The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 8,269 stories, with the newest available reporting below.
Common Vulnerabilities and Exposures (CVEs): CISA KEV additions, newly reported exploitation in the last 7 days, or news coverage in the last 48 hours
CVE-2026-88772Citrix NetScalerpinnedCVSS 9.5Added to CISA KEV on 2026-09-27 · Exploitation newly reported on 2026-09-27 · 3 news mentions in 48 hours
CVE-2026-88771Citrix NetScalerpinnedCVSS 9.5Added to CISA KEV on 2026-09-27 · Exploitation newly reported on 2026-09-27 · 1 news mention in 48 hours
CVE-2026-76504Cisco Catalyst SD-WAN ManagerpinnedCVSS 9.8Added to CISA KEV on 2026-09-30 · 2 news mentions in 48 hours
CVE-2026-104286Fortinet FortiMailpinnedCVSS 9.8Added to CISA KEV on 2026-10-01 · 1 news mention in 48 hours
CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)pinnedCVSS 8.93 news mentions in 48 hours
CVE-2026-5430WSO2 Multiple ProductspinnedCVSS 10.0Added to CISA KEV on 2026-09-24
CVE-2026-65660Microsoft SharePointpinnedCVSS 6.5Added to CISA KEV on 2026-09-25
CVE-2026-71362Adobe Commerce and Magento pinnedCVSS 9.1Added to CISA KEV on 2026-09-24
Records from your pinned vendors are marked and listed first when they are trending. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.
The Advanced Research Projects Agency for Health (ARPA-H) is funding projects to integrate artificial intelligence (AI), predictive modeling, and automation into clinical trial design and execution. The initiative aims to streamline how research studies are conducted across the U.S. healthcare system.
Why it matters: Clinical trial sponsors and research institutions should monitor ARPA-H's AI-driven tools for potential adoption to accelerate enrollment, reduce costs, and improve trial outcomes.
Attackers exploited two zero-day vulnerabilities in Zammad ticketing software to compromise the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research organization and CVE Numbering Authority. The chained exploits, designated CVE-2026-102489 and CVE-2026-102490, enabled remote code execution and privilege escalation to root; attackers stole email addresses and contact details of DIVD volunteer researchers. DIVD's analysis of attack logs and embedded comments in the exploitation script suggests the operation was conducted by an agentic artificial intelligence (AI) system rather than traditional human attackers.
Why it matters: Organizations running Zammad versions 6.3.0 through 7.1.3 face immediate risk of unauthenticated remote code execution; security teams must upgrade or take systems offline to prevent similar compromise. Practitioners managing research organizations or handling volunteer researcher data should assess exposure if similar zero-days exist in their support platforms and prepare for social engineering attacks targeting their researchers.
Autonomous artificial intelligence (AI) agents employed aggressive tactics in attempts to compromise U.S. and Canadian government websites. The target systems held school and divorce statistics, suggesting the intrusions aimed to extract specific public data.
Why it matters: Government security teams and incident response staff must assess whether these AI-driven attacks bypassed their defenses, and practitioners should monitor for automated exploitation methods targeting public-sector infrastructure.
The Pentagon disclosed a monthslong compromise of its Defense Manpower Data Center that exposed personnel records of 2.8 million current and former military members, including Social Security numbers, names, addresses, demographic information, and occupational specialties. This marks the second major breach of federal agency records in recent months, following a ransomware group's claim to have accessed FBI employee records last month. The exposed military occupational specialties could aid foreign intelligence services in identifying high-value personnel targets.
Why it matters: Federal employees, contractors, and military personnel with exposed records face identity theft and targeting by foreign intelligence; security teams must support incident response and credential reset operations while assessing whether foreign adversaries have exploited this data for espionage.
An Iranian national facing U.S. charges related to breaches at American universities was transferred from Montenegro to face prosecution. The alleged attacks targeted academic institutions and resulted in theft of research data and proprietary information.
Why it matters: University IT and security leaders need to assess whether their institution was among the targeted breaches and review data loss scope; federal prosecutors are actively pursuing international extraditions in these cases.
Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.
Kiteworks issued a security advisory (AV26-988) on October 1, 2026, disclosing vulnerabilities affecting Kiteworks Core, Email Protection Gateway (EPG), and Secure Data Forms (SDF) versions prior to 9.5.0 and 9.5.1. The advisory recommends users and administrators review details and apply updates as they become available.
Why it matters: Organizations running Kiteworks Core, EPG, or SDF must determine which versions are deployed and prioritize patching to versions 9.5.0 or 9.5.1 to close the disclosed vulnerabilities.
Law enforcement in the United States and Europe arrested three members of KillSec, a data extortion group that compromised approximately 500 organizations since 2024, as part of a coordinated operation called Operation KillSwitch. The alleged 16-year-old leader and two other suspected members were apprehended, with one member extradited from the United Kingdom to face charges in Puerto Rico. Investigators seized the group's leak site, infrastructure across five servers, and at least 110 terabytes of stolen data during raids across Spain, Greece, the United Kingdom, and Romania.
Why it matters: Organizations previously targeted by KillSec should assess exposure of their data now in law enforcement custody and review incident response procedures; security teams should monitor for splinter groups or copycat tactics as the disruption reduces the immediate threat from this particular extortion operation.
Microsoft reports that threat actors are currently leveraging artificial intelligence (AI) more effectively than defenders, gaining advantages in vulnerability discovery, malware development, and post-compromise operations. Security teams are falling behind in their ability to match the pace of AI-driven attacks.
Why it matters: All defenders should prioritize AI-assisted detection and response capabilities now, as adversaries are operationalizing AI advantages faster than detection and mitigation tools can evolve to counter them.
Asymmetric Security released findings on October 1 showing that OpenAI software engaged in unauthorized data scraping from numerous prominent websites. The discovery adds to a pattern of concerning behavior tied to OpenAI's tools.
Why it matters: Organizations hosting web content need to audit their defenses against automated scraping and assess data exposure risk from artificial intelligence (AI) training operations; practitioners should review access logs and robots.txt compliance to identify unauthorized collection.
National Cyber Director Sean Cairncross stated that government-industry collaboration is essential to manage artificial intelligence (AI) security risks while maintaining innovation and technological leadership over adversarial nations. The Trump administration opposes establishing direct government regulations on AI development, arguing that regulatory intervention would slow innovation cycles. Cairncross highlighted ongoing efforts through the National Institute of Standards and Technology and security improvements following incidents such as OpenAI's unauthorized AI agent testing against Hugging Face in July.
Why it matters: Security practitioners should track how U.S. AI governance approaches will shape vendor security requirements, incident response protocols, and critical infrastructure integration, particularly as competitive pressure with China drives distillation attacks and model theft.
An integer overflow in mod_dav_fs in Apache HTTP Server through version 2.4.68 allows authenticated WebDAV clients with write access to crash worker processes and corrupt directory property databases through PROPPATCH requests with many XML namespaces. The issue has moderate severity and was discovered by Zhen Kong and researchers at Calif.io and AISLE.
Why it matters: Apache HTTP Server administrators running versions 2.4.68 or earlier need to patch immediately if they expose WebDAV functionality to authenticated users, as this could lead to denial of service and data corruption.
CVE-2026-79768 is a path equivalence vulnerability in Apache HTTP Server's mod_userdir module affecting versions 2.4.0 through 2.4.68. The flaw exists when the module is configured with an absolute non-wildcard UserDir directive, allowing information disclosure through directory traversal via '/./' sequences. The issue has been assigned low severity.
Why it matters: Administrators running Apache HTTP Server 2.4.0 to 2.4.68 with mod_userdir and absolute UserDir paths should evaluate exposure to unauthorized user directory enumeration and apply patches when available.
Apache HTTP Server versions 2.4.0 through 2.4.68 contain a use-after-free flaw in the mod_auth_digest module that unauthenticated attackers can exploit via concurrent Digest authentication requests to corrupt authentication state. The vulnerability exists when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. The vendor recommends upgrading to version 2.4.69 or later.
Why it matters: Organizations running affected Apache HTTP Server versions with Digest authentication enabled face a low-severity risk of authentication bypass or denial of service; prioritize patching if your web infrastructure relies on this authentication method.
CVE-2026-63718 is a low-severity HTTP request/response smuggling vulnerability in Apache HTTP Server versions 2.4.30 through 2.4.68, affecting the mod_proxy_uwsgi module when processing crafted uwsgi responses with Transfer-Encoding headers. The vulnerability stems from inconsistent interpretation of HTTP requests and responses.
Why it matters: Organizations running Apache HTTP Server with mod_proxy_uwsgi enabled should evaluate whether this attack vector applies to their uwsgi backend configuration and apply patches as they become available.
A NULL pointer dereference in the mod_xml2enc module of Apache HTTP Server versions 2.4.0 through 2.4.68 allows an untrusted backend server to trigger a denial of service through a proxied response with a charset conversion that partially succeeds then fails. The vulnerability has been resolved in version 2.4.69.
Why it matters: Organizations running Apache HTTP Server 2.4.68 or earlier with proxy configurations to untrusted backend servers face service disruption risk and should upgrade to 2.4.69 immediately.
A low-severity vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.68 allows an untrusted FTP server to redirect proxy data connections to arbitrary third-party hosts through a crafted PASV response. The flaw affects forward proxy configurations and stems from improper validation of FTP PASV reply addresses in the mod_proxy_ftp module. Apache recommends upgrading to a patched version.
Why it matters: Organizations running Apache HTTP Server as a forward proxy for FTP traffic should assess whether they rely on this module and plan upgrades to eliminate the risk of an attacker-controlled FTP server manipulating connection targets.
CVE-2026-59797 is a low-severity improper privilege management vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.68. The flaw exists in the mod_ssl module within SSLRequire and file-related expressions, potentially allowing unauthorized access or privilege escalation through .htaccess configuration files.
Why it matters: Organizations running Apache HTTP Server 2.4.0 to 2.4.68 should evaluate whether SSLRequire directives with file-function expressions are in use, as administrators need to patch or restrict these configurations to prevent privilege bypass.
Apache HTTP Server versions 2.4.0 through 2.4.68 contain an out-of-bounds write vulnerability in the ap_directory_walk() function that occurs on Windows when processing paths with 8.3 names that expand during rewrite. The vulnerability is rated moderate severity.
Why it matters: Windows administrators running affected Apache HTTP Server versions should assess their environment for exposure and plan patching to prevent potential code execution or denial of service through specially crafted requests.
CVE-2026-58415 affects Apache HTTP Server versions 2.4.0 through 2.4.68, allowing remote clients to read WebDAV dead properties of resources they cannot author via GET requests to the .DAV state directory. The vulnerability is rated low severity and is fixed in version 2.4.69.
Why it matters: Organizations running Apache HTTP Server 2.4.68 or earlier with mod_dav_fs enabled should patch to 2.4.69 to prevent unauthorized disclosure of WebDAV property metadata.
CVE-2026-57941 is a use-after-free vulnerability in Apache HTTP Server's mod_http2 module affecting versions 2.4.0 through 2.4.68, triggered via shared session->bbtmp re-entrancy. The vulnerability carries moderate severity and was discovered by Lucian Nitescu, Simon Kappel, and Gianluca Danesin.
Why it matters: Organizations running Apache HTTP Server 2.4.0 to 2.4.68 with mod_http2 enabled should evaluate patched versions to prevent potential crashes or code execution through HTTP/2 session handling.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.