The latest security reporting, combined across sources and tagged, newest first
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by RSS. No account required.
Why now: this site build contains 6,626 stories, with the newest available reporting below.
Common Vulnerabilities and Exposures (CVEs): CISA KEV additions, newly reported exploitation in the last 7 days, or news coverage in the last 48 hours
CVE-2026-85706GitLab Community Edition and Enterprise EditionCVSS 10.0Added to CISA KEV on 2026-09-11 · Exploitation newly reported on 2026-09-11 · 3 news mentions in 48 hours
CVE-2026-86060MikroTik RouterOSCVSS 9.2Added to CISA KEV on 2026-09-10 · Exploitation newly reported on 2026-09-08 · 1 news mention in 48 hours
CVE-2026-86218N-able N-centralCVSS 10.0Added to CISA KEV on 2026-09-08 · Exploitation newly reported on 2026-09-07
CVE-2026-84869ConnectWise ScreenConnectCVSS 9.9Added to CISA KEV on 2026-09-11 · Exploitation newly reported on 2026-09-10
CVE-2026-87491Google Chromium V8CVSS 8.8Added to CISA KEV on 2026-09-09 · Exploitation newly reported on 2026-09-09
CVE-2026-20079Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCVSS 10.0Added to CISA KEV on 2026-09-09 · Exploitation newly reported on 2026-09-09
Attackers are actively exploiting a recently patched vulnerability in self-hosted GitLab instances to steal files and credentials from public-facing servers. The vendor urges all self-hosted users to apply the patch immediately.
Why it matters: Organizations running self-hosted GitLab are at immediate risk of credential and source code theft; patches must be deployed without delay.
The CyberEdBoard will host a webinar on September 24 to present a maturity model developed by Carnegie Mellon's Software Engineering Institute and Accenture. The framework helps organizations evaluate their artificial intelligence (AI) adoption readiness and develop strategies for consistent, repeatable, and scalable outcomes.
Why it matters: Security leaders and enterprise architects need this maturity model to assess organizational readiness for AI deployment and identify capability gaps before investment.
This is a webinar announcement about securing cyber-physical systems in healthcare environments. No substantive content or event details are provided.
Why it matters: Healthcare practitioners need to understand attack surface risks to critical infrastructure, but this stub offers no actionable findings or timelines.
A Twitch browser extension with 30,000 installations in official Chrome and Firefox stores transmits users' Twitch OAuth session tokens to an external commercial bot service. The extension, called Twitch Enhanced Viewer | JeetBot, exposes sensitive authentication credentials to unauthorized access.
Why it matters: Twitch users with this extension installed have their OAuth tokens exposed to a third party, enabling account takeover, unauthorized streaming, channel modifications, and credential compromise. Security teams should alert users to uninstall the extension and revoke Twitch OAuth tokens immediately.
The author has scheduled speaking engagements at several venues over the coming weeks, including a League of Women Voters event on September 22, 2026, CanSecWest 2026 in Vancouver from September 30 to October 1, 2026, a talk at Bentley University on October 6, 2026, and an appearance at ATTENTION: Democracy, Rebuilt in Montreal from October 21 to 23, 2026. A previously announced talk at the Elevate Festival has been canceled.
Why it matters: This is a personal calendar update with no security practitioner relevance or actionable information.
An unauthenticated arbitrary file upload vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture plugin, affecting versions up to 2.0.3.1, allows attackers to upload PHP webshells and achieve remote code execution. Wordfence has blocked over 100,000 exploit attempts since the vulnerability's public disclosure on February 20, 2026, with active exploitation occurring across multiple attack campaigns. The plugin was patched in version 2.0.3.2, and affected WordPress sites should update immediately.
Why it matters: WordPress site operators using WooCommerce Wholesale Lead Capture (6,000+ active installations) face immediate risk of complete site compromise; patch to version 2.0.3.2 now and review uploads directories and web server logs for evidence of exploitation.
Attackers gained control of HBO Max's official Reddit account and deployed malicious advertisements that executed ClickFix attacks against Windows and macOS systems, installing information-stealing malware on compromised devices.
Why it matters: Security teams and endpoint defenders managing Windows and macOS environments need to monitor for ClickFix infection indicators and educate users about malware delivery through compromised corporate social media accounts.
Tracker inference
vulnerabilitiesCVE-2022-3437CVE-2026-20683+259 more
Apple released updates across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS on September 14, 2026, patching 261 vulnerabilities, the largest number in Apple's history. The vulnerabilities span multiple components including kernel, WebKit, file systems, and system services, with exposures ranging from denial of service and memory corruption to privilege escalation and data disclosure. None of the patched CVEs are documented as being actively exploited, though some patches address critical issues such as sandbox escapes and arbitrary code execution.
Why it matters: Organizations running Apple devices need to prioritize testing and deployment of these patches, particularly for kernel, WebKit, and privilege escalation issues (CVE-2026-84607, CVE-2026-43689, CVE-2026-43691, CVE-2026-84506) that could allow attackers to compromise systems. Users upgrading to macOS 27 should verify compatibility with security tools like Little Snitch before proceeding, as some third-party applications require updates to function correctly on the new OS version.
Researchers from KU Leuven, ETH Zurich, Durham University, and Google demonstrated a hardware attack called DDRop that exploits memory encryption weaknesses in confidential computing systems. The attack uses a custom circuit board costing under $200 to intercept and drop writes to encrypted memory, allowing attackers with physical access to read protected data and forge attestation reports. The vulnerability affects Intel TDX, Scalable SGX, and AMD SEV-SNP implementations, with no straightforward fix available from vendors.
Why it matters: Cloud service providers and enterprises using confidential virtual machines for sensitive workloads face a risk if attackers gain physical access to servers, requiring security review of data center physical access controls and threat modeling assumptions.
Cisco patched a vulnerability in Secure Email Gateway caused by insufficient validation of incoming email messages in AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL instructions to execute arbitrary SQL commands and subsequently gain root-level command execution on the underlying operating system. Active exploitation has been observed in the wild.
Why it matters: Organizations running Cisco Secure Email Gateway must apply this patch urgently and audit systems for signs of compromise, as exploitation is already occurring.
ClickFix attacks use fake advertisements on social media platforms to deceive users into downloading malicious software that compromises their systems. The campaign has recently targeted Mac and Windows users through fraudulent HBO Max ads posted on Reddit.
Why it matters: Mac and Windows users are at immediate risk of system compromise if they click on deceptive ads on Reddit and other platforms; security teams should alert users to verify sources before downloading software from ads.
Researchers disclosed DDRop, a hardware attack that exploits memory protection weaknesses in Intel Total Data eXchange (TDX) and AMD Secure Encrypted Virtualization Secure Nested Paging (SEV-SNP) by silently dropping memory writes, causing the processor to repeatedly read stale encrypted data. The attack requires prior software control and brief physical access to install a circuit.
Why it matters: Organizations relying on Intel TDX or AMD SEV-SNP for confidential computing isolation should assess whether their threat model includes attackers with existing software compromise and brief hardware access, as these protections may be circumvented.
Threat intelligence firm Hunt.io identified an attacker maintaining persistent access within 3BB, a major Thai broadband provider, through MeshCentral, a legitimate remote management tool. The intrusion was discovered after the attacker exposed a server containing their tools and credential lists on the public internet.
Why it matters: Internet service provider customers and administrators at 3BB face credential theft and network compromise; practitioners should review MeshCentral deployments for unauthorized access and assess whether internal systems are exposed to the internet.
Python's tarfile module contains a vulnerability in its extraction filters that allows attackers to modify files and disclose content by exploiting hard links to symlinks during archive extraction. The flaw affects systems that use tarfile's filtering mechanisms when processing untrusted tar archives.
Why it matters: Python developers and systems that process tar archives from untrusted sources face potential file modification and information disclosure; patching or disabling tarfile extraction of untrusted archives is critical.
Telegram Desktop contained a vulnerability that allowed malicious JavaScript to be injected into HTML export files through crafted bot messages. When a user opened the exported file in a browser, the hidden script could exfiltrate the message contents from that file.
Why it matters: Telegram Desktop users who export chats to HTML and open them in a browser face data theft risk if they receive messages from compromised bots; patch or avoid opening exports in browsers until fixed.
Jerod Santo, a developer, open source maintainer, and podcaster, joined Socket as Head of Media. Santo highlighted rising supply chain attacks, artificial intelligence (AI)-driven vulnerability discovery, and zero-day exploits as defining security challenges. He emphasized the need for nuanced conversations and informed perspectives on supply chain security beyond headlines.
Why it matters: Software developers and security teams should care because supply chain attacks are accelerating in frequency and sophistication, affecting their dependencies and third-party integrations, and informed industry discussion helps organizations understand and mitigate these risks.
Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.
Android published a security bulletin on September 8, 2026, to address vulnerabilities affecting Android devices. The Cyber Centre recommends users and administrators review the bulletin and apply available updates.
Why it matters: Android device users and administrators need to assess and patch affected systems according to the September 2026 security bulletin to reduce exposure to known vulnerabilities.
Red Heron, a suspected Chinese threat actor, exploited a recently disclosed remote code execution (RCE) vulnerability in Gitea to compromise 13 organizations across six countries. The group scanned over 1,386 Gitea instances globally and maintained a separate dataset of 477 Taiwan-based systems as part of a coordinated campaign.
Why it matters: Organizations running internet-facing Gitea instances are under active attack; practitioners should immediately identify and patch vulnerable Gitea deployments and review access logs for signs of exploitation.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.