CYBERSECURITYTRACKER
TRACKING4,114 stories770 vuln stories
The watch floor

Everything moving in security, ranked by what matters now.

Reporting is aggregated and cross-verified across multiple authoritative sources. Stories are clustered, de-duplicated, and tagged by category, vendor, and threat actor. Filter to your role, pin your stack, subscribe or point your reader at a feed. No account required.

Skip to latest stories
Presets
Loading feed…
breaches incidents

UK: ICO reprimands ACRO Criminal Records Office after data breach

The UK Information Commissioner's Office (ICO) issued a reprimand to ACRO Criminal Records Office, a national police unit, for violations of data security requirements under the UK General Data Protection Regulation (GDPR). The reprimand cited breaches of Articles 32(1), 32(1)(b), and 32(1)(d), which address technical and organizational security measures. The incident involved a data breach affecting the organization's handling of Police Certificates and International Child Protection Certificates.

Why it matters: Organizations processing sensitive personal data such as criminal records or child protection information must ensure adequate security controls; this case demonstrates that law enforcement agencies face the same GDPR obligations and enforcement action as private sector entities.

breaches incidents

KR: Sogang University data breach exposes 180,000 student, staff accounts

Sogang University in South Korea confirmed a cyberattack that exposed personal information for approximately 180,000 students, alumni, and staff members. The breach involved data linked to the university's integrated login accounts, though the identity of the attacker remains unknown. The university disclosed the incident on Saturday.

Why it matters: South Korean students, alumni, and staff at Sogang University should monitor for credential compromise and identity theft; practitioners managing higher education institutions should review account security and notification protocols.

government policy

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts

CISA released new cybersecurity resources targeting K-12 schools and districts. The announcement coincides with conflicting reports about ransomware trends in education, with one source claiming attacks declined in the first half of 2026 while others highlight growing threats to schools.

Why it matters: K-12 administrators and IT teams need these resources to protect student data and operational continuity; ransomware groups continue to view schools as accessible targets despite fluctuating attack volume.

vulnerabilitiesCVE-2025-3248CVE-2025-68613

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable's Research Special Operations team is tracking a cluster of seven agentic AI incidents since July 2026, anchored by Taiwan's confirmed August 2026 attack in which autonomous AI agents mapped 21 government systems, compromised 85 accounts, and exfiltrated 2,564 personnel records in four days. The cluster also includes JADEPUFFER (which exploited CVE-2025-3248 in Langflow for database extortion) and knaithe/KnYuan (a Chinese-speaking operator using the same AI agent framework for autonomous vulnerability scanning), demonstrating that the capability to deploy autonomous offensive AI has shifted from theoretical to operational and is accessible to solo operators. The common exploitation vector across all incidents is identity and authentication exposure: discoverable federation endpoints, weak credentials, and misconfigured SSO (single sign-on) systems that autonomous agents can traverse at machine speed without human direction between each action.

Why it matters: Any organization running centralized authentication (OAuth, OpenID Connect, SAML, Keycloak) or hosting developer documentation on public platforms exposes the same discoverable attack surface Taiwan's agents exploited; organizations deploying their own AI agents face governance gaps (purpose limitation, kill-switch, network isolation) that create insider risk comparable to the external threat; defenders must shift from CVE-centric models to behavioral detection of automated reconnaissance and credential campaigns, because the exposure is the entire discoverable attack surface, not a single patched vulnerability.

ai security

How Anthropic plans to watermark Claude's AI-generated text

Anthropic is developing a watermarking technique to identify text generated by its Claude AI model. The approach aims to provide a technical method for detecting AI-generated content beyond obvious stylistic patterns.

Why it matters: Security teams and content moderators need reliable detection tools as AI-generated text becomes harder to distinguish from human writing; watermarking could help identify synthetic content in phishing, misinformation, and social engineering campaigns.

government policy

New York City Lawmakers Push to ‘Ban the Scan’ at MSG

New York City lawmakers, musicians, and privacy advocates held a press conference outside Madison Square Garden to call for stricter limits on biometric surveillance deployment at public venues. The effort, described as 'Ban the Scan,' seeks to restrict how venues collect and use facial recognition and other biometric data.

Why it matters: Venue operators and security teams should monitor this advocacy movement, as passage of such restrictions could limit biometric authentication and identification tools at entertainment and public gathering spaces.

vulnerabilitiesCVE-2025-49132CVE-2026-15409

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Metasploit Framework 6.5 released with 13 new exploit modules targeting remote code execution vulnerabilities in WordPress, Ghost CMS, Joomla, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, and a Linux kernel privilege escalation. The release also introduces HTTP malleable C2 profiles for Meterpreter payloads, Model Context Protocol (MCP) functionality, Windows ARM (AArch64) reverse shells, and numerous bug fixes and enhancements.

Why it matters: Red teamers and penetration testers gain immediate access to working exploits for recently disclosed vulnerabilities affecting widely deployed platforms; defenders and system administrators should patch the affected applications urgently to prevent exploitation of these remote code execution flaws.

breaches incidents

Investigation of banking hack leads to arrests in Germany, Brazil

Germany's federal police agency (BKA) arrested three suspects in Europe on fraud charges related to a banking hack investigation. Brazil's federal police simultaneously arrested four additional suspects on similar charges stemming from the same incident.

Why it matters: Financial services practitioners and fraud prevention teams need to monitor this case for indicators of compromise affecting their customer base and coordinate with law enforcement regarding potential exposure.

industry

Mission-Driven Security: Inside a Global Bank's Defense

Standard Chartered's group Chief Information Security Officer discusses the shift from technical to strategic leadership roles in security, the value of business acumen among security executives, and how artificial intelligence is transforming both defensive measures and attacker techniques in the banking sector.

Why it matters: Banking security leaders should understand how peer institutions are balancing technical expertise with business strategy, and how AI is reshaping their threat landscape and defense priorities.

ot ics

What we know about the alleged Iranian hacks on US water utilities

Hackers have targeted and breached multiple US water utility systems in recent weeks, with allegations pointing to Iranian government involvement. The incident represents a wave of coordinated attacks on critical water infrastructure.

Why it matters: Water utility operators and federal agencies overseeing critical infrastructure must immediately assess their exposure to similar attacks and coordinate incident response, as nation-state actors targeting water systems pose direct public health and safety risks.

vulnerabilitiesCVE-2026-65400

Vulnerability giving attackers full control of Macs is under active exploitation

A high-severity macOS vulnerability (CVE-2026-65400) in the screen sharing feature allows remote code execution with root privileges and is currently being exploited in the wild. The Netherlands National Cyber Security Centrum reported active abuse on systems with port 5900 exposed to the internet, where attackers installed Monero crypto miners after gaining access. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week.

Why it matters: Mac users with screen sharing enabled and port 5900 exposed need to patch immediately; attackers are actively deploying crypto miners and establishing root access on vulnerable systems.

breaches incidents

Hackers arrested over €30M bank fraud exploiting service provider flaw

Four cybercriminals were arrested in Brazil and three others were charged in Europe for exploiting a vulnerability at a service provider to fraudulently withdraw funds from Commerzbank customer accounts. The scheme resulted in approximately 30 million euros in losses.

Why it matters: Banks and their customers face exposure when service provider vulnerabilities go unpatched; practitioners should review vendor vulnerability disclosures and assess whether their own service providers have similar flaws.

ai security

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Vulnerability discovery rates are accelerating as AI-augmented tools enable researchers to find more flaws at scale. The National Institute of Standards and Technology (NIST) is exploring whether AI could help manage this growing volume of disclosures and remediation demands.

Why it matters: Security teams face expanding vulnerability backlogs driven by AI-enhanced scanning, making prioritization and patch planning increasingly difficult; NIST's inquiry signals the industry may need new AI-assisted approaches to triage and response.

Upcoming Speaking Engagements

This article lists the author's upcoming speaking engagements at various conferences and events across North America between September and October 2026, including appearances at LAcon V, Elevate Festival, CanSecWest, and other venues. The piece provides dates, locations, and formats for each scheduled talk and panel participation.

Why it matters: Practitioners seeking to attend cybersecurity conferences or connect with industry speakers should note these event dates and locations for planning purposes.

breaches incidents

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office

The Scottish Government's Prosecutor's Office experienced a data breach involving a third party vendor. The vendor's compromise may have extended access to other government agencies, potentially widening the scope of the incident.

Why it matters: Scottish Government staff, justice sector partners, and citizens whose data is held by prosecutors face exposure; practitioners should assess whether their organization uses the same third party vendor and verify their own access logs.

vulnerabilities

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The Netherlands' National Cyber Security Centre (NCSC) warns that a macOS authentication bypass vulnerability is under active exploitation following the release of public exploit code. Attackers are using the flaw in Screen Sharing to deploy Monero cryptocurrency miners on affected systems.

Why it matters: macOS users and system administrators need to patch immediately, as this vulnerability enables unauthenticated remote code execution that directly leads to cryptominer installation and resource theft.

cloud saasResearch

Wiz on Wiz: How the Wiz FinOps Team Uses Wiz Cloud Cost

Wiz published a case study on how its own FinOps team uses Wiz Cloud Cost for cost investigation and optimization. The article demonstrates the platform's capabilities through internal use, focusing on cost visibility with cloud context.

Why it matters: Cloud security practitioners evaluating cost management tools should understand how Wiz's own platform performs in practice, though this is a vendor showcase rather than independent validation.

cloud saas

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks can exploit multiple vectors beyond phishing, including stolen OAuth tokens that grant access to Gmail, Drive, and connected services. Organizations require comprehensive security strategies that address the full attack surface rather than relying on single-point defenses.

Why it matters: Security teams managing Google Workspace deployments need to assess whether their defenses cover token theft and compromise, not just email-based attacks, to reduce the risk of account takeover and data exfiltration.

regulatory

What Boards Need to Know About Tech Risk

A brief question appears to ask why boards often underestimate technology risk until crises occur, but the article text offers no substantive analysis, findings, or guidance to address the question.

Why it matters: Board members and executives deciding whether to increase security investment budgets or governance frameworks will find no actionable data or trend analysis here.

vulnerabilities

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched three days prior is already facing active exploitation, according to Defused threat intelligence. The flaw allows attackers to execute arbitrary code on affected systems.

Why it matters: Organizations running SAP Commerce Cloud must apply the patch immediately if not already done, as active attacks confirm the vulnerability is now a critical priority for deployment teams.

See the daily change brief for what changed since the previous snapshot. Looking further back? Browse the daily archive, this feed's own history.