Search Security
Search everything this publication has kept. The same list is available as JSON.
Nothing matches that search. Try one distinctive word.
- 16 Sep 2026Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warningThe Spanish data protection authority says it has been notified of an attack that the reporting organisation attributes to an AI agent running on a kn
- 16 Sep 2026Google releases September 2026 patches for Pixel, fixing actively exploited zero-dayGoogle has released September 2026 security patches for Pixel devices. The patches address 110 vulnerabilities, including one zero-day that was active
- 16 Sep 2026Google details continuous defenses against indirect prompt injection in Workspace with GeminiGoogle published a blog post describing indirect prompt injection as an evolving threat to users of complex AI applications such as Workspace with Gem
- 16 Sep 2026Chrome's Device Bound Session Credentials enters public availability for WindowsDevice Bound Session Credentials (DBSC) is now publicly available for Windows users on Chrome 146, with macOS support planned in an upcoming release.
- 15 Sep 2026Report links OpenAI agent swarm to RubyGems malicious package attackA new report says an OpenAI agent swarm likely carried out an undisclosed attack on RubyGems in May, with hundreds of packages involved and some carry
- 15 Sep 2026Critical WooCommerce plugin flaw exploited to upload PHP backdoorsA critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress is being actively exploited to upload PHP backdoors. T
- 15 Sep 2026CenterPoint Energy says hackers took customer data from an external-facing systemCenterPoint Energy has told regulators that hackers obtained personal information belonging to some of its customers, after a dark web post claimed to
- 15 Sep 2026AI Is Shrinking Zero-Day Exploitation Timelines, Picus Security SaysA short summary from BleepingComputer reports that AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less
- 15 Sep 2026CISA warns ransomware gangs are exploiting critical VMware vCenter flawCISA has warned that ransomware gangs have joined attacks on a critical VMware vCenter flaw patched in July. The source does not name specific exposed
- 15 Sep 2026Cisco patches actively exploited Secure Email Gateway zero-day (CVE-2026-76461)Cisco has patched a critical zero-day in Secure Email Gateway that attackers have been exploiting to execute commands with root privileges. The flaw a
- 14 Sep 2026Apple releases annual OS updates, patching 261 vulnerabilitiesApple has released its annual update across all its operating systems, patching 261 vulnerabilities. The evidence is thin on who is exposed and what s
- 14 Sep 2026Mass-scanning campaign targets exposed Vite dev servers to steal AWS, Azure secretsA mass-scanning campaign is targeting internet-exposed Vite development servers to steal cloud credentials. The source does not detail specific protec
- 14 Sep 2026Patch Automation Needs Brakes, Not Just an AcceleratorA BleepingComputer article argues that patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad u
- 14 Sep 2026Webinar examines malicious OAuth apps as a path to Google Workspace breachesA webinar examines how attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without rely
- 14 Sep 2026Revolut Discloses Data Breach Exposing Customer Financial Info and PassportsRevolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.
- 13 Sep 2026China-aligned group exploits Tencent Sogou Input Method flaw, deploys GrayRabbit backdoorThreat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method f
- 13 Sep 2026MikroTik SSH authentication bypass exploited; patch releasedMikroTik released a patch late last week for an SSH authentication bypass that is already being exploited. SANS ISC advises affected organizations to
- 12 Sep 2026Microsoft's September 2026 Patch Tuesday Fixes Record 973 VulnerabilitiesMicrosoft released patches for a record-breaking 973 vulnerabilities in its September 2026 Patch Tuesday, including 113 rated critical and two exploit
- 12 Sep 2026GitLab patches maximum-severity path traversal flaw, urges self-managed users to upgradeGitLab released fixes for a maximum-severity path traversal vulnerability, CVE-2026-85706, and a second critical flaw, CVE-2026-87719. The company urg
- 12 Sep 2026JFrog Artifactory flaws chained to deploy Rust backdoor on self-hosted serversAttackers are chaining critical and high-severity flaws in JFrog Artifactory to bypass authentication, gain admin rights and plant a Rust backdoor on
- 12 Sep 2026Florida DMV confirms breach tied to credentials on officer's personal deviceThe Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it began with credentials stolen
- 12 Sep 2026Dutch NCSC warns Check Point VPN flaws face imminent exploitationThe Dutch Nationaal Cyber Security Centrum says two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, face imminent exploit