CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
The watch floor

Everything moving in security, ranked by what matters now.

One feed of clustered, de-duplicated stories across 43 sources, tagged by category, vendor, and threat actor. Filter to your role, pin your stack, subscribe or point your reader at a feed. No account required.

Presets
Loading feed…
ai security

Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack

The CEO of Hugging Face responded to a reported cyberattack involving autonomous agent technology by calling for heightened transparency in the industry. The statement emphasizes the novel nature of such an attack and signals the need for coordinated disclosure practices.

Why it matters: AI practitioners and security teams need to understand emerging attack vectors targeting autonomous agents and track industry transparency commitments as a baseline for incident response.

vulnerabilities

Scans for ESAFENET CDG 3 Document Management System Weak Logins

ESAFENET's CDG (Content Data Guard) document management system is being actively scanned for exploitation using default credentials. The product, which targets Chinese markets, ships with weak default passwords that appear in public exploit templates despite meeting standard password complexity requirements. Attackers are leveraging these known default logins to attempt unauthorized access to CDG deployments.

Why it matters: Organizations running ESAFENET CDG must immediately change all default passwords and audit for unauthorized access, as exploit code for these credentials is publicly available and actively being used in scanning campaigns.

vulnerabilities

GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI have integrated time-based defenses into Dependabot to mitigate supply chain attacks. The mechanism restricts the window during which compromised dependencies can propagate and cause damage across dependent projects.

Why it matters: Development teams and practitioners managing open source dependencies need to update their dependency strategies to leverage these new protections, which reduce exposure when packages are compromised.

breaches incidents

Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open

AnMed Health System, which operates four hospitals in Upstate South Carolina and northeast Georgia, experienced a phone and internet outage affecting all locations. Emergency rooms remained operational during the incident despite the connectivity disruption.

Why it matters: Healthcare administrators and IT security teams need to assess whether this outage resulted from a cyberattack or infrastructure failure, as both scenarios demand immediate incident response and communication protocol activation.

breaches incidents

A-list directors, actors and celebrities exposed in Tribeca film festival data leak

A security researcher discovered four publicly accessible, unencrypted databases connected to the Tribeca Film Festival, including a development database containing over 203,000 records. The databases lacked password protection and exposed sensitive information about festival-associated individuals.

Why it matters: Film industry professionals, festival organizers, and anyone whose data was in these databases face privacy and social engineering risks; practitioners should review their own cloud storage and database configurations for similar misconfigurations.

breaches incidents

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

A weekly news roundup covered multiple security topics, including active exploitation of a ServiceNow pre-authentication remote code execution vulnerability and a breach of Hugging Face. The piece also discussed how organizations increasingly run multiple AI platforms simultaneously across different vendors and departments.

Why it matters: ServiceNow administrators and organizations using Hugging Face need immediate visibility into whether they are affected by the active exploitation and breach; Hugging Face users should assess what credentials or data may have been exposed and reset access tokens if necessary.

cloud saasResearch

FAQs from the Field: Is Wiz a Runtime Security Tool?

The company Wiz clarifies that its platform includes runtime security capabilities beyond risk prevention. The brief article addresses a common prospect question about the scope of Wiz's security functionality.

Why it matters: Cloud security practitioners evaluating Wiz need to understand its full feature set, including runtime capabilities, when assessing whether it meets your organization's runtime security requirements.

cloud saasResearch

From Posture to Runtime: A Unified Approach to OpenShift Security

Red Hat describes an integrated security approach for OpenShift that combines configuration posture assessment with runtime threat detection and response. The offering addresses the shared responsibility model where security teams maintain visibility across their operational scope within the platform.

Why it matters: Security teams managing OpenShift deployments need to understand how posture management and runtime protection work together to reduce gaps in their security coverage.

threat intel

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Threat actors are conducting ClickFix attacks on Steam discussion forums, disguising malicious downloads as solutions for gaming and computer issues that instead deliver XMRig cryptominers to infected systems. The campaign exploits the trust users place in community forums when seeking technical support, creating a social engineering vector at scale within a popular gaming platform.

Why it matters: Gamers and technical support seekers on Steam face credential theft and system resource consumption; security teams should educate users about verifying software sources and monitor for XMRig indicators on corporate networks where employees may use gaming platforms.

threat intel

The hacker who humiliated spyware makers and was never caught

A profile examines Phineas Fisher, a hacktivist credited with breaching multiple controversial government spyware vendors and remaining unidentified. The article explores Fisher's operations, methods, and significance in the hacker community.

Why it matters: Security teams defending spyware makers and government contractors should understand Fisher's demonstrated capabilities and the operational security gaps that enabled persistent access; this case illustrates both the threat model and the gaps in their defenses.

threat intel2 sources

Malicious sites use JavaScript to build malware in browser memory

A malvertising campaign deploys fraudulent cryptocurrency and trading platform websites containing malicious JavaScript that constructs malware in browser memory, bypassing traditional file-based detection methods.

Why it matters: Cryptocurrency traders and users of targeted platforms face immediate credential theft and financial loss from in-memory malware that leaves minimal forensic traces.

breaches incidents

US House Votes to Extend Cyber Sharing Law for 10 Years

The U.S. House of Representatives voted to extend a key cyberthreat sharing law for 10 years by including the reauthorization in the fiscal year 2027 national defense authorization act. The measure passed narrowly on a 216-212 vote Wednesday and was attached to the $1.15 trillion defense policy bill after the reauthorization had been stalled.

Why it matters: Organizations and security practitioners depend on cyberthreat information sharing mechanisms to improve their defenses; the extension ensures continuity of this critical infrastructure for collaborative threat intelligence.

breaches incidents

AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’

A registered nurse in northern Sydney has been charged after allegedly downloading patient data without authorization. NSW Police launched an investigation following a report to the agency and subsequently searched a home in Frenchs Forest as part of the inquiry.

Why it matters: Healthcare providers and compliance teams must monitor internal access to patient records and implement controls to prevent unauthorized downloads, as employee data theft represents a direct breach of patient privacy and trust.

breaches incidents

No Need to Hack When It’s Leaking: Click to Pray edition

The Click To Pray app, a prayer application endorsed by the Pope with hundreds of thousands of users, exposed users' names and email addresses through a data leak. An ethical hacker discovered the exposure, which had persisted for months or longer.

Why it matters: Users of the Click To Pray app face phishing and targeted social engineering attacks due to their exposed personal information, and organizations using religiously-affiliated apps should audit their security controls immediately.

ransomware

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are leveraging email addresses from ShinyHunters data leaks to conduct sextortion campaigns demanding $2,000 in Bitcoin from recipients. The attackers are exploiting publicly available breach data to target victims with extortion threats.

Why it matters: Organizations and individuals whose emails appeared in ShinyHunters leaks face active sextortion threats; practitioners should monitor for related compromise indicators and prepare incident response for affected users.

vulnerabilitiesCVE-2026-16723

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers are actively exploiting CVE-2026-16723, a critical remote code execution vulnerability in Alibaba's Fastjson JSON library for Java. The flaw allows unauthenticated code execution in affected Spring Boot applications with a CVSS score of 9.0. No patched version is currently available.

Why it matters: Organizations running Fastjson 1.x in Spring Boot deployments face immediate remote code execution risk; immediate assessment and mitigation planning are required until a patch is released.

threat intel

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

OpenAI models used in a hack of Hugging Face remained active on the internet for several days before detection. The incident underscores the exposure window between initial compromise and discovery in supply chain security contexts.

Why it matters: Security teams should monitor for unexpected model or API activity to detect compromised credentials or systems; this case shows attackers can maintain presence long enough to exfiltrate data or pivot further.

threat intel

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

CTM360 research documents a shift in insurance-focused phishing tactics from delayed account compromise to real-time hijacking. Attackers now move immediately upon credential capture rather than waiting for a later opportunity to exploit stolen usernames and passwords.

Why it matters: Insurance industry employees and customers face immediate account takeover during active phishing sessions, requiring faster detection and response protocols than the traditional delayed-compromise model.

ransomware

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p-affiliated threat actors are exploiting unauthenticated remote code execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain pre-authentication information disclosure in FlexPLM with server-side flaws in Windchill's login servlet to gain unauthorized access. This activity is part of an active data extortion campaign.

Why it matters: Organizations running PTC Windchill or FlexPLM with internet exposure face immediate risk of compromise by a known ransomware operator; patching or restricting network access to these systems should be prioritized today.

ransomware

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

DevMan operators maintain a web portal that enables affiliates to build ransomware payloads, track earnings, and manage victim information. The Swiss cybersecurity firm PRODAFT tracks the operation under the threat actor name Funky Mantis and reports that the platform centralizes multiple ransomware-as-a-service functions in one location.

Why it matters: Organizations are at risk from an increasingly organized ransomware operation with distributed affiliate models; security practitioners should monitor for DevMan/Funky Mantis campaigns and implement detection for this RaaS tooling.

Looking further back? Browse the daily archive, this feed's own history.