CYBERSECURITYTRACKER
TRACKING4,101 stories767 vuln stories
The watch floor

Everything moving in security, ranked by what matters now.

Reporting is aggregated and cross-verified across multiple authoritative sources. Stories are clustered, de-duplicated, and tagged by category, vendor, and threat actor. Filter to your role, pin your stack, subscribe or point your reader at a feed. No account required.

Skip to latest stories
Presets
Loading feed…

Upcoming Speaking Engagements

This article lists the author's upcoming speaking engagements at various conferences and events across North America between September and October 2026, including appearances at LAcon V, Elevate Festival, CanSecWest, and other venues. The piece provides dates, locations, and formats for each scheduled talk and panel participation.

Why it matters: Practitioners seeking to attend cybersecurity conferences or connect with industry speakers should note these event dates and locations for planning purposes.

breaches incidents

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office

The Scottish Government's Prosecutor's Office experienced a data breach involving a third party vendor. The vendor's compromise may have extended access to other government agencies, potentially widening the scope of the incident.

Why it matters: Scottish Government staff, justice sector partners, and citizens whose data is held by prosecutors face exposure; practitioners should assess whether their organization uses the same third party vendor and verify their own access logs.

vulnerabilities

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The Netherlands' National Cyber Security Centre (NCSC) warns that a macOS authentication bypass vulnerability is under active exploitation following the release of public exploit code. Attackers are using the flaw in Screen Sharing to deploy Monero cryptocurrency miners on affected systems.

Why it matters: macOS users and system administrators need to patch immediately, as this vulnerability enables unauthenticated remote code execution that directly leads to cryptominer installation and resource theft.

cloud saasResearch

Wiz on Wiz: How the Wiz FinOps Team Uses Wiz Cloud Cost

Wiz published a case study on how its own FinOps team uses Wiz Cloud Cost for cost investigation and optimization. The article demonstrates the platform's capabilities through internal use, focusing on cost visibility with cloud context.

Why it matters: Cloud security practitioners evaluating cost management tools should understand how Wiz's own platform performs in practice, though this is a vendor showcase rather than independent validation.

cloud saas

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks can exploit multiple vectors beyond phishing, including stolen OAuth tokens that grant access to Gmail, Drive, and connected services. Organizations require comprehensive security strategies that address the full attack surface rather than relying on single-point defenses.

Why it matters: Security teams managing Google Workspace deployments need to assess whether their defenses cover token theft and compromise, not just email-based attacks, to reduce the risk of account takeover and data exfiltration.

regulatory

What Boards Need to Know About Tech Risk

A brief question appears to ask why boards often underestimate technology risk until crises occur, but the article text offers no substantive analysis, findings, or guidance to address the question.

Why it matters: Board members and executives deciding whether to increase security investment budgets or governance frameworks will find no actionable data or trend analysis here.

vulnerabilities

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched three days prior is already facing active exploitation, according to Defused threat intelligence. The flaw allows attackers to execute arbitrary code on affected systems.

Why it matters: Organizations running SAP Commerce Cloud must apply the patch immediately if not already done, as active attacks confirm the vulnerability is now a critical priority for deployment teams.

government policy

US courts will start publishing how often the government uses spyware

The Administrative Office of the U.S. Courts announced it will begin publishing data on how frequently judges approve government spyware use for wiretapping suspects. This marks an increase in transparency around surveillance tool authorization.

Why it matters: Government and civil rights stakeholders need visibility into spyware authorization trends to assess potential abuse and inform oversight discussions.

breaches incidents2 sources

France investigates tax authority breach after hacker claims 600,000 victims

French authorities confirmed unauthorized access to systems at the Directorate General of Public Finances in late June. A threat actor claims to have affected approximately 600,000 individuals through the compromise.

Why it matters: French taxpayers and residents whose data may be held by the tax authority are exposed to identity theft and fraud; practitioners managing government agency security should assess whether similar access pathways exist in their environments.

Grouped because: title similarity 100

breaches incidents

NHS admits data breach by sending patient data via pagers

The NHS acknowledged a data breach in which sensitive medical information on transplant patients, including names, dates of birth, and organ types, was transmitted over unencrypted pager networks. A BBC investigation uncovered the practice of routinely sending this personal data through an insecure communication channel.

Why it matters: NHS transplant patients and healthcare organizations face exposure of personally identifiable and medical information; practitioners should review whether their organizations use legacy unencrypted devices for sensitive communications and implement secure alternatives.

ai securityResearch

Securing Data in the AI era

Artificial intelligence (AI) is altering the data security landscape, requiring organizations to gain visibility into their connected systems, exposed assets, and underlying risk drivers.

Why it matters: Security practitioners need to reassess data protection strategies as AI adoption changes threat vectors and exposure scope across enterprise infrastructure.

industry

Cyera's Oasis Security Buy Is All About AI Agent Control

Cyera has acquired Oasis Security in a $1 billion deal designed to unify data security and identity management into a single control plane for AI agents. The combined offering redefines privileged access by anchoring it to business context instead of traditional static role-based models.

Why it matters: Security leaders responsible for AI deployments and identity governance need to track how vendors are architecting access controls for autonomous agents, as this represents a shift in how privilege is managed in AI-driven environments.

industry

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

A brief roundup covers multiple security incidents including layoffs at Rapid7, vulnerabilities in refrigeration systems, a North Korean IT worker breaching a federal agency, and a DEF CON attendee's involvement in a Delta flight disruption. The stories also mention a government AI platform deal and aerospace security concerns related to Boeing aircraft.

Why it matters: Organizations using Rapid7 tools should monitor for service continuity; federal agencies need to review hiring and vetting practices after the North Korean breach; airlines and aerospace manufacturers must address authentication and supply chain risks; and conference attendees should understand legal boundaries for security research.

ransomware

Shell investigates 'potential incident' after Clop data theft claims

Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data from the company. The investigation is ongoing to confirm the scope and nature of the breach.

Why it matters: Oil and gas sector practitioners and organizations with supply chain links to Shell should monitor for indicators of compromise and assess exposure to potential data leaks or operational disruptions.

vulnerabilities

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

A compromise affecting approximately 2,500 organizations was primarily driven by a Trivy vulnerability rather than malicious LiteLLM packages as initially suspected. The majority of affected companies experienced exposure before the LiteLLM packages containing malicious code were released.

Why it matters: Organizations using Trivy and LiteLLM need to assess their exposure timeline and prioritize patching Trivy to prevent future exploitation of the underlying vulnerability.

threat intel

Who’s Tracking You? Use This New Service to Find Out

DecryptAds, a new free service launched by security researchers, aggregates publicly available adtech configuration files (ads.txt, app-ads.txt, and sellers.json) to reveal which companies track users and serve ads across websites and mobile applications. The tool identifies concerning patterns including advertising partners based in geopolitical risk areas like Russia and China, potential conflicts of interest where firms act as both publisher and reseller, and connections to AI-generated content farms that lack protective measures against malicious ads. DecryptAds also features a quiet removals feed that tracks when ad networks silently delist suspicious partners without public disclosure.

Why it matters: Security practitioners and organizations should use DecryptAds to audit their own web properties and identify third-party adtech risks, geopolitical exposures, and potential malvertising vectors; defenders should understand that malicious ads increasingly target lower-quality AI content farms rather than major sites, and that supply chain visibility in adtech remains fragmented because ad networks do not broadly share structured data needed to trace malware delivery.

threat intel

New Android malware relays bank cards to fraudsters while victims still hold them

Group-IB researchers disclosed WindRelay, a new Android malware that captures payment card data via NFC (Near Field Communication) and transmits it to attackers in real time. The malware pairs with SpyNote, a remote access trojan, to give attackers control over the victim's device. The attack begins with a fraudulent phone call claiming to be from the victim's bank.

Why it matters: Android users and financial institutions face exposure to real-time card theft while victims hold their phones; practitioners should monitor for WindRelay and SpyNote distribution and alert customers to avoid answering unsolicited calls from purported banks.

government policy

If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them

An opinion essay argues that if OpenAI and Anthropic fail to achieve profitability in the markets, the US government should nationalize them and operate them as public agencies for AI research and development. The authors contend that frontier AI models are expensive to train, depreciate quickly, compete with free open-source alternatives, and lack sustainable business models, while their technical talent and products remain valuable to society. They propose restructuring these companies into government-operated labs similar to national research institutions, with separate governance for innovation and compute operations, potentially modeled after existing public utilities and international precedents.

Why it matters: Enterprise and government decision-makers should monitor the financial viability debates around major AI labs, as policy shifts toward public ownership could affect access, pricing, licensing, and governance of frontier AI models they depend on or compete against.

cloud saas

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

Google Cloud has announced a roadmap to achieve post-quantum cryptography readiness by 2029, with intermediate milestones planned for 2027 and 2028. The timeline addresses the anticipated threat from quantum computing to current encryption standards.

Why it matters: Cloud infrastructure operators and security teams relying on Google Cloud services need to track this roadmap and plan their own cryptographic transitions to remain protected against future quantum-enabled attacks.

ai security

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode

OpenAI released GPT-5.6 Sol with an Ultrafast mode powered by Cerebras, delivering up to 14 times faster processing and 750 output tokens per second compared to standard processing. The feature entered limited preview through the OpenAI API for select customers.

Why it matters: Developers and organizations using OpenAI's API should evaluate whether faster inference speeds enable new use cases or reduce operational costs for their applications.

Looking further back? Browse the daily archive, this feed's own history.