Research
The watch floor
Security signals ranked by what matters now, plus the latest reporting.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are clustered, de-duplicated, and tagged by category, vendor, and threat actor. Filter to your role, pin your stack, subscribe or point your reader at a feed. No account required.
Browse latest storiesSkip to latest storiesFilter by role (optional)View filtered stories
Trending, last 7 days
Most covered
Ranked by distinct source count; recency breaks ties.
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
- CISA Adds One Known Exploited Vulnerability to Catalog
- Iran-Linked Hackers Shut Down UK Power Plant for Four Days
- TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- Lawmakers seek watchdog review of federal hacking of Americans
Common Vulnerabilities and Exposures (CVEs) gaining attention
- CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)new CISA KEV
- CVE-2026-64849MLflow MLflownew CISA KEV
- CVE-2026-60004Gitea Giteanew CISA KEV
- CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-innew CISA KEV
- CVE-2026-72530TrueConf Servernew CISA KEV
- CVE-2026-72529TrueConf Servernew CISA KEV
Latest stories, newest first
Research
The State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities
Research
Insights into Suspected DPRK Workers: Red Flags to Look Out For
CISA confirms hackers targeted over 100 US water systems during July
ransomware
National Kidney Registry allegedly hacked by DireWolf ransomware group
cloud saas
Who Has Admin Rights in your Entra ID Directory?
Election official says Tina Peters would be consultant, won’t have access to election systems
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Iran-linked hackers expand infrastructure across Europe and Middle East, report says
AI Speeds Up Malware Development, Not Its Success Rate: Analysis
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
Boston Scientific says cyberattack disrupted operations globally
vulnerabilities
Hackers target Microsoft SharePoint RCE chain with PoC exploit
FBI disrupts proxy network enabling Chinese espionage operations
Snowflake ends service-account passwords. Now comes the hard part
Ubiquiti patches three max severity security vulnerabilities
Spyware for Babies
breaches incidents
A recommendation from the Saskatchewan Information and Privacy Commissioner caught our eye
vulnerabilitiesCVE-2023-34124CVE-2023-34132
Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
No stories match your current filters. Reset search and filters to show all stories.
See the daily change brief for what changed since the previous snapshot. Looking further back? Browse the daily archive, this feed's own history.