CYBERSECURITYTRACKER
TRACKING8,289 stories in this site build1,881 vulnerability news stories in this site build

State now. Changed: +1022 tier promotions, 0 known-exploited vulnerability additions, 1443 leak-site claims, and 0 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 8,289 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
threat intel

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes

Source: Infosecurity Magazine.

ClingSTUN malware exploits known vulnerabilities in unpatched Internet of Things (IoT) devices and abuses public Session Traversal Utilities for Network Address Translation (STUN) servers to establish and maintain persistent proxy access to infected devices. This technique allows attackers to use compromised IoT hardware as intermediate nodes for network traffic tunneling and other malicious activities.

Why it matters: Organizations operating unpatched IoT devices face immediate risk of exploitation and network compromise, as attackers can convert these devices into proxy infrastructure for further attacks or data exfiltration.

Tracker inference

breaches incidents

South Korea probes bank breaches amid suspected AI-powered attacks

Source: BleepingComputer.

South Korea's Financial Services Commission held an emergency meeting after cyberattacks targeted multiple financial institutions in the country. The breaches are suspected to involve artificial intelligence (AI)-powered attack methods, marking a shift in sophistication for threat actors operating in the region.

Why it matters: Financial institutions and their customers in South Korea face exposure to account compromise and fraud; practitioners should assess whether AI-enhanced attack techniques are emerging in their threat landscape and update detection rules accordingly.

Tracker inference

threat intelResearchTracker priority: ActCVE-2026-76504CVE-2026-86950+3 more

5th October – Threat Intelligence Report

Source: Check Point Research.

A threat intelligence bulletin covering the week of October 5 reported breaches at Arizona's state court system, Japanese car-sharing service Times Car, and Polish invoicing platform Fakturownia, exposing personal data and identity documents. Researchers tracked autonomous artificial intelligence (AI) agents conducting rudimentary hacking attempts, malicious Custom GPTs delivering remote access malware through ClickFix campaigns, and an AI-enabled threat actor automating cloud reconnaissance using compromised Azure principals. Critical vulnerabilities were patched in Citrix NetScaler, Cisco Catalyst SD-WAN Manager, Apple CoreGraphics, and GitLab AI Gateway, with active exploitation confirmed in at least two cases.

Why it matters: Arizona court system users and Foster Care Review Board participants face identity theft risk from exposed personal and case records. Times Car customers with identity documents exposed should monitor for account fraud and identity theft. Fakturownia users storing financial data on the platform need to reset credentials and monitor for unauthorized transactions. Organizations running Citrix NetScaler, Cisco SD-WAN Manager, or GitLab AI Gateway must patch immediately to block active exploitation. Utilities, telecom, government, and education sectors targeted by Warlock ransomware exploiting SharePoint ToolShell should prioritize SharePoint patching and endpoint protection hardening. AI policy experts at US think tanks, universities, and law firms are being socially engineered by TA419 and should implement multifactor authentication (MFA) and security awareness training. Governments, NGOs, and organizations supporting Ukraine are targeted by Star Blizzard phishing campaigns deploying CosmicPulse backdoors.

Tracker inference

threat intel

Fake brand discounts on social media prey on shoppers’ fear of missing out

Source: Help Net Security.

Cybercriminals are deploying a phishing kit called Milk Dragon on Facebook and TikTok, advertising fake brand discounts to redirect users to phishing sites that harvest payment card details and one-time passwords. Active since October 2025, the campaign has generated 258 phishing pages affecting victims across 66 countries and distinguishes itself through tactics that diverge from typical phishing methods.

Why it matters: E-commerce customers and payment processors need to monitor for these fake discount schemes on social platforms, as the campaign targets financial credentials at scale across multiple geographies and has been operating for a year.

Tracker inference

threat intel

Belarusian hacktivists spent two years inside Russian healthcare network, researchers say

Source: The Record.

Belarusian Cyber Partisans conducted a two-year espionage operation inside a Russian healthcare network, according to analysis by Russian cybersecurity researchers. The group, typically known for public attacks on government and infrastructure targets, maintained a low-profile presence during the campaign.

Why it matters: Healthcare organizations and Russian entities need to assess whether persistent nation-state groups have established footholds in their networks, as long-dwell compromises can enable data theft or operational disruption.

Tracker inference

vulnerabilities

NCSC-2026-0400 [1.00] [M/H] Dell has addressed vulnerabilities in Container storage modules

Source: NCSC Netherlands Advisories.

Dell patched multiple vulnerabilities in Container Storage Modules (CSM) version 1.18.0 and later, which integrate Dell storage systems with Kubernetes and OpenShift platforms. The flaws include authentication and authorization bypasses, privilege escalation, information disclosure, and issues in CSM components and Container Storage Interface (CSI) drivers that could allow attackers to gain administrative access, read sensitive data such as Kubernetes Secrets, manipulate role-based access control (RBAC) configurations, or achieve root-level access to cluster nodes depending on the specific vulnerability and attacker position.

Why it matters: Organizations running Dell CSM in Kubernetes or OpenShift environments must apply the patches immediately to prevent unauthenticated or low-privileged attackers from compromising cluster nodes, stealing secrets, and accessing underlying storage infrastructure.

Tracker inference

industry

LTM launches BlueVerse AgenTraceIQ to monitor AI agents and reverse unintended actions

Source: Help Net Security.

LTM has launched BlueVerse AgenTraceIQ, a service that combines Rubrik Agent Cloud with governance and managed services to help organizations monitor autonomous artificial intelligence (AI) agents. The offering enables guardrails and reversal of unintended agent actions across critical business environments as part of Rubrik's Project Hourglass partner program.

Why it matters: Organizations deploying autonomous AI agents need monitoring and rollback capabilities to prevent costly or damaging unintended actions in production environments.

Tracker inference

identity access

tenfold CE: Our free Identity Governance tool just got 2 new features

Source: BleepingComputer.

Tenfold released two new features in its free Community Edition identity governance tool: shared content governance and real-time event auditing. These additions are available to organizations with under 150 users and support Microsoft 365 management and identity activity investigation.

Why it matters: Teams managing Microsoft 365 environments and identity events can now use these governance and auditing capabilities at no cost, reducing setup friction for smaller organizations.

Tracker inference

ai security

Stellar Cyber 7.0 adds measurable workflows for AI-powered SOCs

Source: Help Net Security.

Stellar Cyber released version 7.0, which integrates artificial intelligence (AI)-powered case triage, measurable security operations center (SOC) workflows, automated response capabilities, and new application programming interfaces (APIs) for security operations. The update transitions from using AI as an analyst assistance tool to a practical operating model for autonomous SOC operations. The release includes deeper investigative evidence features and unified case management across the platform.

Why it matters: SOC teams and security leaders evaluating AI-augmented platforms need to assess whether measurable workflows and automated response features reduce analyst workload and improve incident resolution times in their environment today.

Tracker inference

threat intel

Malwarebytes Scam Link Check analyzes URLs and explains potential risks

Source: Help Net Security.

Malwarebytes launched Scam Link Check, a free web tool that analyzes URLs to assess safety and explain associated risks. Users can submit suspicious links from text, email, chat, or social media and receive results with reasoning and recommended actions.

Why it matters: Anyone receiving suspicious URLs via messaging or email can use this tool to assess potential phishing or scam threats before visiting; security-conscious users and organizations may recommend it as a quick pre-visit screening step.

Tracker inference

breaches incidents

Japanese media group Nikkei discloses cyberattack targeting journalistic sources

Source: The Record.

Nikkei, a major Japanese media group, disclosed a cyberattack that compromised an employee email account and potentially exposed journalistic sources. The incident highlights the risk to media organizations and their confidential contacts from targeted cyber threats.

Why it matters: Journalists and news organizations need to review source protection protocols and email security, as compromised accounts can expose sensitive contacts and undermine investigative reporting.

Tracker inference

vulnerabilitiesTracker priority: TrackCVE-2026-84414

IBM security advisory (AV26-997)

Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.

IBM has disclosed vulnerabilities affecting DataStage on Cloud Pak for Data version 5.4.0.0, Guardium Data Protection version 12.2, and IBM i versions 7.3 through 7.6. The IBM i vulnerability involves incorrect permission assignment in the Network Authentication Service. IBM recommends that administrators review advisories and deploy available updates.

Why it matters: Organizations running IBM i, DataStage, or Guardium Data Protection should check IBM's security advisories and patch schedules to close exposures in authentication and data protection systems.

Tracker inference

threat intel

Alleged dev of Ploutus ATM malware appears in US court after arrest

Source: BleepingComputer.

The U.S. Department of Justice announced the arrest of an individual alleged to have developed Ploutus malware, which was used in jackpotting attacks to steal millions of dollars from ATMs across the United States. The arrest follows years of investigation into the malware's distribution and use in financial crimes.

Why it matters: Financial institutions and ATM operators need to assess whether their systems may have been targeted by Ploutus variants and review transaction logs and security controls to detect and prevent future jackpotting attempts.

Tracker inference

threat intel

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Source: SecurityWeek.

A Linux backdoor named ClingSTUN leverages the STUN protocol to operate as a back-connect proxy, establishes persistence mechanisms, and incorporates exploits for self-propagation across systems.

Why it matters: Linux infrastructure operators need to monitor for ClingSTUN activity, as the backdoor's self-propagation capability and STUN protocol abuse can enable lateral movement and persistent unauthorized access.

Tracker inference

ai security

Need for Speed: AI-Driven Attacks Are Changing Security Strategies

Source: Dark Reading.

Artificial intelligence (AI)-powered attacks are accelerating and operating with increasing automation, prompting security teams to reassess their defensive strategies. A Dark Reading reader poll highlights the urgency of adapting security operations to match the speed and scale of AI-driven threats.

Why it matters: Security practitioners need to evaluate whether current detection and response capabilities can operate at the pace of automated, AI-powered attacks before adversaries outrun their defenses.

Tracker inference

breaches incidents

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Source: SecurityWeek.

Hackers obtained patient information from Clover Health Investments and AngMar Management Services during a breach in July. The incident exposed records for approximately 250,000 individuals across the two healthcare organizations.

Why it matters: Healthcare practitioners and compliance officers need to assess whether their organizations' patient data was among the 250,000 records compromised and begin breach notification and remediation workflows.

Tracker inference

breaches incidents

Hackers Breached Propulsion System of U.S.-Bound Oil Tanker

Source: DataBreaches.net.

FBI and US Coast Guard investigators discovered that hackers compromised the propulsion system of an oil supertanker while it was approaching the Texas coast during summer. The incident demonstrates emerging physical security threats posed by cyberattacks against maritime vessels.

Why it matters: Maritime operators and critical infrastructure owners need to assess propulsion system security immediately, as successful compromise of vessel control systems poses collision, environmental, and safety risks.

Tracker inference

breaches incidents

Daiwa Securities says info on 110,000 clients may have been leaked in vendor incident

Source: DataBreaches.net.

Daiwa Securities, Japan's second-largest brokerage and investment banking firm, disclosed that as many as 110,000 client records may have been compromised in a breach affecting one of its external vendors. The company is investigating the incident and responding to the exposure of client information stored on the vendor's compromised servers.

Why it matters: Clients of Daiwa Securities should monitor accounts and credit for fraud, and the firm must notify affected individuals and regulators under Japan's data protection requirements.

Tracker inference

ransomware

Ransomware group threatens to leak customer data from top insurance companies in South Africa

Source: DataBreaches.net.

The Gentlemen ransomware-as-a-service group has threatened to leak customer data from South African insurance companies LegalWise and Samwumed, with indications that additional organizations may be targeted. The group is among the world's most prolific ransomware operators, responsible for 17% of global ransomware attacks in July.

Why it matters: Insurance customers and policyholders in South Africa face exposure of personal and financial data; insurance companies must assess whether they are targeted and prepare incident response and customer notification.

Tracker inference

ai security

RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models

Source: Help Net Security.

A developer released RemoveMacAI, a free command-line tool that disables Apple's on-device artificial intelligence (AI) features on macOS 27 and removes approximately 12 GB of downloaded AI models from disk. macOS 27 lacks a native toggle for the AI feature, so models persist even after disabling it through settings. The tool addresses this by fully removing the feature and its associated files on Apple silicon Macs.

Why it matters: Users on macOS 27 who want to reclaim storage or disable on-device AI without keeping dormant models need this tool, as the OS provides no built-in way to completely remove the feature and its data.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary