The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 8,289 stories, with the newest available reporting below.
Common Vulnerabilities and Exposures (CVEs): CISA KEV additions, newly reported exploitation in the last 7 days, or news coverage in the last 48 hours
CVE-2026-88779Citrix NetScalerpinnedCVSS 8.7Added to CISA KEV on 2026-10-04 · Exploitation newly reported on 2026-10-04 · 2 news mentions in 48 hours
CVE-2026-104286Fortinet FortiMailpinnedCVSS 9.8Added to CISA KEV on 2026-10-01 · Exploitation newly reported on 2026-10-01
CVE-2026-86950Apple Multiple ProductspinnedCVSS 8.8Added to CISA KEV on 2026-09-29 · 1 news mention in 48 hours
CVE-2026-76504Cisco Catalyst SD-WAN ManagerpinnedCVSS 9.8Added to CISA KEV on 2026-09-30 · 1 news mention in 48 hours
CVE-2026-102490Zammad GmbH ZammadpinnedCVSS 9.4Added to CISA KEV on 2026-10-02
CVE-2026-102489Zammad GmbH ZammadpinnedCVSS 9.4Added to CISA KEV on 2026-10-02
CVE-2026-88772Citrix NetScalerpinnedCVSS 9.52 news mentions in 48 hours
CVE-2026-88771Citrix NetScalerpinnedCVSS 9.52 news mentions in 48 hours
Records from your pinned vendors are marked and listed first when they are trending. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.
ClingSTUN malware exploits known vulnerabilities in unpatched Internet of Things (IoT) devices and abuses public Session Traversal Utilities for Network Address Translation (STUN) servers to establish and maintain persistent proxy access to infected devices. This technique allows attackers to use compromised IoT hardware as intermediate nodes for network traffic tunneling and other malicious activities.
Why it matters: Organizations operating unpatched IoT devices face immediate risk of exploitation and network compromise, as attackers can convert these devices into proxy infrastructure for further attacks or data exfiltration.
South Korea's Financial Services Commission held an emergency meeting after cyberattacks targeted multiple financial institutions in the country. The breaches are suspected to involve artificial intelligence (AI)-powered attack methods, marking a shift in sophistication for threat actors operating in the region.
Why it matters: Financial institutions and their customers in South Korea face exposure to account compromise and fraud; practitioners should assess whether AI-enhanced attack techniques are emerging in their threat landscape and update detection rules accordingly.
Tracker inference
threat intelResearchTracker priority: ActCVE-2026-76504CVE-2026-86950+3 more
A threat intelligence bulletin covering the week of October 5 reported breaches at Arizona's state court system, Japanese car-sharing service Times Car, and Polish invoicing platform Fakturownia, exposing personal data and identity documents. Researchers tracked autonomous artificial intelligence (AI) agents conducting rudimentary hacking attempts, malicious Custom GPTs delivering remote access malware through ClickFix campaigns, and an AI-enabled threat actor automating cloud reconnaissance using compromised Azure principals. Critical vulnerabilities were patched in Citrix NetScaler, Cisco Catalyst SD-WAN Manager, Apple CoreGraphics, and GitLab AI Gateway, with active exploitation confirmed in at least two cases.
Why it matters: Arizona court system users and Foster Care Review Board participants face identity theft risk from exposed personal and case records. Times Car customers with identity documents exposed should monitor for account fraud and identity theft. Fakturownia users storing financial data on the platform need to reset credentials and monitor for unauthorized transactions. Organizations running Citrix NetScaler, Cisco SD-WAN Manager, or GitLab AI Gateway must patch immediately to block active exploitation. Utilities, telecom, government, and education sectors targeted by Warlock ransomware exploiting SharePoint ToolShell should prioritize SharePoint patching and endpoint protection hardening. AI policy experts at US think tanks, universities, and law firms are being socially engineered by TA419 and should implement multifactor authentication (MFA) and security awareness training. Governments, NGOs, and organizations supporting Ukraine are targeted by Star Blizzard phishing campaigns deploying CosmicPulse backdoors.
Cybercriminals are deploying a phishing kit called Milk Dragon on Facebook and TikTok, advertising fake brand discounts to redirect users to phishing sites that harvest payment card details and one-time passwords. Active since October 2025, the campaign has generated 258 phishing pages affecting victims across 66 countries and distinguishes itself through tactics that diverge from typical phishing methods.
Why it matters: E-commerce customers and payment processors need to monitor for these fake discount schemes on social platforms, as the campaign targets financial credentials at scale across multiple geographies and has been operating for a year.
Belarusian Cyber Partisans conducted a two-year espionage operation inside a Russian healthcare network, according to analysis by Russian cybersecurity researchers. The group, typically known for public attacks on government and infrastructure targets, maintained a low-profile presence during the campaign.
Why it matters: Healthcare organizations and Russian entities need to assess whether persistent nation-state groups have established footholds in their networks, as long-dwell compromises can enable data theft or operational disruption.
Dell patched multiple vulnerabilities in Container Storage Modules (CSM) version 1.18.0 and later, which integrate Dell storage systems with Kubernetes and OpenShift platforms. The flaws include authentication and authorization bypasses, privilege escalation, information disclosure, and issues in CSM components and Container Storage Interface (CSI) drivers that could allow attackers to gain administrative access, read sensitive data such as Kubernetes Secrets, manipulate role-based access control (RBAC) configurations, or achieve root-level access to cluster nodes depending on the specific vulnerability and attacker position.
Why it matters: Organizations running Dell CSM in Kubernetes or OpenShift environments must apply the patches immediately to prevent unauthenticated or low-privileged attackers from compromising cluster nodes, stealing secrets, and accessing underlying storage infrastructure.
LTM has launched BlueVerse AgenTraceIQ, a service that combines Rubrik Agent Cloud with governance and managed services to help organizations monitor autonomous artificial intelligence (AI) agents. The offering enables guardrails and reversal of unintended agent actions across critical business environments as part of Rubrik's Project Hourglass partner program.
Why it matters: Organizations deploying autonomous AI agents need monitoring and rollback capabilities to prevent costly or damaging unintended actions in production environments.
Tenfold released two new features in its free Community Edition identity governance tool: shared content governance and real-time event auditing. These additions are available to organizations with under 150 users and support Microsoft 365 management and identity activity investigation.
Why it matters: Teams managing Microsoft 365 environments and identity events can now use these governance and auditing capabilities at no cost, reducing setup friction for smaller organizations.
Stellar Cyber released version 7.0, which integrates artificial intelligence (AI)-powered case triage, measurable security operations center (SOC) workflows, automated response capabilities, and new application programming interfaces (APIs) for security operations. The update transitions from using AI as an analyst assistance tool to a practical operating model for autonomous SOC operations. The release includes deeper investigative evidence features and unified case management across the platform.
Why it matters: SOC teams and security leaders evaluating AI-augmented platforms need to assess whether measurable workflows and automated response features reduce analyst workload and improve incident resolution times in their environment today.
Malwarebytes launched Scam Link Check, a free web tool that analyzes URLs to assess safety and explain associated risks. Users can submit suspicious links from text, email, chat, or social media and receive results with reasoning and recommended actions.
Why it matters: Anyone receiving suspicious URLs via messaging or email can use this tool to assess potential phishing or scam threats before visiting; security-conscious users and organizations may recommend it as a quick pre-visit screening step.
Nikkei, a major Japanese media group, disclosed a cyberattack that compromised an employee email account and potentially exposed journalistic sources. The incident highlights the risk to media organizations and their confidential contacts from targeted cyber threats.
Why it matters: Journalists and news organizations need to review source protection protocols and email security, as compromised accounts can expose sensitive contacts and undermine investigative reporting.
Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.
IBM has disclosed vulnerabilities affecting DataStage on Cloud Pak for Data version 5.4.0.0, Guardium Data Protection version 12.2, and IBM i versions 7.3 through 7.6. The IBM i vulnerability involves incorrect permission assignment in the Network Authentication Service. IBM recommends that administrators review advisories and deploy available updates.
Why it matters: Organizations running IBM i, DataStage, or Guardium Data Protection should check IBM's security advisories and patch schedules to close exposures in authentication and data protection systems.
The U.S. Department of Justice announced the arrest of an individual alleged to have developed Ploutus malware, which was used in jackpotting attacks to steal millions of dollars from ATMs across the United States. The arrest follows years of investigation into the malware's distribution and use in financial crimes.
Why it matters: Financial institutions and ATM operators need to assess whether their systems may have been targeted by Ploutus variants and review transaction logs and security controls to detect and prevent future jackpotting attempts.
A Linux backdoor named ClingSTUN leverages the STUN protocol to operate as a back-connect proxy, establishes persistence mechanisms, and incorporates exploits for self-propagation across systems.
Why it matters: Linux infrastructure operators need to monitor for ClingSTUN activity, as the backdoor's self-propagation capability and STUN protocol abuse can enable lateral movement and persistent unauthorized access.
Artificial intelligence (AI)-powered attacks are accelerating and operating with increasing automation, prompting security teams to reassess their defensive strategies. A Dark Reading reader poll highlights the urgency of adapting security operations to match the speed and scale of AI-driven threats.
Why it matters: Security practitioners need to evaluate whether current detection and response capabilities can operate at the pace of automated, AI-powered attacks before adversaries outrun their defenses.
Hackers obtained patient information from Clover Health Investments and AngMar Management Services during a breach in July. The incident exposed records for approximately 250,000 individuals across the two healthcare organizations.
Why it matters: Healthcare practitioners and compliance officers need to assess whether their organizations' patient data was among the 250,000 records compromised and begin breach notification and remediation workflows.
FBI and US Coast Guard investigators discovered that hackers compromised the propulsion system of an oil supertanker while it was approaching the Texas coast during summer. The incident demonstrates emerging physical security threats posed by cyberattacks against maritime vessels.
Why it matters: Maritime operators and critical infrastructure owners need to assess propulsion system security immediately, as successful compromise of vessel control systems poses collision, environmental, and safety risks.
Daiwa Securities, Japan's second-largest brokerage and investment banking firm, disclosed that as many as 110,000 client records may have been compromised in a breach affecting one of its external vendors. The company is investigating the incident and responding to the exposure of client information stored on the vendor's compromised servers.
Why it matters: Clients of Daiwa Securities should monitor accounts and credit for fraud, and the firm must notify affected individuals and regulators under Japan's data protection requirements.
The Gentlemen ransomware-as-a-service group has threatened to leak customer data from South African insurance companies LegalWise and Samwumed, with indications that additional organizations may be targeted. The group is among the world's most prolific ransomware operators, responsible for 17% of global ransomware attacks in July.
Why it matters: Insurance customers and policyholders in South Africa face exposure of personal and financial data; insurance companies must assess whether they are targeted and prepare incident response and customer notification.
A developer released RemoveMacAI, a free command-line tool that disables Apple's on-device artificial intelligence (AI) features on macOS 27 and removes approximately 12 GB of downloaded AI models from disk. macOS 27 lacks a native toggle for the AI feature, so models persist even after disabling it through settings. The tool addresses this by fully removing the feature and its associated files on Apple silicon Macs.
Why it matters: Users on macOS 27 who want to reclaim storage or disable on-device AI without keeping dormant models need this tool, as the OS provides no built-in way to completely remove the feature and its data.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.