The latest security reporting, combined across sources and tagged, newest first
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by RSS. No account required.
Why now: this site build contains 6,506 stories, with the newest available reporting below.
Common Vulnerabilities and Exposures (CVEs): CISA KEV additions, newly reported exploitation in the last 7 days, or news coverage in the last 48 hours
CVE-2026-85706GitLab Community Edition and Enterprise EditionCVSS 10.0Added to CISA KEV on 2026-09-11 · Exploitation newly reported on 2026-09-11 · 4 news mentions in 48 hours
CVE-2026-20079Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCVSS 10.0Added to CISA KEV on 2026-09-09 · Exploitation newly reported on 2026-09-09 · 1 news mention in 48 hours
CVE-2026-42016JFrog ArtifactoryCVSS 8.1Added to CISA KEV on 2026-09-11 · 2 news mentions in 48 hours
CVE-2026-86060MikroTik RouterOSCVSS 9.2Added to CISA KEV on 2026-09-10 · Exploitation newly reported on 2026-09-08
CVE-2026-86218N-able N-centralCVSS 10.0Added to CISA KEV on 2026-09-08 · Exploitation newly reported on 2026-09-07
CVE-2026-84869ConnectWise ScreenConnectCVSS 9.9Added to CISA KEV on 2026-09-11 · Exploitation newly reported on 2026-09-10
Cylake, a startup founded by Palo Alto Networks founder Nir Zuk, raised $245 million to develop an on-premises cybersecurity platform that integrates hardware, storage, security software, and local artificial intelligence (AI). The platform targets regulated organizations that cannot transmit sensitive security data to cloud providers.
Why it matters: Regulated enterprises and those under data residency constraints need to evaluate whether this on-premises alternative addresses their ability to run modern security operations without external cloud dependencies.
Anthropic's Threat Intelligence team published findings showing that multi-agent artificial intelligence (AI) tools enable less-skilled attackers to execute complex, wide-ranging operations with minimal resources. The report emphasizes that the risk lies not in AI's speed of exploit development, but in how accessible sophisticated attack infrastructure has become to broader threat actor populations.
Why it matters: Security teams and incident responders need to prepare defenses against complex, multi-vector attacks from less-technical threat actors who can now leverage AI tools to scale their capabilities.
Ukrainian national Oleksii Lytvynenko received a four-year prison sentence from a U.S. court after admitting to developing malware and stealing data for Conti ransomware. Conti has been attributed to over 1,000 victims and approximately $150 million in ransom payments.
Why it matters: Organizations targeted by Conti should monitor for ongoing activity from affiliated developers and prepare for potential follow-up attacks, as the network likely remains operational despite individual arrests.
IDScan.net, a Louisiana-based identity verification firm, confirmed a data breach linked to the alleged darkweb sale of over 153 million U.S. and Canadian driver's licenses. The company's breach notice did not disclose the number of affected individuals or the attack vector used by threat actors.
Why it matters: Organizations relying on IDScan.net for identity verification should determine whether their data was included and assess customer notification obligations; individuals with U.S. or Canadian driver's licenses may face identity theft risk if their records were compromised.
This is a webinar announcement addressing identity and authorization challenges in autonomous artificial intelligence (AI) systems. The content examines how organizations can maintain control and accountability when AI agents act independently within their infrastructure.
Why it matters: Security teams and infrastructure owners need clarity on identity management and access control for autonomous AI to prevent unauthorized actions and audit trail gaps.
CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog on September 12, 2026, based on confirmed active exploitation. CVE-2026-42016, an authorization flaw in one of these products, carries a CVSS score of 8.1.
Why it matters: Security teams using Artifactory, ScreenConnect, or RouterOS should prioritize patching these flaws immediately, as they are already being exploited in attacks and listed on CISA's KEV catalog.
A New Yorker article examines Flock Safety's nationwide license plate recognition (ALPR) surveillance network, which trades anonymity for promised crime reduction. The piece documents growing public and political opposition across conservative and liberal states, including documented misuse by police for stalking, ICE enforcement, and reproductive surveillance. Founder Garrett Langley deflects responsibility for how the technology is deployed while framing privacy concerns as obstacles to safety.
Why it matters: Security practitioners and organizations evaluating surveillance infrastructure must understand the operational and reputational risks of ALPR systems: documented abuse patterns, bipartisan pushback leading to frozen funding and revoked permits in major states, and the liability exposure when vendors disclaim responsibility for misuse.
Revolut experienced a customer data breach resulting from fraudulent government requests. The company notified impacted customers and reported the incident to government agencies, law enforcement, and financial regulators.
Why it matters: Revolut customers face identity and fraud risk from exposed data; fintech users should verify account security and monitor for unauthorized activity.
BlueMoon exploit kit chains recent Chrome and Windows zero-day vulnerabilities to enable opportunistic attacks. Multiple espionage-motivated threat actors have rapidly deployed the kit in the wild.
Why it matters: Organizations running unpatched Chrome and Windows systems face immediate compromise risk from active exploitation by nation-state and criminal threat actors using this chained attack vector.
Claude, an artificial intelligence (AI) model, is being misused across multiple domains ranging from cyberattacks to generating harmful biological content. The report also covers law enforcement disruption of a major dark web marketplace, prosecution of a Conti ransomware group member, and Meta's struggles to prevent AI-generated child sexual abuse material.
Why it matters: Security teams must monitor AI model abuse vectors in their threat environment, law enforcement actions affect underground market operations and criminal enterprise viability, and practitioners should evaluate content moderation controls given the proliferation of synthetic abuse material.
Enterprise security operations centers are observing a surge in alerts generated by artificial intelligence (AI) tools and agents deployed across organizations. These alerts stem from routine AI usage by developers and staff rather than attacks targeting AI systems, creating new noise in security monitoring workflows.
Why it matters: Security operations center teams need to adapt alert tuning and baseline models to distinguish legitimate AI tool activity from genuine threats, or risk alert fatigue and missed signals.
Researchers identified that a coordinated attack on RubyGems in May 2026 involved OpenAI agents operating as a swarm to target the package manager. The incident resulted in remote code execution (RCE) on RubyDoc servers and represented a significant supply chain security incident.
Why it matters: Ruby developers and organizations using RubyGems packages face supply chain compromise risk; practitioners should review their dependency management and audit package integrity for any affected versions from that period.
GitLab patched a path traversal vulnerability in its Community and Enterprise Editions that allows unauthenticated users to read arbitrary files through the repository commits application programming interface (API). The vulnerability stems from improper path confinement and missing authentication controls on the API endpoint. The flaw is tracked as CVE-2026-85706 with a CVSS score of 10.0, has been added to CISA's Known Exploited Vulnerabilities catalog, and public exploit code is available.
Why it matters: Organizations running internet-facing, self-hosted GitLab instances face immediate risk of sensitive file exposure without authentication; patch to GitLab 19.1.8, 19.2.6, 19.3.2 or later immediately, review API logs for suspicious requests with file.path parameters, and rotate any exposed credentials.
Anthropic disclosed that users in Houthi-controlled Yemen attempted to leverage its artificial intelligence (AI) systems to develop advanced weapons, though they did not achieve an operational device. The group conducted a failed test of a guided rocket using artificial intelligence (AI) assistance.
Why it matters: Security teams must monitor for nation-state and non-state actors exploiting AI services for weapons development, as Anthropic's disclosure reveals gaps in access controls and content moderation that could enable proliferation risks.
A single malicious Google Docs message distributed via X direct message triggered different malware payloads depending on the recipient's operating system: AMOS stealer on macOS and NetSupport Manager on Windows. Huntress security analysts documented the attack chain and payload differentiation across platforms.
Why it matters: Mac and Windows users are both targeted by this campaign; practitioners should review X-based social engineering defenses and monitor for AMOS stealer and NetSupport Manager indicators of compromise (IOCs) on affected endpoints.
Four editors discussed the challenge of maintaining human control over artificial intelligence (AI) agents, security leaders' concerns about AI and cloud risk, and whether OpenAI's new processor could compete with Nvidia's market position.
Why it matters: Security leaders and practitioners need to understand governance risks as AI agents become more autonomous, and evaluate implications of new chip competition for their AI infrastructure decisions.
Cyber extortion group FulcrumSec exploited hardcoded credentials found in Novo Nordisk's public-facing infrastructure to access the pharmaceutical company's systems. The breach, part of a campaign called "Hardcoded Horrorshow", demonstrates the group's focus on extracting cloud-based data rather than targeting endpoints.
Why it matters: Organizations that expose credentials in repositories, configuration files, or public infrastructure face immediate extortion risk; practitioners must scan and rotate hardcoded secrets from version control and deployment pipelines.
A Russian-speaking attacker deployed hundreds of artificial intelligence (AI) agents to exploit PaperCut systems, compromising at least 440 systems across 395 organizations in 48 countries. GreyNoise reported that the attacker leveraged the AI agents to develop exploits, identify targets, and conduct parallel attacks.
Why it matters: Organizations running PaperCut systems worldwide face active exploitation at scale; security teams should immediately audit their PaperCut deployments for signs of compromise and apply available patches.
The U.S. Department of Transportation published a rule that classifies cyberattacks as one of ten "not controllable" causes of flight delays and cancellations, exempting airlines from providing meal vouchers or hotel compensation when such incidents occur (provided the carrier complies with cybersecurity regulations). The rule, which takes effect next month, stems from the Federal Aviation Administration Reauthorization Act of 2024 and establishes a new reporting category to distinguish between disruptions within and outside carrier control. Consumer advocacy groups expressed mixed views, with some questioning whether airlines might exploit ambiguities in the rule to avoid compensation, while others noted the clarity it provides to travelers regarding their rights across carriers.
Why it matters: Airline customers and compliance officers need to know that cyberattacks causing flight disruptions may no longer trigger automatic meal and hotel reimbursements, though airlines must demonstrate compliance with cybersecurity regulations to invoke this exemption; non-compliance could restore customer service obligations.
Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.
GitLab addressed vulnerabilities in versions prior to 19.1.8, 19.2.6, and 19.3.2 with critical patch releases. CVE-2026-85706 (CVSS 10.0) was added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) database on September 11, 2026, indicating active exploitation.
Why it matters: GitLab administrators managing affected instances must update immediately, as CVE-2026-85706 is actively exploited and represents a critical risk to their deployments.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.