CYBERSECURITYTRACKER
TRACKING3,993 stories741 vuln stories
The watch floor

Everything moving in security, ranked by what matters now.

Reporting is aggregated and cross-verified across multiple authoritative sources. Stories are clustered, de-duplicated, and tagged by category, vendor, and threat actor. Filter to your role, pin your stack, subscribe or point your reader at a feed. No account required.

Skip to latest stories
Presets
Loading feed…
vulnerabilitiesCVE-2026-71362

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento has been detected under active exploitation. Attackers can use the flaw to hijack customer accounts on affected e-commerce platforms.

Why it matters: E-commerce operators running Adobe Commerce or Magento need to patch immediately to prevent account takeover and customer credential theft.

threat intel2 sources

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Over 737 malicious Chrome extensions impersonated legitimate VPN and proxy services on the Chrome Web Store, instead routing user traffic through SOCKS5 proxies controlled by a single operator. The campaign deceived users seeking privacy tools into exposing their internet activity to an attacker-controlled infrastructure. This represents a systematic abuse of the extension platform to intercept and monitor user traffic at scale.

Why it matters: Enterprise and individual users relying on Chrome extensions for privacy or security are at immediate risk of traffic interception and credential theft; practitioners should audit installed extensions against known impostors and validate VPN authenticity through official channels.

breaches incidents

Uber Freight reportedly investigating after hacking group claims data breach

An extortion gang specializing in transportation and private equity targets claims to have breached Uber Freight. The group's post suggests involvement in data theft from the logistics platform.

Why it matters: Uber Freight customers and employees face potential exposure of sensitive logistics, financial, and operational data. Practitioners should monitor for extortion demands and assess whether their supply chain data may be affected.

threat intel

Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan

Researchers at Israeli cyber firm Dream identified a suspected Chinese cyberattack against Taiwan's government that used open-source AI models to conduct what they call a 'near-autonomous' operation. The attackers extracted over 2,500 personnel records and expanded the campaign to target government IT supply chain vendors, a nuclear safety agency, an email system, and energy sector companies, with the AI framework adapting mid-operation through autonomous vulnerability research and learning from failures. The attack demonstrates that while AI-powered offensives still require significant human tuning and fine-tuning to operate effectively, threat actors are increasingly embedding autonomous capabilities into their campaigns.

Why it matters: Government agencies, critical infrastructure operators, and government contractors in Taiwan and elsewhere need to assume adversaries are now combining AI frameworks with supply chain targeting; defenders should inventory exposed admin interfaces, patch misconfigurations, and monitor for coordinated scanning of parallel targets.

breaches incidents

CA: Snoopers Beware; NL’s Privacy Commissioner Recommends Naming Individuals in Snooping-Related Breaches

Newfoundland and Labrador's Privacy Commissioner recommends that public bodies name individuals responsible for privacy breaches involving unauthorized access to records. The recommendation follows an incident where a Newfoundland and Labrador Health Services employee accessed a person's health record without authorization, and the health authority reported the breach to the Privacy Commissioner, who determined the response was appropriate.

Why it matters: Healthcare organizations and public bodies in Newfoundland and Labrador should review their breach notification policies to determine whether naming responsible individuals aligns with the Privacy Commissioner's new guidance, as this may become expected practice.

research

Walmart's "Trusted Agent" Approach to Purple Teaming

Walmart brings its red and blue security teams together in the same physical location to conduct purple teaming exercises that strengthen collaborative defense efforts. This co-location approach aims to build mutual trust and improve security outcomes through joint offensive and defensive testing.

Why it matters: Security teams at large enterprises can apply this operational model to reduce silos between red and blue functions, accelerate threat discovery, and validate defenses more effectively.

vulnerabilities

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Researchers disclosed Plug and Pwn attacks that exploit Windows Plug and Play to force installation of vulnerable vendor software through fake USB devices. The method achieves SYSTEM level privileges on targeted machines. This attack vector leverages the operating system's automatic driver installation mechanism without requiring user interaction beyond physical device connection.

Why it matters: Windows administrators and enterprise security teams need to assess physical access controls and Plug and Play policies, as attackers with brief device proximity can escalate to SYSTEM privileges on unprotected machines.

vulnerabilities

After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug

A security researcher identified as Nightmare Eclipse disclosed a previously unknown Windows zero-day vulnerability after Microsoft issued legal threats against the researcher. The disclosure marks a continued pattern of the researcher releasing unpatched flaws despite corporate pressure.

Why it matters: Windows users and administrators need to assess exposure to this unpatched flaw immediately and monitor for Microsoft's remediation timeline, while this incident highlights the tension between vulnerability disclosure practices and legal threats.

breaches incidents

RESOURCE: Introducing the Cyber Incident Registry

Joseph Topping has launched the Cyber Incident Registry, a research resource designed to document and analyze cyber disruptions. The registry aggregates public information about incidents, affected parties, operational impacts, and other relevant details to help researchers identify patterns and connections between events.

Why it matters: Security practitioners and researchers need centralized, documented incident data to understand attack trends, operational risk patterns, and how breaches correlate across sectors and time.

research

Linux Kernel Process Accounting

Linux kernel process accounting is a built-in feature that logs process execution details to a binary file when processes terminate, providing visibility into system activity beyond what bash history captures. The article covers installation via the acct package, reading logs with the lastcomm command, forwarding logs to a SIEM via syslog-ng, and analyzing summaries with the sa command. Process accounting adds minimal overhead (approximately 50 MB per day) and works at the kernel level, making tampering from unprivileged containers difficult.

Why it matters: Security teams and system administrators should consider enabling process accounting for forensic visibility and incident response, as it captures all process execution on a system with lower overhead than alternative monitoring tools like eBPF, though it does not log command-line arguments.

identity access

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Attackers can impersonate job applicants and gain organizational access by exploiting timing gaps between hiring verification, device provisioning, and account activation. Organizations can mitigate this risk through document verification and biometric liveness checks to confirm applicant identity at critical handoff points.

Why it matters: HR and IT security teams need to close the window between hiring approval and first-day access, as fake employees can obtain company credentials and devices if identity verification is not performed at account creation time.

ransomware

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

A ransomware attack struck Colombia's Justice Ministry shortly before a presidential transition. The incident reflects broader targeting of critical infrastructure and government entities throughout Latin America.

Why it matters: Colombian government officials and justice system operations face operational disruption and potential data theft at a politically sensitive moment; practitioners should monitor for follow-up demands and assess whether transitional personnel have access to incident response protocols.

cloud saas

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Researchers at Reco identified a campaign named City-Forum, in which an attacker has been extracting records from Salesforce and ServiceNow customer portals globally for at least 17 months. The attacker operates from a compromised server using a dormant domain registered in 2002, exploiting portal access that functions as intended without triggering typical breach detection signals.

Why it matters: Organizations using Salesforce or ServiceNow customer portals need to audit portal access logs and data exposure immediately, as the activity is ongoing and affects customers worldwide.

ai security

ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5

ScienceLogic released Skylar AI 2.5, an update to its AI platform that emphasizes secure deployment options for organizations with strict security, sovereignty, and compliance requirements. The release includes improvements to AI accuracy, platform performance, natural language capabilities, and enterprise integrations, positioning the tool as an intelligence layer for IT operations.

Why it matters: IT operations teams and security leaders evaluating AI-driven monitoring platforms should assess whether Skylar AI 2.5's security and sovereignty features meet their regulatory and data residency constraints.

vulnerabilities

Researchers found a way to hijack devices through Zoom screen sharing

Researchers at A Security discovered vulnerabilities in Zoom that could allow remote device hijacking through screen sharing functionality, affecting all major operating systems. The flaws were found using publicly available AI models with fewer than 20 prompts, demonstrating how AI is lowering the barrier to discovering exploitable security gaps. Zoom released a security advisory and began rolling out fixes in early June.

Why it matters: Zoom users on calls with screen sharing enabled are at risk of silent compromise; practitioners should verify patch deployment across their organizations and consider restricting screen sharing privileges given the ease with which such vulnerabilities can now be discovered.

ai security

Deloitte strengthens AI governance to support trusted enterprise adoption

Deloitte has expanded its AI Controls and Assurance services to help enterprises adopt and govern AI systems across their operations. The firm offers end-to-end support spanning the AI lifecycle, combining advisory and assurance services with governance frameworks to balance risk management and value creation.

Why it matters: Enterprise security and risk leaders face a gap between AI adoption plans and governance readiness: 74% of companies plan agentic AI deployment within two years, but only 21% have adequate governance structures in place.

industry

Mindgard Raises $30 Million to Protect AI Systems

Mindgard, a cybersecurity startup focused on AI system protection, raised $30 million in funding. The company plans to use the capital to expand its product development, engineering, sales, and marketing operations.

Why it matters: Security teams evaluating AI risk management tools should monitor Mindgard's growing product roadmap and market presence as the AI security landscape matures.

industry

WhatsApp Unveils New Scam Alert Feature

WhatsApp introduced a scam alert feature to help users identify fraudulent conversations. Signal simultaneously announced automatic key verification to enhance its existing safety number system for end-to-end encrypted messaging.

Why it matters: Messaging app users, particularly those targeted by social engineering attacks, gain new defenses against identity spoofing and account compromise through these platform improvements.

threat intel

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Researchers identified a campaign dubbed 'City-Forum' that exploits unauthenticated guest access on Salesforce and ServiceNow to enumerate and exfiltrate data. The attackers employ custom tooling to conduct these operations stealthily.

Why it matters: Organizations using Salesforce and ServiceNow must review guest access configurations and monitor for unauthorized data enumeration, as this campaign targets configurations that are difficult to detect.

breaches incidents

Three intrusions at UK criminal records office went undetected for two years

Three separate intrusions at the UK's ACRO (criminal records office) remained undetected for two years due to unread antivirus alerts and an unpatched content management system, according to a regulatory reprimand. The breaches highlight gaps in monitoring and patch management at a sensitive government agency.

Why it matters: UK government staff, criminal justice users, and potentially crime victims were exposed; practitioners should review alert triage processes and patch cadences for critical systems handling sensitive data.

Looking further back? Browse the daily archive, this feed's own history.