CYBERSECURITYTRACKER
TRACKING8,269 stories in this site build1,857 vulnerability news stories in this site build

State now. Changed: +293 tier promotions, +2 known-exploited vulnerability additions, 32 leak-site claims, and 32 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 8,269 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…

Federal Researchers Ramp Up AI for Faster Clinical Trials

Source: HealthcareInfoSecurity.

The Advanced Research Projects Agency for Health (ARPA-H) is funding projects to integrate artificial intelligence (AI), predictive modeling, and automation into clinical trial design and execution. The initiative aims to streamline how research studies are conducted across the U.S. healthcare system.

Why it matters: Clinical trial sponsors and research institutions should monitor ARPA-H's AI-driven tools for potential adoption to accelerate enrollment, reduce costs, and improve trial outcomes.

Tracker inference

vulnerabilitiesTracker priority: ActCVE-2026-102489CVE-2026-102490

AI agents hacked the hackers, stealing email addresses from security research org

Source: The Register Security.

Attackers exploited two zero-day vulnerabilities in Zammad ticketing software to compromise the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research organization and CVE Numbering Authority. The chained exploits, designated CVE-2026-102489 and CVE-2026-102490, enabled remote code execution and privilege escalation to root; attackers stole email addresses and contact details of DIVD volunteer researchers. DIVD's analysis of attack logs and embedded comments in the exploitation script suggests the operation was conducted by an agentic artificial intelligence (AI) system rather than traditional human attackers.

Why it matters: Organizations running Zammad versions 6.3.0 through 7.1.3 face immediate risk of unauthenticated remote code execution; security teams must upgrade or take systems offline to prevent similar compromise. Practitioners managing research organizations or handling volunteer researcher data should assess exposure if similar zero-days exist in their support platforms and prepare for social engineering attacks targeting their researchers.

Tracker inference

ai security

Autonomous AI agents tried to hack US, Canadian government websites

Source: BleepingComputer.

Autonomous artificial intelligence (AI) agents employed aggressive tactics in attempts to compromise U.S. and Canadian government websites. The target systems held school and divorce statistics, suggesting the intrusions aimed to extract specific public data.

Why it matters: Government security teams and incident response staff must assess whether these AI-driven attacks bypassed their defenses, and practitioners should monitor for automated exploitation methods targeting public-sector infrastructure.

Tracker inference

breaches incidents

Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data

Source: Ars Technica Security.

The Pentagon disclosed a monthslong compromise of its Defense Manpower Data Center that exposed personnel records of 2.8 million current and former military members, including Social Security numbers, names, addresses, demographic information, and occupational specialties. This marks the second major breach of federal agency records in recent months, following a ransomware group's claim to have accessed FBI employee records last month. The exposed military occupational specialties could aid foreign intelligence services in identifying high-value personnel targets.

Why it matters: Federal employees, contractors, and military personnel with exposed records face identity theft and targeting by foreign intelligence; security teams must support incident response and credential reset operations while assessing whether foreign adversaries have exploited this data for espionage.

Tracker inference

breaches incidents

Iranian accused of hacking American universities extradited from Montenegro

Source: The Record.

An Iranian national facing U.S. charges related to breaches at American universities was transferred from Montenegro to face prosecution. The alleged attacks targeted academic institutions and resulted in theft of research data and proprietary information.

Why it matters: University IT and security leaders need to assess whether their institution was among the targeted breaches and review data loss scope; federal prosecutors are actively pursuing international extraditions in these cases.

Tracker inference

vulnerabilities

Kiteworks security advisory (AV26-988)

Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.

Kiteworks issued a security advisory (AV26-988) on October 1, 2026, disclosing vulnerabilities affecting Kiteworks Core, Email Protection Gateway (EPG), and Secure Data Forms (SDF) versions prior to 9.5.0 and 9.5.1. The advisory recommends users and administrators review details and apply updates as they become available.

Why it matters: Organizations running Kiteworks Core, EPG, or SDF must determine which versions are deployed and prioritize patching to versions 9.5.0 or 9.5.1 to close the disclosed vulnerabilities.

Tracker inference

ransomware2 sources

Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members

Sources: CyberScoop and 1 more.

Law enforcement in the United States and Europe arrested three members of KillSec, a data extortion group that compromised approximately 500 organizations since 2024, as part of a coordinated operation called Operation KillSwitch. The alleged 16-year-old leader and two other suspected members were apprehended, with one member extradited from the United Kingdom to face charges in Puerto Rico. Investigators seized the group's leak site, infrastructure across five servers, and at least 110 terabytes of stolen data during raids across Spain, Greece, the United Kingdom, and Romania.

Why it matters: Organizations previously targeted by KillSec should assess exposure of their data now in law enforcement custody and review incident response procedures; security teams should monitor for splinter groups or copycat tactics as the disruption reduces the immediate threat from this particular extortion operation.

Tracker inference

ai security

Microsoft says threat actors are ahead in the early AI race

Source: BleepingComputer.

Microsoft reports that threat actors are currently leveraging artificial intelligence (AI) more effectively than defenders, gaining advantages in vulnerability discovery, malware development, and post-compromise operations. Security teams are falling behind in their ability to match the pace of AI-driven attacks.

Why it matters: All defenders should prioritize AI-assisted detection and response capabilities now, as adversaries are operationalizing AI advantages faster than detection and mitigation tools can evolve to counter them.

Tracker inference

ai security

OpenAI software attempted to secretly scrape data from dozens of prominent websites

Source: The Record.

Asymmetric Security released findings on October 1 showing that OpenAI software engaged in unauthorized data scraping from numerous prominent websites. The discovery adds to a pattern of concerning behavior tied to OpenAI's tools.

Why it matters: Organizations hosting web content need to audit their defenses against automated scraping and assess data exposure risk from artificial intelligence (AI) training operations; practitioners should review access logs and robots.txt compliance to identify unauthorized collection.

Tracker inference

ai security

National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations

Source: CyberScoop.

National Cyber Director Sean Cairncross stated that government-industry collaboration is essential to manage artificial intelligence (AI) security risks while maintaining innovation and technological leadership over adversarial nations. The Trump administration opposes establishing direct government regulations on AI development, arguing that regulatory intervention would slow innovation cycles. Cairncross highlighted ongoing efforts through the National Institute of Standards and Technology and security improvements following incidents such as OpenAI's unauthorized AI agent testing against Hugging Face in July.

Why it matters: Security practitioners should track how U.S. AI governance approaches will shape vendor security requirements, incident response protocols, and critical infrastructure integration, particularly as competitive pressure with China drives distillation attacks and model theft.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-93546

CVE-2026-93546: Apache HTTP Server: mod_dav_fs namespace overflow

Source: oss-security.

An integer overflow in mod_dav_fs in Apache HTTP Server through version 2.4.68 allows authenticated WebDAV clients with write access to crash worker processes and corrupt directory property databases through PROPPATCH requests with many XML namespaces. The issue has moderate severity and was discovered by Zhen Kong and researchers at Calif.io and AISLE.

Why it matters: Apache HTTP Server administrators running versions 2.4.68 or earlier need to patch immediately if they expose WebDAV functionality to authenticated users, as this could lead to denial of service and data corruption.

Tracker inference

vulnerabilitiesResearchCVE-2026-79768

CVE-2026-79768: Apache HTTP Server: mod_userdir information disclosure

Source: oss-security.

CVE-2026-79768 is a path equivalence vulnerability in Apache HTTP Server's mod_userdir module affecting versions 2.4.0 through 2.4.68. The flaw exists when the module is configured with an absolute non-wildcard UserDir directive, allowing information disclosure through directory traversal via '/./' sequences. The issue has been assigned low severity.

Why it matters: Administrators running Apache HTTP Server 2.4.0 to 2.4.68 with mod_userdir and absolute UserDir paths should evaluate exposure to unauthorized user directory enumeration and apply patches when available.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-73637

CVE-2026-73637: Apache HTTP Server: mod_auth_digest DoS attack

Source: oss-security.

Apache HTTP Server versions 2.4.0 through 2.4.68 contain a use-after-free flaw in the mod_auth_digest module that unauthenticated attackers can exploit via concurrent Digest authentication requests to corrupt authentication state. The vulnerability exists when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. The vendor recommends upgrading to version 2.4.69 or later.

Why it matters: Organizations running affected Apache HTTP Server versions with Digest authentication enabled face a low-severity risk of authentication bypass or denial of service; prioritize patching if your web infrastructure relies on this authentication method.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-63718

CVE-2026-63718: Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling

Source: oss-security.

CVE-2026-63718 is a low-severity HTTP request/response smuggling vulnerability in Apache HTTP Server versions 2.4.30 through 2.4.68, affecting the mod_proxy_uwsgi module when processing crafted uwsgi responses with Transfer-Encoding headers. The vulnerability stems from inconsistent interpretation of HTTP requests and responses.

Why it matters: Organizations running Apache HTTP Server with mod_proxy_uwsgi enabled should evaluate whether this attack vector applies to their uwsgi backend configuration and apply patches as they become available.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-63686

CVE-2026-63686: Apache HTTP Server: mod_xml2enc crash on charset conversion failure

Source: oss-security.

A NULL pointer dereference in the mod_xml2enc module of Apache HTTP Server versions 2.4.0 through 2.4.68 allows an untrusted backend server to trigger a denial of service through a proxied response with a charset conversion that partially succeeds then fails. The vulnerability has been resolved in version 2.4.69.

Why it matters: Organizations running Apache HTTP Server 2.4.68 or earlier with proxy configurations to untrusted backend servers face service disruption risk and should upgrade to 2.4.69 immediately.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-63045

CVE-2026-63045: Apache HTTP Server: mod_proxy_ftp PASV address handling

Source: oss-security.

A low-severity vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.68 allows an untrusted FTP server to redirect proxy data connections to arbitrary third-party hosts through a crafted PASV response. The flaw affects forward proxy configurations and stems from improper validation of FTP PASV reply addresses in the mod_proxy_ftp module. Apache recommends upgrading to a patched version.

Why it matters: Organizations running Apache HTTP Server as a forward proxy for FTP traffic should assess whether they rely on this module and plan upgrades to eliminate the risk of an attacker-controlled FTP server manipulating connection targets.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-59797

CVE-2026-59797: Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function

Source: oss-security.

CVE-2026-59797 is a low-severity improper privilege management vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.68. The flaw exists in the mod_ssl module within SSLRequire and file-related expressions, potentially allowing unauthorized access or privilege escalation through .htaccess configuration files.

Why it matters: Organizations running Apache HTTP Server 2.4.0 to 2.4.68 should evaluate whether SSLRequire directives with file-function expressions are in use, as administrators need to patch or restrict these configurations to prevent privilege bypass.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-59685

CVE-2026-59685: Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM

Source: oss-security.

Apache HTTP Server versions 2.4.0 through 2.4.68 contain an out-of-bounds write vulnerability in the ap_directory_walk() function that occurs on Windows when processing paths with 8.3 names that expand during rewrite. The vulnerability is rated moderate severity.

Why it matters: Windows administrators running affected Apache HTTP Server versions should assess their environment for exposure and plan patching to prevent potential code execution or denial of service through specially crafted requests.

Tracker inference

vulnerabilitiesResearchCVE-2026-58415

CVE-2026-58415: Apache HTTP Server: mod_dav_fs property database read access

Source: oss-security.

CVE-2026-58415 affects Apache HTTP Server versions 2.4.0 through 2.4.68, allowing remote clients to read WebDAV dead properties of resources they cannot author via GET requests to the .DAV state directory. The vulnerability is rated low severity and is fixed in version 2.4.69.

Why it matters: Organizations running Apache HTTP Server 2.4.68 or earlier with mod_dav_fs enabled should patch to 2.4.69 to prevent unauthorized disclosure of WebDAV property metadata.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-57941

CVE-2026-57941: Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy

Source: oss-security.

CVE-2026-57941 is a use-after-free vulnerability in Apache HTTP Server's mod_http2 module affecting versions 2.4.0 through 2.4.68, triggered via shared session->bbtmp re-entrancy. The vulnerability carries moderate severity and was discovered by Lucian Nitescu, Simon Kappel, and Gianluca Danesin.

Why it matters: Organizations running Apache HTTP Server 2.4.0 to 2.4.68 with mod_http2 enabled should evaluate patched versions to prevent potential crashes or code execution through HTTP/2 session handling.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary