CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build

State now. Changed: 0 tier promotions, +4 known-exploited vulnerability additions, 27 leak-site claims, and 0 confirmed breaches since yesterday.

Why today matters · What to watch now

The latest security reporting, combined across sources and tagged, newest first

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by RSS. No account required.

Why now: this site build contains 6,506 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
industry

Cylake Gets $245M to Build Cloud-Free Cybersecurity Platform

Source: HealthcareInfoSecurity.

Cylake, a startup founded by Palo Alto Networks founder Nir Zuk, raised $245 million to develop an on-premises cybersecurity platform that integrates hardware, storage, security software, and local artificial intelligence (AI). The platform targets regulated organizations that cannot transmit sensitive security data to cloud providers.

Why it matters: Regulated enterprises and those under data residency constraints need to evaluate whether this on-premises alternative addresses their ability to run modern security operations without external cloud dependencies.

Tracker inference

ai security

Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks

Source: HealthcareInfoSecurity.

Anthropic's Threat Intelligence team published findings showing that multi-agent artificial intelligence (AI) tools enable less-skilled attackers to execute complex, wide-ranging operations with minimal resources. The report emphasizes that the risk lies not in AI's speed of exploit development, but in how accessible sophisticated attack infrastructure has become to broader threat actor populations.

Why it matters: Security teams and incident responders need to prepare defenses against complex, multi-vector attacks from less-technical threat actors who can now leverage AI tools to scale their capabilities.

Tracker inference

ransomware

Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison

Source: HealthcareInfoSecurity.

Ukrainian national Oleksii Lytvynenko received a four-year prison sentence from a U.S. court after admitting to developing malware and stealing data for Conti ransomware. Conti has been attributed to over 1,000 victims and approximately $150 million in ransom payments.

Why it matters: Organizations targeted by Conti should monitor for ongoing activity from affiliated developers and prepare for potential follow-up attacks, as the network likely remains operational despite individual arrests.

Tracker inference

breaches incidents

ID Verification Firm IDScan.net Confirms Data Breach

Source: HealthcareInfoSecurity.

IDScan.net, a Louisiana-based identity verification firm, confirmed a data breach linked to the alleged darkweb sale of over 153 million U.S. and Canadian driver's licenses. The company's breach notice did not disclose the number of affected individuals or the attack vector used by threat actors.

Why it matters: Organizations relying on IDScan.net for identity verification should determine whether their data was included and assess customer notification obligations; individuals with U.S. or Canadian driver's licenses may face identity theft risk if their records were compromised.

Tracker inference

ai security

Webinar | Who Controls the AI Acting on Your Behalf? The Identity Problem Behind Autonomous AI

Source: HealthcareInfoSecurity.

This is a webinar announcement addressing identity and authorization challenges in autonomous artificial intelligence (AI) systems. The content examines how organizations can maintain control and accountability when AI agents act independently within their infrastructure.

Why it matters: Security teams and infrastructure owners need clarity on identity management and access control for autonomous AI to prevent unauthorized actions and audit trail gaps.

Tracker inference

vulnerabilitiesTracker priority: ActCVE-2026-42016

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

Source: The Hacker News.

CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog on September 12, 2026, based on confirmed active exploitation. CVE-2026-42016, an authorization flaw in one of these products, carries a CVSS score of 8.1.

Why it matters: Security teams using Artifactory, ScreenConnect, or RouterOS should prioritize patching these flaws immediately, as they are already being exploited in attacks and listed on CISA's KEV catalog.

Tracker inference

Spies, surveillance and rogue AI: Best infosec long reads 9/12/26

Source: Metacurity.

A New Yorker article examines Flock Safety's nationwide license plate recognition (ALPR) surveillance network, which trades anonymity for promised crime reduction. The piece documents growing public and political opposition across conservative and liberal states, including documented misuse by police for stalking, ICE enforcement, and reproductive surveillance. Founder Garrett Langley deflects responsibility for how the technology is deployed while framing privacy concerns as obstacles to safety.

Why it matters: Security practitioners and organizations evaluating surveillance infrastructure must understand the operational and reputational risks of ALPR systems: documented abuse patterns, bipartisan pushback leading to frozen funding and revoked permits in major states, and the liability exposure when vendors disclaim responsibility for misuse.

Tracker inference

breaches incidents

Revolut confirms customer data breach through fake government requests

Source: TechCrunch Security.

Revolut experienced a customer data breach resulting from fraudulent government requests. The company notified impacted customers and reported the incident to government agencies, law enforcement, and financial regulators.

Why it matters: Revolut customers face identity and fraud risk from exposed data; fintech users should verify account security and monitor for unauthorized activity.

Tracker inference

vulnerabilities

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Source: SecurityWeek.

BlueMoon exploit kit chains recent Chrome and Windows zero-day vulnerabilities to enable opportunistic attacks. Multiple espionage-motivated threat actors have rapidly deployed the kit in the wild.

Why it matters: Organizations running unpatched Chrome and Windows systems face immediate compromise risk from active exploitation by nation-state and criminal threat actors using this chained attack vector.

Tracker inference

ai security

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

Source: Wired Security.

Claude, an artificial intelligence (AI) model, is being misused across multiple domains ranging from cyberattacks to generating harmful biological content. The report also covers law enforcement disruption of a major dark web marketplace, prosecution of a Conti ransomware group member, and Meta's struggles to prevent AI-generated child sexual abuse material.

Why it matters: Security teams must monitor AI model abuse vectors in their threat environment, law enforcement actions affect underground market operations and criminal enterprise viability, and practitioners should evaluate content moderation controls given the proliferation of synthetic abuse material.

Tracker inference

ai security

When the Whole Company Adopts AI: What It Does to Your SOC

Source: The Hacker News.

Enterprise security operations centers are observing a surge in alerts generated by artificial intelligence (AI) tools and agents deployed across organizations. These alerts stem from routine AI usage by developers and staff rather than attacks targeting AI systems, creating new noise in security monitoring workflows.

Why it matters: Security operations center teams need to adapt alert tuning and baseline models to distinguish legitimate AI tool activity from genuine threats, or risk alert fatigue and missed signals.

Tracker inference

threat intel2 sources

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

Sources: The Hacker News and 1 more.

Researchers identified that a coordinated attack on RubyGems in May 2026 involved OpenAI agents operating as a swarm to target the package manager. The incident resulted in remote code execution (RCE) on RubyDoc servers and represented a significant supply chain security incident.

Why it matters: Ruby developers and organizations using RubyGems packages face supply chain compromise risk; practitioners should review their dependency management and audit package integrity for any affected versions from that period.

Tracker inference

vulnerabilitiesTracker priority: ActCVE-2026-85706

NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions

Source: NCSC Netherlands Advisories.

GitLab patched a path traversal vulnerability in its Community and Enterprise Editions that allows unauthenticated users to read arbitrary files through the repository commits application programming interface (API). The vulnerability stems from improper path confinement and missing authentication controls on the API endpoint. The flaw is tracked as CVE-2026-85706 with a CVSS score of 10.0, has been added to CISA's Known Exploited Vulnerabilities catalog, and public exploit code is available.

Why it matters: Organizations running internet-facing, self-hosted GitLab instances face immediate risk of sensitive file exposure without authentication; patch to GitLab 19.1.8, 19.2.6, 19.3.2 or later immediately, review API logs for suspicious requests with file.path parameters, and rotate any exposed credentials.

Tracker inference

ai security

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Source: SecurityWeek.

Anthropic disclosed that users in Houthi-controlled Yemen attempted to leverage its artificial intelligence (AI) systems to develop advanced weapons, though they did not achieve an operational device. The group conducted a failed test of a guided rocket using artificial intelligence (AI) assistance.

Why it matters: Security teams must monitor for nation-state and non-state actors exploiting AI services for weapons development, as Anthropic's disclosure reveals gaps in access controls and content moderation that could enable proliferation risks.

Tracker inference

threat intelResearch

Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware

Source: Huntress.

A single malicious Google Docs message distributed via X direct message triggered different malware payloads depending on the recipient's operating system: AMOS stealer on macOS and NetSupport Manager on Windows. Huntress security analysts documented the attack chain and payload differentiation across platforms.

Why it matters: Mac and Windows users are both targeted by this campaign; practitioners should review X-based social engineering defenses and monitor for AMOS stealer and NetSupport Manager indicators of compromise (IOCs) on affected endpoints.

Tracker inference

ai security

ISMG Editors: Can Humans Still Keep AI Agents in Check?

Source: HealthcareInfoSecurity.

Four editors discussed the challenge of maintaining human control over artificial intelligence (AI) agents, security leaders' concerns about AI and cloud risk, and whether OpenAI's new processor could compete with Nvidia's market position.

Why it matters: Security leaders and practitioners need to understand governance risks as AI agents become more autonomous, and evaluate implications of new chip competition for their AI infrastructure decisions.

Tracker inference

breaches incidents

Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens

Source: HealthcareInfoSecurity.

Cyber extortion group FulcrumSec exploited hardcoded credentials found in Novo Nordisk's public-facing infrastructure to access the pharmaceutical company's systems. The breach, part of a campaign called "Hardcoded Horrorshow", demonstrates the group's focus on extracting cloud-based data rather than targeting endpoints.

Why it matters: Organizations that expose credentials in repositories, configuration files, or public infrastructure face immediate extortion risk; practitioners must scan and rotate hardcoded secrets from version control and deployment pipelines.

Tracker inference

breaches incidents

AI Agents Used in PaperCut Attacks on 395 Organizations

Source: HealthcareInfoSecurity.

A Russian-speaking attacker deployed hundreds of artificial intelligence (AI) agents to exploit PaperCut systems, compromising at least 440 systems across 395 organizations in 48 countries. GreyNoise reported that the attacker leveraged the AI agents to develop exploits, identify targets, and conduct parallel attacks.

Why it matters: Organizations running PaperCut systems worldwide face active exploitation at scale; security teams should immediately audit their PaperCut deployments for signs of compromise and apply available patches.

Tracker inference

regulatory

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

Source: CyberScoop.

The U.S. Department of Transportation published a rule that classifies cyberattacks as one of ten "not controllable" causes of flight delays and cancellations, exempting airlines from providing meal vouchers or hotel compensation when such incidents occur (provided the carrier complies with cybersecurity regulations). The rule, which takes effect next month, stems from the Federal Aviation Administration Reauthorization Act of 2024 and establishes a new reporting category to distinguish between disruptions within and outside carrier control. Consumer advocacy groups expressed mixed views, with some questioning whether airlines might exploit ambiguities in the rule to avoid compensation, while others noted the clarity it provides to travelers regarding their rights across carriers.

Why it matters: Airline customers and compliance officers need to know that cyberattacks causing flight disruptions may no longer trigger automatic meal and hotel reimbursements, though airlines must demonstrate compliance with cybersecurity regulations to invoke this exemption; non-compliance could restore customer service obligations.

Tracker inference

vulnerabilitiesTracker priority: ActCVE-2026-85706

GitLab security advisory (AV26-917)

Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.

GitLab addressed vulnerabilities in versions prior to 19.1.8, 19.2.6, and 19.3.2 with critical patch releases. CVE-2026-85706 (CVSS 10.0) was added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) database on September 11, 2026, indicating active exploitation.

Why it matters: GitLab administrators managing affected instances must update immediately, as CVE-2026-85706 is actively exploited and represents a critical risk to their deployments.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary