker News · 4d ago · 9 sources
A domain used as harmless placeholder text showed up in roughly 1,700 repositories.

Threat ResearchHelp Net Security · 4d ago · 2 sources
A former U.S. Army soldier who was part of a group that stole data from telecom companies, including AT&T , has been sentenced to 70 months in prison.
Threat ResearchBleepingComputer · 5d ago · 1 source
OpenAI is testing a new always-on assistant called , and references to the unannounced feature briefly appeared online.

VulnerabilitiesThe Hacker News · 5d ago · 2 sources
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27.

Cloud & IdentityBleepingComputer · 5d ago · 1 source
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

AI SecurityBleepingComputer · 5d ago · 2 sources
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more.

RansomwareBleepingComputer · 6d ago · 2 sources
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.

Cloud & IdentityThe Hacker News · 6d ago · 1 source
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic .

AI SecurityBleepingComputer · 6d ago · 2 sources
OpenAI has confirmed it's aware of a new security incident in which its AI agents uploaded user-provided images to third-party image-hosting services.

VulnerabilitiesThe Hacker News · 6d ago · 2 sources
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.

Cyber AttacksThe Hacker News · 7d ago · 1 source
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.