CYBERSECURITYTRACKER
TRACKING8,401 stories in this site build1,917 vulnerability news stories in this site build

State now. Changed: +1333 tier promotions, 0 known-exploited vulnerability additions, 31 leak-site claims, and 2 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 8,401 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
breaches incidents

Denmark Braces for Wave of Phishing Attacks

Source: HealthcareInfoSecurity.

A breach of Denmark's Central Register of Persons exposed names, addresses, CPR numbers, and other personal details of 8.8 million residents. The attackers exploited legitimate access credentials from a small company to reach the register. Danish authorities are preparing for a subsequent wave of phishing attacks targeting the exposed population.

Why it matters: Practitioners in Denmark and organizations serving Danish residents should expect targeted phishing campaigns against the 8.8 million affected individuals and prepare incident response, user awareness, and credential monitoring accordingly.

Tracker inference

threat intel

Connected Data Exposes Hidden Third-Party Risk

Source: HealthcareInfoSecurity.

Moody's analysis examines how third-party risk is shifting as financial institutions strengthen banking controls, pushing illicit activity toward trade and commercial relationships. The piece discusses how artificial intelligence (AI) and continuous monitoring are transforming risk detection approaches for enterprises. Organizations need to assess risks beyond their direct business partners as the threat landscape evolves.

Why it matters: Financial services and enterprises managing third-party relationships must expand monitoring scope to detect illicit activity migrating through supply chains and indirect business connections, particularly as regulatory pressure tightens direct banking controls.

Tracker inference

ai security

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Source: Dark Reading.

Google deployed an artificial intelligence (AI) agent called PageBreak to identify security flaws in its web applications, discovering 500 issues across the portfolio. The tool combines AI-driven testing with deterministic validation to assess risk and prioritize exploitability.

Why it matters: Application security teams should monitor AI-assisted vulnerability discovery methods as a scalable alternative to traditional testing, since automated agents can now identify hundreds of flaws at scale.

Tracker inference

government policy

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Source: CyberScoop.

Former NSA Director Paul Nakasone stated that a broad restructuring of the National Security Agency around artificial intelligence (AI), China, and cybersecurity is probably necessary to address rapidly evolving threats, but emphasized that success depends on implementation rather than reorganization alone. Nakasone noted that adversaries now exploit network access in an average of 29 minutes, down from hours in 2018, creating pressure on defenders to adopt AI-driven defenses before attackers fully weaponize the technology. He also highlighted staffing challenges, including an aging national security workforce with limited competition for talent against private companies.

Why it matters: Federal security practitioners and policy leaders should track the NSA's organizational changes to understand how U.S. cyber defense priorities are shifting and what new tools and architectures may emerge to address the compressed attack timeline and AI-enabled threats.

Tracker inference

vulnerabilitiesResearchCVE-2026-4637CVE-2026-4638

SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638

Source: Full Disclosure.

SEC Consult published a security advisory disclosing two high-impact vulnerabilities in Paessler PRTG Network Monitor versions before 26.2.120.1449. The affected CVEs are CVE-2026-4637 and CVE-2026-4638, with a patch available in version 26.2.120.1449.

Why it matters: Organizations deploying PRTG Network Monitor must upgrade immediately to patch high-severity vulnerabilities that could expose network monitoring infrastructure to attack.

Tracker inference

breaches incidents

Trump Mobile customers' data dumped - and some never even received their gold device

Source: The Register Security.

Trump Mobile suffered a data breach affecting 3,615 customers, with the ransomware-as-a-service group BYOD claiming to have stolen names, email addresses, phone numbers, home addresses, and order details. The attackers reportedly gained initial access through an infostealer targeting a Liberty Mobile employee, and claim the wireless provider did not use multifactor authentication (MFA). Trump Mobile's response and delayed security response suggested a lack of incident response capability, and a second criminal group, EndZone, also claimed responsibility for a contemporaneous breach of the same data.

Why it matters: Mobile virtual network operator (MVNO) customers and partner organizations face supply-chain compromise risk when MVNOs lack MFA and incident response protocols; security leaders should audit their MVNO partners' security posture and verify that vendors handling customer personally identifiable information (PII) maintain proper access controls.

Tracker inference

ai security

IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams

Source: Dark Reading.

Nick Kakolowski from IANS discusses how artificial intelligence (AI) is affecting Chief Information Security Officer (CISO) budgets and organizational security staffing in a video interview. The conversation covers return on investment (ROI) considerations and shifts in security team composition driven by AI adoption.

Why it matters: CISOs evaluating AI investments need to understand budget implications and team restructuring trends to plan resources and staffing effectively.

Tracker inference

vulnerabilitiesResearchTracker priority: TrackCVE-2026-21589

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)

Source: watchTowr Labs.

CVE-2026-21589 affects multiple Atlassian products including Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye through a pre-authentication arbitrary file read vulnerability in the atlassian-plugins-webresource library. The flaw exploits path traversal via double colon (::) encoding to read sensitive files from the application webroot, including WEB-INF directory contents. When Atlassian Crowd is configured for identity management, attackers can extract Crowd credentials from the crowd.properties file and achieve complete administrative compromise of the Crowd instance and all integrated Atlassian applications.

Why it matters: Organizations running on-premises deployments of Jira, Confluence, Bitbucket, or other affected Atlassian products must patch immediately: hundreds of thousands of instances are exposed to unauthenticated file read and potential account takeover if Crowd is integrated. Security practitioners should prioritize updating to the fixed versions listed (Jira Software 9.12.40, 10.3.26, or 11.3.12; Confluence 9.2.26, 10.2.19; and others) and verify whether Crowd is in use, as the attack chain enables complete administrative access.

Tracker inference

threat intel

'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates

Source: Dark Reading.

A proof-of-concept technique called BigDiskBuster maintains the appearance of Microsoft Defender running while blocking security updates, creating an undetected vulnerability window. The method requires no exploit and operates silently, leaving the service seemingly functional while detection gaps persist.

Why it matters: Organizations relying on Microsoft Defender may believe they are protected when the service is actually running with outdated definitions and patches. Security teams should verify that both Defender itself and its definitions update successfully, not just confirm the service is running.

Tracker inference

breaches incidents2 sources

ASOS confirms data breach after “HACKED” in-app notifications

Sources: BleepingComputer and 1 more.

ASOS acknowledged a data breach after hackers delivered unauthorized push notifications via its mobile application and claimed to have accessed customer data stored in the company's Snowflake environment. The breach was confirmed Tuesday following the unauthorized in-app messages.

Why it matters: ASOS customers face potential exposure of personal data from a cloud platform compromise; practitioners should assess whether their organization processes ASOS data and review Snowflake security configurations for similar risks.

Tracker inference

vulnerabilities

CISO perspectives on managing vulnerability risks in the age of AI

Source: Microsoft Security Blog.

Frontier artificial intelligence (AI) models are accelerating vulnerability discovery at scale, with Microsoft reporting close to 1,000 vulnerabilities in September 2026 alone. Chief information security officers (CISOs) must now balance patching speed with correctness across unprecedented finding volumes, while deploying defense-in-depth controls and tools like Microsoft Baseline Security Mode (BSM) to manage the risk. Microsoft is also collaborating with industry peers to scan and remediate vulnerabilities in critical open-source components before attackers exploit them.

Why it matters: CISOs managing Microsoft and multi-vendor infrastructure face sharply increased patch volumes and shortened exploit windows; they should accelerate patching of critical systems to within 24 hours, allocate resources for triage, deploy AI-powered scanning harnesses, and implement BSM to harden their default posture against the growing threat from AI-assisted exploitation.

Tracker inference

breaches incidents

South Korean officials believe AI agents were used to hack several banks

Source: The Record.

South Korean officials report that personal data of at least 68,000 people was exposed across at least seven financial institutions in breaches attributed to a Chinese cybersecurity tool. Investigators believe artificial intelligence (AI) agents were deployed in the attacks against the banks' systems.

Why it matters: South Korean financial services and their customers face exposure of personal data; practitioners at financial institutions should review intrusion detection and access logs for indicators of AI-driven reconnaissance and lateral movement.

Tracker inference

industry

LibreOffice says ‘no AI’ is now a software feature

Source: TechCrunch Security.

LibreOffice announced it will not include artificial intelligence (AI) features in its default configuration, prioritizing user privacy. The open source document editor maker rejected integrating AI capabilities into standard deployments.

Why it matters: Users and administrators adopting LibreOffice can rely on the absence of AI processing by default, avoiding involuntary data transmission or behavioral changes without explicit configuration.

Tracker inference

threat intel

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

Source: BleepingComputer.

Attackers deployed fake versions of ChatGPT, Gemini, Claude, and Perplexity sites to harvest login credentials and multifactor authentication (MFA) codes from advertising account managers using browser-in-browser attack techniques. The campaign exploits the popularity of these artificial intelligence (AI) services to deceive users into entering sensitive authentication data on fraudulent pages.

Why it matters: Ad account managers and teams using these AI services are at immediate risk of account compromise and unauthorized access to advertising budgets; validate any login prompts and enable strong MFA where available.

Tracker inference

cloud saas

Microsoft extends the Outlook naughty step with two more file types

Source: The Register Security.

Microsoft is blocking .msix and .msixbundle file attachments in Outlook for Windows and Outlook on the Web starting in early to mid-November 2026 to prevent malicious Windows application packages from compromising devices. Administrators can allow these extensions in OwaMailboxPolicy if needed for legitimate business purposes. The action expands Outlook's existing blocked file list, which already includes .py, .ps1, and .cab files.

Why it matters: Exchange Online and New Outlook for Windows users will be unable to receive these attachments by default, potentially disrupting workflows that legitimately use .msix packages for software distribution; administrators must prepare policy changes if their organizations require these file types.

Tracker inference

vulnerabilities

IBM’s AI-powered vulnerability clearinghouse finds hundreds of Java flaws

Source: Cybersecurity Dive.

IBM announced an artificial intelligence (AI)-powered vulnerability database that identified hundreds of previously unknown flaws in Java software. The finding highlights gaps in how organizations currently manage their software supply chain security.

Why it matters: Development teams and security leaders need to evaluate whether their vulnerability discovery and remediation processes can keep pace with the volume of issues an AI system can now surface in widely-used components.

Tracker inference

ai security

How to mitigate the risk from AI-generated apps built by your 'citizen coder' employees

Source: Tenable Blog.

Non-technical employees using generative artificial intelligence (AI) tools to build workplace applications, often called citizen coding, can create security vulnerabilities, misconfigurations, and data sprawl if developed without oversight. A five-tier governance framework combining executive strategy, AI governance boards, departmental functional leaders, IT enablement, and community support can allow organizations to permit citizen coding while maintaining security and compliance guardrails. Mandatory security training and peer leadership through department-level AI Functional Leaders help mitigate risks while avoiding counterproductive blanket prohibitions.

Why it matters: Security and IT teams need a governance structure to address shadow AI risks from employee-built applications, as prohibiting citizen coding typically drives development underground and creates unmanaged vulnerabilities in production systems.

Tracker inference

ransomware

Osaka Metropolitan University cancels classes after suspected ransomware attack

Source: The Record.

Osaka Metropolitan University cancelled classes after a suspected ransomware attack that disrupted its internal network, email, and administrative and academic systems. The university confirmed the outage left critical infrastructure unavailable.

Why it matters: Academic institutions and their students face extended service disruptions and potential data exposure when ransomware compromises core systems; organizations should review incident response and backup protocols.

Tracker inference

vulnerabilities

Securing Agent-to-Agent Communication: The Next Identity Frontier

Source: Rapid7 Blog.

As organizations deploy autonomous artificial intelligence (AI) agents, security architectures designed for human users and static endpoints face new challenges when AI agents dynamically collaborate and delegate tasks across environments without human intervention. Security teams must treat AI agents as first-class identities with their own permissions and monitoring while addressing five key risks: identity delegation chaining, behavioral drift that obscures compromise from normal variance, tool and protocol abuse, cascading access across compromised agents, and fragmented observability across multi-agent decision paths. Teams can extend existing identity, telemetry, and least-privilege practices into AI agent environments by auditing agent communication paths, enforcing task-scoped temporary credentials, standardizing inter-agent telemetry, and integrating agent event streams into security information and event management (SIEM) and behavioral analytics platforms.

Why it matters: Security leaders deploying AI agents must redesign monitoring and access controls now to prevent agents from becoming vectors for data exfiltration, privilege escalation, or prompt injection attacks before autonomous agent adoption scales beyond current visibility and governance capabilities.

Tracker inference

vulnerabilitiesResearchCVE-2026-77050CVE-2026-84429+2 more

Django CVE-2026-77050, CVE-2026-84429, CVE-2026-87890, and CVE-2026-87975

Source: oss-security.

Django released security patches addressing four vulnerabilities identified as CVE-2026-77050, CVE-2026-84429, CVE-2026-87890, and CVE-2026-87975. The announcement was posted on October 6, 2026, with links to the official advisory and CVE records for each issue.

Why it matters: Django developers and maintainers must apply these patches to prevent potential exploitation of affected applications in production environments.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary