The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 8,401 stories, with the newest available reporting below.
CVE-2014-8361Realtek SDKpinnedCVSS 9.81 news mention in 48 hours
Records from your pinned vendors are marked and listed first when they are trending. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.
A breach of Denmark's Central Register of Persons exposed names, addresses, CPR numbers, and other personal details of 8.8 million residents. The attackers exploited legitimate access credentials from a small company to reach the register. Danish authorities are preparing for a subsequent wave of phishing attacks targeting the exposed population.
Why it matters: Practitioners in Denmark and organizations serving Danish residents should expect targeted phishing campaigns against the 8.8 million affected individuals and prepare incident response, user awareness, and credential monitoring accordingly.
Moody's analysis examines how third-party risk is shifting as financial institutions strengthen banking controls, pushing illicit activity toward trade and commercial relationships. The piece discusses how artificial intelligence (AI) and continuous monitoring are transforming risk detection approaches for enterprises. Organizations need to assess risks beyond their direct business partners as the threat landscape evolves.
Why it matters: Financial services and enterprises managing third-party relationships must expand monitoring scope to detect illicit activity migrating through supply chains and indirect business connections, particularly as regulatory pressure tightens direct banking controls.
Google deployed an artificial intelligence (AI) agent called PageBreak to identify security flaws in its web applications, discovering 500 issues across the portfolio. The tool combines AI-driven testing with deterministic validation to assess risk and prioritize exploitability.
Why it matters: Application security teams should monitor AI-assisted vulnerability discovery methods as a scalable alternative to traditional testing, since automated agents can now identify hundreds of flaws at scale.
Former NSA Director Paul Nakasone stated that a broad restructuring of the National Security Agency around artificial intelligence (AI), China, and cybersecurity is probably necessary to address rapidly evolving threats, but emphasized that success depends on implementation rather than reorganization alone. Nakasone noted that adversaries now exploit network access in an average of 29 minutes, down from hours in 2018, creating pressure on defenders to adopt AI-driven defenses before attackers fully weaponize the technology. He also highlighted staffing challenges, including an aging national security workforce with limited competition for talent against private companies.
Why it matters: Federal security practitioners and policy leaders should track the NSA's organizational changes to understand how U.S. cyber defense priorities are shifting and what new tools and architectures may emerge to address the compressed attack timeline and AI-enabled threats.
SEC Consult published a security advisory disclosing two high-impact vulnerabilities in Paessler PRTG Network Monitor versions before 26.2.120.1449. The affected CVEs are CVE-2026-4637 and CVE-2026-4638, with a patch available in version 26.2.120.1449.
Why it matters: Organizations deploying PRTG Network Monitor must upgrade immediately to patch high-severity vulnerabilities that could expose network monitoring infrastructure to attack.
Trump Mobile suffered a data breach affecting 3,615 customers, with the ransomware-as-a-service group BYOD claiming to have stolen names, email addresses, phone numbers, home addresses, and order details. The attackers reportedly gained initial access through an infostealer targeting a Liberty Mobile employee, and claim the wireless provider did not use multifactor authentication (MFA). Trump Mobile's response and delayed security response suggested a lack of incident response capability, and a second criminal group, EndZone, also claimed responsibility for a contemporaneous breach of the same data.
Why it matters: Mobile virtual network operator (MVNO) customers and partner organizations face supply-chain compromise risk when MVNOs lack MFA and incident response protocols; security leaders should audit their MVNO partners' security posture and verify that vendors handling customer personally identifiable information (PII) maintain proper access controls.
Nick Kakolowski from IANS discusses how artificial intelligence (AI) is affecting Chief Information Security Officer (CISO) budgets and organizational security staffing in a video interview. The conversation covers return on investment (ROI) considerations and shifts in security team composition driven by AI adoption.
Why it matters: CISOs evaluating AI investments need to understand budget implications and team restructuring trends to plan resources and staffing effectively.
CVE-2026-21589 affects multiple Atlassian products including Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye through a pre-authentication arbitrary file read vulnerability in the atlassian-plugins-webresource library. The flaw exploits path traversal via double colon (::) encoding to read sensitive files from the application webroot, including WEB-INF directory contents. When Atlassian Crowd is configured for identity management, attackers can extract Crowd credentials from the crowd.properties file and achieve complete administrative compromise of the Crowd instance and all integrated Atlassian applications.
Why it matters: Organizations running on-premises deployments of Jira, Confluence, Bitbucket, or other affected Atlassian products must patch immediately: hundreds of thousands of instances are exposed to unauthenticated file read and potential account takeover if Crowd is integrated. Security practitioners should prioritize updating to the fixed versions listed (Jira Software 9.12.40, 10.3.26, or 11.3.12; Confluence 9.2.26, 10.2.19; and others) and verify whether Crowd is in use, as the attack chain enables complete administrative access.
A proof-of-concept technique called BigDiskBuster maintains the appearance of Microsoft Defender running while blocking security updates, creating an undetected vulnerability window. The method requires no exploit and operates silently, leaving the service seemingly functional while detection gaps persist.
Why it matters: Organizations relying on Microsoft Defender may believe they are protected when the service is actually running with outdated definitions and patches. Security teams should verify that both Defender itself and its definitions update successfully, not just confirm the service is running.
ASOS acknowledged a data breach after hackers delivered unauthorized push notifications via its mobile application and claimed to have accessed customer data stored in the company's Snowflake environment. The breach was confirmed Tuesday following the unauthorized in-app messages.
Why it matters: ASOS customers face potential exposure of personal data from a cloud platform compromise; practitioners should assess whether their organization processes ASOS data and review Snowflake security configurations for similar risks.
Frontier artificial intelligence (AI) models are accelerating vulnerability discovery at scale, with Microsoft reporting close to 1,000 vulnerabilities in September 2026 alone. Chief information security officers (CISOs) must now balance patching speed with correctness across unprecedented finding volumes, while deploying defense-in-depth controls and tools like Microsoft Baseline Security Mode (BSM) to manage the risk. Microsoft is also collaborating with industry peers to scan and remediate vulnerabilities in critical open-source components before attackers exploit them.
Why it matters: CISOs managing Microsoft and multi-vendor infrastructure face sharply increased patch volumes and shortened exploit windows; they should accelerate patching of critical systems to within 24 hours, allocate resources for triage, deploy AI-powered scanning harnesses, and implement BSM to harden their default posture against the growing threat from AI-assisted exploitation.
South Korean officials report that personal data of at least 68,000 people was exposed across at least seven financial institutions in breaches attributed to a Chinese cybersecurity tool. Investigators believe artificial intelligence (AI) agents were deployed in the attacks against the banks' systems.
Why it matters: South Korean financial services and their customers face exposure of personal data; practitioners at financial institutions should review intrusion detection and access logs for indicators of AI-driven reconnaissance and lateral movement.
LibreOffice announced it will not include artificial intelligence (AI) features in its default configuration, prioritizing user privacy. The open source document editor maker rejected integrating AI capabilities into standard deployments.
Why it matters: Users and administrators adopting LibreOffice can rely on the absence of AI processing by default, avoiding involuntary data transmission or behavioral changes without explicit configuration.
Attackers deployed fake versions of ChatGPT, Gemini, Claude, and Perplexity sites to harvest login credentials and multifactor authentication (MFA) codes from advertising account managers using browser-in-browser attack techniques. The campaign exploits the popularity of these artificial intelligence (AI) services to deceive users into entering sensitive authentication data on fraudulent pages.
Why it matters: Ad account managers and teams using these AI services are at immediate risk of account compromise and unauthorized access to advertising budgets; validate any login prompts and enable strong MFA where available.
Microsoft is blocking .msix and .msixbundle file attachments in Outlook for Windows and Outlook on the Web starting in early to mid-November 2026 to prevent malicious Windows application packages from compromising devices. Administrators can allow these extensions in OwaMailboxPolicy if needed for legitimate business purposes. The action expands Outlook's existing blocked file list, which already includes .py, .ps1, and .cab files.
Why it matters: Exchange Online and New Outlook for Windows users will be unable to receive these attachments by default, potentially disrupting workflows that legitimately use .msix packages for software distribution; administrators must prepare policy changes if their organizations require these file types.
IBM announced an artificial intelligence (AI)-powered vulnerability database that identified hundreds of previously unknown flaws in Java software. The finding highlights gaps in how organizations currently manage their software supply chain security.
Why it matters: Development teams and security leaders need to evaluate whether their vulnerability discovery and remediation processes can keep pace with the volume of issues an AI system can now surface in widely-used components.
Non-technical employees using generative artificial intelligence (AI) tools to build workplace applications, often called citizen coding, can create security vulnerabilities, misconfigurations, and data sprawl if developed without oversight. A five-tier governance framework combining executive strategy, AI governance boards, departmental functional leaders, IT enablement, and community support can allow organizations to permit citizen coding while maintaining security and compliance guardrails. Mandatory security training and peer leadership through department-level AI Functional Leaders help mitigate risks while avoiding counterproductive blanket prohibitions.
Why it matters: Security and IT teams need a governance structure to address shadow AI risks from employee-built applications, as prohibiting citizen coding typically drives development underground and creates unmanaged vulnerabilities in production systems.
Osaka Metropolitan University cancelled classes after a suspected ransomware attack that disrupted its internal network, email, and administrative and academic systems. The university confirmed the outage left critical infrastructure unavailable.
Why it matters: Academic institutions and their students face extended service disruptions and potential data exposure when ransomware compromises core systems; organizations should review incident response and backup protocols.
As organizations deploy autonomous artificial intelligence (AI) agents, security architectures designed for human users and static endpoints face new challenges when AI agents dynamically collaborate and delegate tasks across environments without human intervention. Security teams must treat AI agents as first-class identities with their own permissions and monitoring while addressing five key risks: identity delegation chaining, behavioral drift that obscures compromise from normal variance, tool and protocol abuse, cascading access across compromised agents, and fragmented observability across multi-agent decision paths. Teams can extend existing identity, telemetry, and least-privilege practices into AI agent environments by auditing agent communication paths, enforcing task-scoped temporary credentials, standardizing inter-agent telemetry, and integrating agent event streams into security information and event management (SIEM) and behavioral analytics platforms.
Why it matters: Security leaders deploying AI agents must redesign monitoring and access controls now to prevent agents from becoming vectors for data exfiltration, privilege escalation, or prompt injection attacks before autonomous agent adoption scales beyond current visibility and governance capabilities.
Tracker inference
vulnerabilitiesResearchCVE-2026-77050CVE-2026-84429+2 more
Django released security patches addressing four vulnerabilities identified as CVE-2026-77050, CVE-2026-84429, CVE-2026-87890, and CVE-2026-87975. The announcement was posted on October 6, 2026, with links to the official advisory and CVE records for each issue.
Why it matters: Django developers and maintainers must apply these patches to prevent potential exploitation of affected applications in production environments.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.