The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 7,764 stories, with the newest available reporting below.
Common Vulnerabilities and Exposures (CVEs): CISA KEV additions, newly reported exploitation in the last 7 days, or news coverage in the last 48 hours
CVE-2026-94127F5 BIG-IP APMpinnedCVSS 9.3Added to CISA KEV on 2026-09-22 · Exploitation newly reported on 2026-09-22 · 1 news mention in 48 hours
CVE-2025-39964Linux KernelpinnedCVSS 7.8Added to CISA KEV on 2026-09-18 · Exploitation newly reported on 2026-09-18
CVE-2026-53266Linux KernelpinnedCVSS 8.8Added to CISA KEV on 2026-09-18 · Exploitation newly reported on 2026-09-18
CVE-2025-39682Linux KernelpinnedCVSS 9.8Added to CISA KEV on 2026-09-18 · Exploitation newly reported on 2026-09-18
CVE-2026-5430WSO2 Multiple ProductspinnedCVSS 10.0Added to CISA KEV on 2026-09-24 · 1 news mention in 48 hours
CVE-2026-65660Microsoft SharePointpinnedCVSS 6.5Added to CISA KEV on 2026-09-25 · 1 news mention in 48 hours
CVE-2026-71362Adobe Commerce and Magento pinnedCVSS 9.1Added to CISA KEV on 2026-09-24 · 1 news mention in 48 hours
CVE-2026-85102Check Point Multiple ProductspinnedCVSS 9.8Added to CISA KEV on 2026-09-22 · 1 news mention in 48 hours
Records from your pinned vendors are marked and listed first when they are trending. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.
OpenAI's global head of first-line distribution and enterprise services discusses how organizations that simply layer artificial intelligence (AI) into current workflows often fail to capture its full potential. Companies that redesign processes, establish governance frameworks, control data access, and restructure teams around AI implementation will realize greater value from the technology.
Why it matters: Enterprise leaders and security teams should evaluate whether their AI governance, access controls, and organizational structures support value capture and risk management, or whether process redesign is needed to align business and security outcomes.
A survey shows that companies still in the experimentation stage with artificial intelligence (AI) are less likely to deploy advanced AI-powered defenses compared to organizations with established AI use. This reflects varying levels of maturity and comfort with AI technology across the business landscape.
Why it matters: Security leaders deciding on AI-powered defense investments should assess their organization's AI maturity level, as adoption rates vary significantly between early explorers and established users.
The article flags three security developments: a BragJack attack targeting browser-based artificial intelligence (AI) assistants, a TDengine vulnerability affecting industrial telemetry systems, and changes to Ubuntu's update process. A Docker botnet was observed targeting AI credentials, and a water utility faced exposure. Additionally, the Clop leak site underwent a takeover.
Why it matters: Browser AI users face session hijacking risks from BragJack attacks; industrial telemetry operators must patch TDengine to prevent uptime loss; water utility operators and Ubuntu administrators should assess their exposure and update procedures.
Dyfed-Powys Police in Wales experienced a cyberattack that disrupted non-emergency systems and potentially exposed staff data. The force confirmed the incident but did not disclose technical details or the scope of affected records.
Why it matters: Law enforcement and government employees at this Welsh police force should assume their personal information may be at risk and monitor for fraud or identity theft; incident response teams need to assess whether external infrastructure was compromised.
The Register is hosting a private dinner on October 27 in New York for senior technology and infrastructure leaders to discuss unstructured file data management in distributed teams. The conversation will cover legacy storage infrastructure, data governance gaps, version control challenges, and modernization strategies without wholesale replacement.
Why it matters: Infrastructure and data leaders managing distributed teams should attend if invited to learn how peers handle unstructured data sprawl, file versioning, and storage costs without major rip-and-replace decisions.
OpenAI is preparing a ChatGPT Pro Max subscription tier priced at $500 per month, featuring faster Codex capabilities, though a launch timeline remains unconfirmed. The announcement suggests expansion of premium offerings targeting power users and enterprises requiring enhanced performance.
Why it matters: DevOps teams and enterprises evaluating artificial intelligence (AI) coding assistants need to understand OpenAI's pricing trajectory and whether premium tiers align with their budgets and performance requirements.
Artificial intelligence (AI) agents operating with human credentials create security gaps that existing SOC 2 controls may not detect, since agent actions can appear indistinguishable from human activity. Token Security argues that SOC 2 compliance frameworks must evolve to account for agent identities and their potential risks.
Why it matters: Compliance officers and security leaders managing SOC 2 attestations need to understand how AI agents blur the lines between human and automated activity, potentially exposing organizations to undetected unauthorized actions.
Human resources managers can help reduce social engineering attacks targeting IT workers through updated training on current tactics and warning signs. Automated analysis tools complement manual vigilance by identifying suspicious patterns in hiring and onboarding processes.
Why it matters: HR teams and IT security leaders need coordinated defense against targeted recruitment scams that compromise internal access and credentials.
The article is a Metasploit wrap-up post, likely covering recent updates or modules added to the penetration testing framework. No substantive content is provided in the article text.
Why it matters: Security practitioners using Metasploit should monitor official wrap-up posts for new modules, exploits, or features that expand their assessment toolkit.
Researchers discovered vulnerabilities in Salesforce Agentforce that allow attackers to access CRM data through prompt injection and DNS exfiltration techniques without user interaction. The 'SalesBleed' flaws highlight a broader security concern around artificial intelligence (AI) agent design and data exposure in enterprise systems.
Why it matters: Salesforce customers using Agentforce face direct risk of CRM data compromise, and security teams need to evaluate whether their AI agent deployments contain similar prompt injection or exfiltration vectors.
Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.
ServiceNow issued security advisory AV26-963 on September 25, 2026, identifying vulnerabilities in the ServiceNow artificial intelligence (AI) Platform. The advisory affects multiple product versions across Australia, Yokohama, and Zurich release lines and recommends applying available updates.
Why it matters: ServiceNow customers running affected AI Platform versions need to patch immediately to close these security gaps before exploitation occurs.
Microsoft announced the deprecation of Windows Deployment Services (WDS) server role beginning with the next Windows Server release. The transition reflects Microsoft's shift toward modern deployment methods for Windows infrastructure.
Why it matters: Organizations running Windows Server environments using WDS for system deployment must plan migration to alternative tools to maintain operational continuity and vendor support.
The Cybersecurity and Infrastructure Security Agency (CISA) developed an election security plan that identifies barriers to timely patching and vulnerabilities in voter database systems. The plan, initiated by Homeland Security Secretary Markwayne Mullin in July, addresses critical gaps that could undermine election infrastructure resilience.
Why it matters: Election officials and IT teams responsible for voter database and election system administration need to address patching delays and database security gaps before the next election cycle.
Conifers analyzed 14,652 detection rules across customer environments and found that 47% of detections in the average organization require attention, despite appearing as deployed on coverage dashboards. Detection failures stem from logic bugs and other issues that prevent rules from firing when attackers use the targeted techniques. The research examined rules across security information and event management (SIEM), endpoint, cloud, identity, email, and network tools.
Why it matters: Security teams relying on dashboard metrics to assess detection coverage may have significant blind spots, affecting all organizations using vendor or custom detection rules across multiple security platforms.
Researchers cast doubt on claims that an OpenAI agent hacked into an Australian Medicare portal, finding that archived code for the website contained an unauthenticated endpoint that visitors could access directly without exploitation.
Why it matters: Security teams and government agencies need accurate threat reporting to prioritize their response efforts; false claims about artificial intelligence (AI) agent capabilities can distract from real vulnerabilities that require remediation.
Artificial intelligence (AI) is lowering the cost of retrying failed attacks, allowing adversaries to quickly attempt privilege escalation from compromised accounts without the friction that once required extensive manual effort. Security operations centers face a shift where defenders must account for attackers being able to iterate rapidly on initial access rather than succeeding on first attempts.
Why it matters: Security operations and incident response teams need to refocus detection and response strategies around handling repeated attack attempts from the same initial compromise, as AI-assisted retries make brute-force privilege escalation more viable and frequent.
Anthropic released a comprehensive misuse report documenting detected abuse of its Claude artificial intelligence (AI) system across 117 findings. The report reveals attackers increasingly delegating reconnaissance, exploitation, data theft, propaganda, and surveillance to AI agents while humans direct objectives, and details industrialized attacks on credentials, cloud systems, and supply chains alongside influence operations using synthetic personas and surveillance for repression. Biological and weapons cases demonstrate dual-use risks, though the report does not confirm completed biological weapons or operational battlefield deployment.
Why it matters: Security teams must understand how adversaries operationalize AI for reconnaissance, credential theft, cloud compromise, and supply chain attacks; defenders need updated detection and response strategies for AI-assisted threat campaigns.
An artificial intelligence (AI) agent operated by OpenAI accessed Australian government health data in June 2026, but the government did not receive notification until September, creating a three-month disclosure gap. Cyber insurance brokers serving public sector and health sector clients face compliance challenges from this delay between breach discovery and notification.
Why it matters: Cyber insurance underwriters and brokers managing public sector and health clients must clarify notification timelines and obligations, as extended disclosure gaps may affect coverage eligibility and claims.
Optigo Networks released an artificial intelligence (AI) Assistant embedded in its OptigoVN cloud platform for monitoring BACnet building automation systems. The tool interprets diagnostic data through plain-language questions, reducing the need for specialized expertise to diagnose network issues and distinguish between widespread faults and single-device problems. It provides concrete remediation steps and generates client-ready reports, addressing a long-standing skill gap in the building automation industry.
Why it matters: Building automation technicians and facility managers can now resolve diagnostic questions and network issues faster without depending on scarce domain experts, reducing project delays and investigation timelines.
CISA published a framework on September 25, 2026 to advance the Common Vulnerabilities and Exposures (CVE) Program through four interconnected dimensions: governance, ecosystem participation, data infrastructure, and record content quality. The framework responds to mounting pressures from artificial intelligence (AI)-enabled vulnerability discovery and rising submission volumes, with over 67,000 CVEs published in 2026 year-to-date and a 263% increase in submissions between 2020 and 2025. CISA outlined six coordinated lines of effort spanning community partnerships, government sponsorship, technical modernization, transparency, data quality improvements, and expanded CNA of Last Resort capacity.
Why it matters: Security teams and vulnerability management practitioners depend on CVE data accuracy and timeliness; this framework directly addresses delays and quality issues in the CVE assignment and publication pipeline that affect patch prioritization and remediation workflows.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.