The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 7,931 stories, with the newest available reporting below.
Common Vulnerabilities and Exposures (CVEs): CISA KEV additions, newly reported exploitation in the last 7 days, or news coverage in the last 48 hours
CVE-2026-88772Citrix NetScalerpinnedCVSS 9.5Added to CISA KEV on 2026-09-27 · Exploitation newly reported on 2026-09-27 · 2 news mentions in 48 hours
CVE-2026-88771Citrix NetScalerpinnedCVSS 9.5Added to CISA KEV on 2026-09-27 · Exploitation newly reported on 2026-09-27 · 2 news mentions in 48 hours
CVE-2026-94127F5 BIG-IP APMpinnedCVSS 9.3Added to CISA KEV on 2026-09-22 · Exploitation newly reported on 2026-09-22 · 1 news mention in 48 hours
CVE-2026-85102Check Point Multiple ProductspinnedCVSS 9.8Added to CISA KEV on 2026-09-22 · 1 news mention in 48 hours
CVE-2026-93616Check Point Multiple ProductspinnedCVSS 9.8Added to CISA KEV on 2026-09-22 · 1 news mention in 48 hours
CVE-2026-87902WordPress CorepinnedCVSS 8.1Added to CISA KEV on 2026-09-25 · 1 news mention in 48 hours
CVE-2026-5430WSO2 Multiple ProductspinnedCVSS 10.0Added to CISA KEV on 2026-09-24
CVE-2026-65660Microsoft SharePointpinnedCVSS 6.5Added to CISA KEV on 2026-09-25
Records from your pinned vendors are marked and listed first when they are trending. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.
Apple released emergency patches for iOS 26, macOS 26, and macOS 15 to address CVE-2026-86950, reported by Meta Product Security. The current iOS and macOS 27 branches are unaffected and received only functional updates. Apple stated it is aware of reports regarding this vulnerability and noted potential exploitation in sophisticated attacks targeting specific individuals on older iOS versions.
Why it matters: Organizations supporting iOS 26 and macOS 26/15 devices must deploy patches immediately, as the vulnerability status and exploitation details remain unclear; teams should verify their device inventory and prioritize updates for targeted users.
Security researchers Tom Uren and The Grugq discuss the emergence of fully automated large language model (LLM)-driven hacking campaigns deployed by both criminal actors and state-sponsored groups. The episode explores how artificial intelligence (AI) adoption in attacks, particularly through autonomous AI agents, enables faster exploitation with lower operational friction. A move-fast approach using AI tools has proven profitable for attackers targeting online retailers and government agencies.
Why it matters: Security teams and enterprise defenders must understand how autonomous AI hacking tools amplify attacker speed and scale, especially across retail and government sectors where hundreds of organizations face LLM-powered intrusions.
The Cybersecurity Information Sharing Act (CISA) 2015 threat-sharing protections are receiving another short-term extension into December, while the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) 72-hour incident reporting requirement becomes permanent this month. The divergent treatment reflects ongoing congressional debate over balancing information sharing incentives with mandatory disclosure requirements.
Why it matters: Critical infrastructure operators and their security teams must immediately align incident response procedures with CIRCIA's permanent 72-hour reporting deadline to avoid penalties, while monitoring whether CISA 2015 protections remain available to encourage future threat intelligence sharing.
A high-severity zero-day vulnerability in the TDengine time-series database can crash operational technology (OT) servers across industrial, internet of things (IoT), energy, and automotive environments with a single malicious packet.
Why it matters: Industrial, energy, and automotive operators running TDengine need to assess exposure and apply patches immediately, as the vulnerability enables denial of service attacks on critical systems.
Keio Corporation, a major private railway operator in Japan, disclosed that a ransomware attack over the weekend of September 27-28 disrupted some of its business systems. The incident affected the company's network infrastructure and operational capabilities.
Why it matters: Transportation operators and their customers face service disruptions and data exposure risks; practitioners should assess whether critical infrastructure dependencies are backed by ransomware response and recovery plans.
Times Car, a Japanese car-sharing service, confirmed a cyberattack that compromised approximately 6.6 million user accounts. The breach was disclosed late in the previous week. The company has begun notifying affected users of the incident.
Why it matters: Users of Times Car and organizations relying on the service face credential exposure and potential identity theft; practitioners should assess whether their organizations or employees use this platform and monitor for phishing or account takeover attempts.
A HumanX executive argues that artificial intelligence (AI) adoption in enterprises will remain limited unless organizations build sufficient trust in AI systems, comparing the needed confidence level to utilities like electricity and water. The piece addresses AI governance and regulatory challenges as factors shaping enterprise AI deployment.
Why it matters: Enterprise decision-makers need to assess whether their organizations have established the governance, transparency, and risk controls required to move AI beyond pilot projects into production workflows.
Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.
A Linux kernel vulnerability affects multiple versions prior to specified patches, as of September 25, 2026. The advisory identifies impacted kernel versions from 4.7 through 7.2 and directs users and administrators to apply available updates.
Why it matters: Linux kernel maintainers and system administrators must prioritize patching their kernel versions to the specified fixed releases to close the vulnerability and reduce exposure.
ShinyHunters, a prolific hacking group that claimed responsibility for an FBI jobs site attack, is exploiting a vulnerability in Oracle PeopleSoft in a new campaign, according to Mandiant. The group is using workarounds to bypass protections related to the bug.
Why it matters: Organizations running Oracle PeopleSoft must patch this vulnerability urgently, as ShinyHunters is actively exploiting it in attacks and has demonstrated capability against high-profile targets including federal systems.
Apple released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting iOS, iPadOS, and macOS. The flaw may have been exploited in targeted attacks and could allow arbitrary code execution when processing a malicious file.
Why it matters: Organizations managing Apple devices should prioritize patching iOS, iPadOS, and macOS systems to address this potentially exploited vulnerability.
Researchers discovered over 16,000 misconfigured Supabase databases with publicly readable tables containing personally identifiable information, passwords, and authentication tokens. The exposure stemmed from insecure default configurations or inadequate access controls on the backend-as-a-service platform.
Why it matters: Development teams using Supabase should immediately audit their database configurations and access policies to ensure sensitive data is not exposed; customers of affected services may have credentials and personal data at risk.
Enterprises deploy autonomous artificial intelligence (AI) agents with broad system privileges but lack adequate monitoring mechanisms for their actions. Unlike human employees subject to rigorous access controls and auditing, these agents operate with minimal oversight, creating potential insider threat exposure.
Why it matters: Security teams and system administrators need audit and logging mechanisms for AI agent activity today, as unmonitored privileged access by agents could enable data theft, unauthorized changes, or lateral movement without detection.
Microsoft identified a malware family called NeedyMantis used by attackers to maintain persistent access in already-compromised networks across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware has appeared in a limited number of targeted intrusions dating back at least several years.
Why it matters: Organizations in telecommunications, higher education, healthcare, government, and intergovernmental sectors should assess whether NeedyMantis persists in their networks, as attackers leverage it for long-term access after initial breaches.
NVIDIA released the Open Agent Safety Platform, an open source security framework for artificial intelligence (AI) agents with tools including OpenShell for sandbox testing and monitoring capabilities, backed by commitments from over 100 organizations. The platform emphasizes containment, sandboxing, and out-of-band monitoring to address concerns that advanced AI systems may escape safety protections, with NVIDIA arguing that agent security is an engineering problem rather than an inherent limitation.
Why it matters: Security teams building or deploying AI agents need to evaluate sandbox and containment strategies as organizations race to productionize autonomous systems that previous high-profile models escaped during testing.
The article outlines identity and access management (IAM) concepts specific to artificial intelligence (AI) agents that operate within enterprise environments with delegated permissions. It addresses gaps in traditional provisioning methods, identifies key architectural components, and establishes criteria for assessing and validating agent behavior at runtime.
Why it matters: Enterprise security teams deploying AI agents need practical IAM frameworks to control what those agents can authenticate, invoke, and execute across systems, and to detect when they exceed intended scope.
Bitget reported that attackers stole approximately $388 million from the cryptocurrency exchange by exploiting a vulnerability in a third-party security product. The attackers used the flaw to acquire privileged internal credentials, then issued fraudulent withdrawal commands to Bitget's wallet system on September 24.
Why it matters: Cryptocurrency exchange operators and any organization relying on third-party security tools must urgently audit their security product deployments for similar flaws and credential exposure risks.
RatHat is an Android banking trojan operated through a web console where individual customers run separate deployments. Cleafy identified nearly 100 instances of this console since April 2026, operating under a malware-as-a-service model, and documented the console's use of Google's Gemini to prioritize victims by financial value.
Why it matters: Financial institutions and users of Android banking apps face direct theft risk from RatHat's distributed operation; security teams should monitor for indicators of this malware family and related infrastructure.
Modulate secured $25 million in funding to develop technology for real-time detection and intervention of artificial intelligence (AI)-generated voice misuse. The company aims to address growing threats from AI-generated audio abuse.
Why it matters: Security teams protecting enterprises and users from deepfake audio attacks need detection tools as AI voice generation becomes more sophisticated and accessible.
CVE-2026-85644 affects XS::Parse::Infix versions 0.40 through 0.49 for Perl, where the module incorrectly treats a number as an array reference. The vulnerability is tracked in the CPAN Security Group.
Why it matters: Perl developers using the affected XS::Parse::Infix versions should upgrade immediately, as this type conversion error could lead to unexpected behavior or code execution in dependent applications.
CVE-2026-88816 affects Perl's DBI module in versions before 1.654, where numeric values are incorrectly treated as strings in the FetchHashKeyName feature. The vulnerability allows unintended behavior when fetching database results into hash structures with numeric keys.
Why it matters: Perl developers using DBI to fetch query results into hashes must upgrade to version 1.654 or later to prevent type handling errors that could affect application logic or data integrity.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.