The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 7,772 stories, with the newest available reporting below.
Common Vulnerabilities and Exposures (CVEs): CISA KEV additions, newly reported exploitation in the last 7 days, or news coverage in the last 48 hours
CVE-2026-94127F5 BIG-IP APMpinnedCVSS 9.3Added to CISA KEV on 2026-09-22 · Exploitation newly reported on 2026-09-22 · 1 news mention in 48 hours
CVE-2025-39964Linux KernelpinnedCVSS 7.8Added to CISA KEV on 2026-09-18 · Exploitation newly reported on 2026-09-18
CVE-2026-53266Linux KernelpinnedCVSS 8.8Added to CISA KEV on 2026-09-18 · Exploitation newly reported on 2026-09-18
CVE-2025-39682Linux KernelpinnedCVSS 9.8Added to CISA KEV on 2026-09-18 · Exploitation newly reported on 2026-09-18
CVE-2026-5430WSO2 Multiple ProductspinnedCVSS 10.0Added to CISA KEV on 2026-09-24 · 1 news mention in 48 hours
CVE-2026-65660Microsoft SharePointpinnedCVSS 6.5Added to CISA KEV on 2026-09-25 · 1 news mention in 48 hours
CVE-2026-71362Adobe Commerce and Magento pinnedCVSS 9.1Added to CISA KEV on 2026-09-24 · 1 news mention in 48 hours
CVE-2026-85102Check Point Multiple ProductspinnedCVSS 9.8Added to CISA KEV on 2026-09-22 · 1 news mention in 48 hours
Records from your pinned vendors are marked and listed first when they are trending. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.
Uniphore's CEO argues that enterprises should deploy artificial intelligence (AI) workloads on sovereign, on-premises infrastructure rather than relying on closed frontier models. The concern centers on proprietary data and trade secrets potentially being learned by external AI systems and shared with competitors.
Why it matters: Enterprise executives and security leaders deciding on AI deployment models need to assess whether cloud-based AI services pose unacceptable risks to competitive advantage and intellectual property.
Artificial intelligence (AI) systems with access to comprehensive business data may still reach poor decisions without understanding the regulatory, strategic, and human factors that influence operations. According to Aily Labs founder Bianca Anghelina, numerical data alone does not capture the full context required for effective business decision-making.
Why it matters: Organizations deploying AI for business optimization should ensure systems understand domain constraints and business logic, not just data patterns, to avoid costly misguided recommendations.
Businesses implementing artificial intelligence (AI) into legacy processes often achieve marginal efficiency gains that fail to improve financial outcomes, a phenomenon termed 'cappuccino ROI.' Real return on investment materializes when organizations redesign workflows to place AI at the center and redefine human roles to complement AI agents.
Why it matters: Enterprise buyers need to shift from bolting AI onto existing processes to fundamentally restructuring operations and human responsibilities in order to achieve measurable business impact from AI investments.
The Wordfence Bug Bounty Program processed 1,066 vulnerability submissions in June 2026, with 306 active researchers contributing to WordPress security. The program awarded $42,553 in total bounties, with an average bounty of $230.02 per validated submission, and identified high-impact vulnerabilities including remote code execution flaws in Everest Forms Pro and UpdraftPlus plugins.
Why it matters: WordPress site owners and plugin developers should monitor this monthly report to understand current vulnerability trends, patch critical issues in their installed plugins, and consider adopting Wordfence protection to defend against newly disclosed threats before attackers exploit them.
Silent Push published six threat investigations covering ransomware group infrastructure, attacker activity targeting Amgen, dangling DNS subdomain vulnerabilities, residential proxy networks, North Korean IT worker recruitment, and phishing operations. The collection spans research conducted between June and September 2026.
Why it matters: Security teams benefit from examining adversary infrastructure patterns, early indicators of targeting, and attack techniques like DNS takeovers and fast-flux operations to strengthen detection and response capabilities.
Anthropic expanded access to Claude Code by enabling cloud session deployments without research preview enrollment and offering up to $250 in complimentary usage credits to new users. The program aims to broaden trial opportunities for the feature.
Why it matters: Development teams evaluating Claude Code for integration into workflows can now test the tool at no initial cost with meaningful credit allocations.
Kiteworks, a platform for secure data transfer over the internet, instructed customers to shut down their servers after receiving a credible threat notification from law enforcement regarding an imminent cyberattack. The company took the precautionary step to protect customer infrastructure from the anticipated threat.
Why it matters: Organizations using Kiteworks for secure file transfer need to assess the threat status and whether to take servers offline; law enforcement notification suggests active targeting of the platform and its customer base.
OpenAI's global head of first-line distribution and enterprise services discusses how organizations that simply layer artificial intelligence (AI) into current workflows often fail to capture its full potential. Companies that redesign processes, establish governance frameworks, control data access, and restructure teams around AI implementation will realize greater value from the technology.
Why it matters: Enterprise leaders and security teams should evaluate whether their AI governance, access controls, and organizational structures support value capture and risk management, or whether process redesign is needed to align business and security outcomes.
A survey shows that companies still in the experimentation stage with artificial intelligence (AI) are less likely to deploy advanced AI-powered defenses compared to organizations with established AI use. This reflects varying levels of maturity and comfort with AI technology across the business landscape.
Why it matters: Security leaders deciding on AI-powered defense investments should assess their organization's AI maturity level, as adoption rates vary significantly between early explorers and established users.
The article flags three security developments: a BragJack attack targeting browser-based artificial intelligence (AI) assistants, a TDengine vulnerability affecting industrial telemetry systems, and changes to Ubuntu's update process. A Docker botnet was observed targeting AI credentials, and a water utility faced exposure. Additionally, the Clop leak site underwent a takeover.
Why it matters: Browser AI users face session hijacking risks from BragJack attacks; industrial telemetry operators must patch TDengine to prevent uptime loss; water utility operators and Ubuntu administrators should assess their exposure and update procedures.
Dyfed-Powys Police in Wales experienced a cyberattack that disrupted non-emergency systems and potentially exposed staff data. The force confirmed the incident but did not disclose technical details or the scope of affected records.
Why it matters: Law enforcement and government employees at this Welsh police force should assume their personal information may be at risk and monitor for fraud or identity theft; incident response teams need to assess whether external infrastructure was compromised.
The Register is hosting a private dinner on October 27 in New York for senior technology and infrastructure leaders to discuss unstructured file data management in distributed teams. The conversation will cover legacy storage infrastructure, data governance gaps, version control challenges, and modernization strategies without wholesale replacement.
Why it matters: Infrastructure and data leaders managing distributed teams should attend if invited to learn how peers handle unstructured data sprawl, file versioning, and storage costs without major rip-and-replace decisions.
OpenAI is preparing a ChatGPT Pro Max subscription tier priced at $500 per month, featuring faster Codex capabilities, though a launch timeline remains unconfirmed. The announcement suggests expansion of premium offerings targeting power users and enterprises requiring enhanced performance.
Why it matters: DevOps teams and enterprises evaluating artificial intelligence (AI) coding assistants need to understand OpenAI's pricing trajectory and whether premium tiers align with their budgets and performance requirements.
Artificial intelligence (AI) agents operating with human credentials create security gaps that existing SOC 2 controls may not detect, since agent actions can appear indistinguishable from human activity. Token Security argues that SOC 2 compliance frameworks must evolve to account for agent identities and their potential risks.
Why it matters: Compliance officers and security leaders managing SOC 2 attestations need to understand how AI agents blur the lines between human and automated activity, potentially exposing organizations to undetected unauthorized actions.
Human resources managers can help reduce social engineering attacks targeting IT workers through updated training on current tactics and warning signs. Automated analysis tools complement manual vigilance by identifying suspicious patterns in hiring and onboarding processes.
Why it matters: HR teams and IT security leaders need coordinated defense against targeted recruitment scams that compromise internal access and credentials.
The article is a Metasploit wrap-up post, likely covering recent updates or modules added to the penetration testing framework. No substantive content is provided in the article text.
Why it matters: Security practitioners using Metasploit should monitor official wrap-up posts for new modules, exploits, or features that expand their assessment toolkit.
Researchers discovered vulnerabilities in Salesforce Agentforce that allow attackers to access CRM data through prompt injection and DNS exfiltration techniques without user interaction. The 'SalesBleed' flaws highlight a broader security concern around artificial intelligence (AI) agent design and data exposure in enterprise systems.
Why it matters: Salesforce customers using Agentforce face direct risk of CRM data compromise, and security teams need to evaluate whether their AI agent deployments contain similar prompt injection or exfiltration vectors.
Researchers identified a new variant of PamStealer macOS malware that implements server-side decryption for its main payload, preventing offline analysis. The updated version maintains its JavaScript for Automation dropper but changes the lure and delivery approach, building on previous variants that stored decryption keys locally.
Why it matters: macOS users and defenders need to monitor for this evolved PamStealer variant, which raises the barrier to payload inspection and suggests active development by threat actors targeting Apple systems.
Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.
ServiceNow issued security advisory AV26-963 on September 25, 2026, identifying vulnerabilities in the ServiceNow artificial intelligence (AI) Platform. The advisory affects multiple product versions across Australia, Yokohama, and Zurich release lines and recommends applying available updates.
Why it matters: ServiceNow customers running affected AI Platform versions need to patch immediately to close these security gaps before exploitation occurs.
Microsoft announced the deprecation of Windows Deployment Services (WDS) server role beginning with the next Windows Server release. The transition reflects Microsoft's shift toward modern deployment methods for Windows infrastructure.
Why it matters: Organizations running Windows Server environments using WDS for system deployment must plan migration to alternative tools to maintain operational continuity and vendor support.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.