CYBERSECURITYTRACKER
TRACKING6,635 stories in this site build1,367 vulnerability news stories in this site build

State now. Changed: +62 tier promotions, 0 known-exploited vulnerability additions, 18 leak-site claims, and 6 confirmed breaches between the two successful daily updates shown.

Why today matters · What to watch now

The latest security reporting, combined across sources and tagged, newest first

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by RSS. No account required.

Why now: this site build contains 6,635 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
breaches incidents

Finnish Police Alert Europe Over Fugitive Vastaamo Hacker

Source: HealthcareInfoSecurity.

Finnish authorities issued a European Arrest Warrant for Aleksanteri Kivimäki, convicted for the Vastaamo breach, after he failed to return to prison. Kivimäki was responsible for stealing 33,000 psychotherapy records and extorting patients in one of Finland's most significant healthcare data breaches.

Why it matters: Healthcare organizations and their patients across Europe should be aware that the perpetrator of a major psychotherapy records theft remains at large, and law enforcement coordination may affect ongoing investigations or victim support efforts.

Tracker inference

regulatory

UK Panel Calls for Fresh Approach to Regulating Medical AI

Source: HealthcareInfoSecurity.

A UK government commission recommended a life-cycle risk-based regulatory approach for artificial intelligence (AI)-enabled medical devices and healthcare software, rather than relying solely on premarket reviews. The commission found that one-time approval models are insufficient as these technologies continue to evolve over time.

Why it matters: Medical device manufacturers, healthcare providers, and regulators need to understand the shift toward continuous monitoring and post-market oversight of AI systems, which will affect product development timelines, compliance costs, and market authorization strategies in the UK and potentially influence international regulatory trends.

Tracker inference

identity access

Beyond MFA: Protecting the Browser Session From Identity Attacks

Source: HealthcareInfoSecurity.

The article discusses security measures for protecting browser sessions against identity-based attacks beyond the use of multifactor authentication (MFA). It explores additional safeguards and techniques to defend authenticated sessions from compromise.

Why it matters: Security practitioners need to understand session protection strategies because MFA alone is insufficient; attackers exploit legitimate sessions through cookie theft, malware, and other post-authentication attacks that directly impact user accounts and organizational assets.

Tracker inference

identity access

When Access Reviews Aren’t Enough: Closing the Gaps in Identity Governance

Source: HealthcareInfoSecurity.

Access reviews alone cannot fully address identity governance challenges. Organizations must implement additional controls and processes to identify and remediate gaps in permission management across their systems.

Why it matters: Security practitioners need to understand that periodic access reviews are insufficient for preventing unauthorized access and must design layered identity governance strategies to reduce risk.

Tracker inference

threat intel

Seeing Isn’t Believing: The New Reality of Social Engineering

Source: HealthcareInfoSecurity.

The article carries a title about social engineering and perception but provides no substantive text or content to analyze.

Why it matters: Security practitioners need concrete examples, threat indicators, or actionable guidance to assess risk and implement defenses; this stub offers none.

Tracker inference

ot ics

When Cyberattacks Become Patient Safety Risks: How to Secure Healthcare’s Connected Devices

Source: HealthcareInfoSecurity.

Healthcare organizations face patient safety risks when cyberattacks target connected medical devices and systems. The article discusses the intersection of cybersecurity and clinical safety, highlighting how breaches can compromise device functionality and patient care delivery. Securing healthcare's connected infrastructure requires integrated approaches to both IT security and medical device safety.

Why it matters: Healthcare practitioners and IT teams must prioritize medical device security to prevent attacks that directly threaten patient outcomes and operational continuity.

Tracker inference

breaches incidents

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Source: BleepingComputer.

Japan's Digital Agency discovered a data breach affecting approximately 246,000 records containing personal information of government employees. The incident involved a vulnerability in a virtual private network (VPN) system. The agency has confirmed the exposure of personnel data but the full scope and remediation timeline remain under investigation.

Why it matters: Government employees and contractors across Japan face identity theft and targeted social engineering risks; security teams should immediately audit VPN access logs and credential systems for signs of unauthorized access.

Tracker inference

industry

Homebrew 7.0.0 gets built-in GUI, better security controls

Source: BleepingComputer.

Homebrew package manager version 7.0.0 introduced a built-in vulnerability scanner, enhanced security controls, and released its native BrewUI graphical interface. The update brings improved tooling for users managing software dependencies on macOS and Linux systems.

Why it matters: Developers and DevOps teams using Homebrew should evaluate the new security scanner and controls to reduce supply chain risks in their build environments.

Tracker inference

vulnerabilities

In-the-Wild Attacks Hit Popular DevSecOps Platform GitLab

Source: HealthcareInfoSecurity.

Attackers are actively exploiting a recently patched vulnerability in self-hosted GitLab instances to steal files and credentials from public-facing servers. The vendor urges all self-hosted users to apply the patch immediately.

Why it matters: Organizations running self-hosted GitLab are at immediate risk of credential and source code theft; patches must be deployed without delay.

Tracker inference

ai security

Is Your Organization Mature Enough for AI?

Source: HealthcareInfoSecurity.

The CyberEdBoard will host a webinar on September 24 to present a maturity model developed by Carnegie Mellon's Software Engineering Institute and Accenture. The framework helps organizations evaluate their artificial intelligence (AI) adoption readiness and develop strategies for consistent, repeatable, and scalable outcomes.

Why it matters: Security leaders and enterprise architects need this maturity model to assess organizational readiness for AI deployment and identify capability gaps before investment.

Tracker inference

ot ics

Live Webinar | Securing the New Attack Surface: Defending Healthcare’s High-Leverage Cyber-Physical Systems (CPS)

Source: HealthcareInfoSecurity.

This is a webinar announcement about securing cyber-physical systems in healthcare environments. No substantive content or event details are provided.

Why it matters: Healthcare practitioners need to understand attack surface risks to critical infrastructure, but this stub offers no actionable findings or timelines.

Tracker inference

breaches incidents

Twitch extension with 30K installs exposes users’ OAuth tokens

Source: BleepingComputer.

A Twitch browser extension with 30,000 installations in official Chrome and Firefox stores transmits users' Twitch OAuth session tokens to an external commercial bot service. The extension, called Twitch Enhanced Viewer | JeetBot, exposes sensitive authentication credentials to unauthorized access.

Why it matters: Twitch users with this extension installed have their OAuth tokens exposed to a third party, enabling account takeover, unauthorized streaming, channel modifications, and credential compromise. Security teams should alert users to uninstall the extension and revoke Twitch OAuth tokens immediately.

Tracker inference

Upcoming Speaking Engagements

Source: Schneier on Security.

The author has scheduled speaking engagements at several venues over the coming weeks, including a League of Women Voters event on September 22, 2026, CanSecWest 2026 in Vancouver from September 30 to October 1, 2026, a talk at Bentley University on October 6, 2026, and an appearance at ATTENTION: Democracy, Rebuilt in Montreal from October 21 to 23, 2026. A previously announced talk at the Elevate Festival has been canceled.

Why it matters: This is a personal calendar update with no security practitioner relevance or actionable information.

Tracker inference

vulnerabilitiesResearchTracker priority: ActCVE-2026-27540

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

Source: Wordfence.

An unauthenticated arbitrary file upload vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture plugin, affecting versions up to 2.0.3.1, allows attackers to upload PHP webshells and achieve remote code execution. Wordfence has blocked over 100,000 exploit attempts since the vulnerability's public disclosure on February 20, 2026, with active exploitation occurring across multiple attack campaigns. The plugin was patched in version 2.0.3.2, and affected WordPress sites should update immediately.

Why it matters: WordPress site operators using WooCommerce Wholesale Lead Capture (6,000+ active installations) face immediate risk of complete site compromise; patch to version 2.0.3.2 now and review uploads directories and web server logs for evidence of exploitation.

Tracker inference

government policy2 sources

Five alleged leaders of Black Axe’s operations in South Africa extradited to US

Sources: CyberScoop and 1 more.

Five alleged leaders of Black Axe's South African operations were extradited to the United States to face charges including wire fraud, money laundering, and identity theft. The defendants are accused of running romance and advance fee scams targeting U.S. victims by assuming fake identities and requesting money under false pretenses. The extradition follows increased law enforcement activity against Black Axe across multiple countries in recent months.

Why it matters: U.S.-based fraud victims and their financial institutions face ongoing exposure to Black Axe's sophisticated romance and business email compromise schemes; practitioners should review fraud detection controls and victim reporting procedures given the group's continued global operations.

Tracker inference

threat intel

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Source: BleepingComputer.

Attackers gained control of HBO Max's official Reddit account and deployed malicious advertisements that executed ClickFix attacks against Windows and macOS systems, installing information-stealing malware on compromised devices.

Why it matters: Security teams and endpoint defenders managing Windows and macOS environments need to monitor for ClickFix infection indicators and educate users about malware delivery through compromised corporate social media accounts.

Tracker inference

vulnerabilitiesCVE-2022-3437CVE-2026-20683+259 more

Apple Updates Everything

Source: SANS Internet Storm Center.

Apple released updates across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS on September 14, 2026, patching 261 vulnerabilities, the largest number in Apple's history. The vulnerabilities span multiple components including kernel, WebKit, file systems, and system services, with exposures ranging from denial of service and memory corruption to privilege escalation and data disclosure. None of the patched CVEs are documented as being actively exploited, though some patches address critical issues such as sandbox escapes and arbitrary code execution.

Why it matters: Organizations running Apple devices need to prioritize testing and deployment of these patches, particularly for kernel, WebKit, and privilege escalation issues (CVE-2026-84607, CVE-2026-43689, CVE-2026-43691, CVE-2026-84506) that could allow attackers to compromise systems. Users upgrading to macOS 27 should verify compatibility with security tools like Little Snitch before proceeding, as some third-party applications require updates to function correctly on the new OS version.

Tracker inference

vulnerabilities

New hardware device can RAM into encrypted memory, expose your data

Source: The Register Security.

Researchers from KU Leuven, ETH Zurich, Durham University, and Google demonstrated a hardware attack called DDRop that exploits memory encryption weaknesses in confidential computing systems. The attack uses a custom circuit board costing under $200 to intercept and drop writes to encrypted memory, allowing attackers with physical access to read protected data and forge attestation reports. The vulnerability affects Intel TDX, Scalable SGX, and AMD SEV-SNP implementations, with no straightforward fix available from vendors.

Why it matters: Cloud service providers and enterprises using confidential virtual machines for sensitive workloads face a risk if attackers gain physical access to servers, requiring security review of data center physical access controls and threat modeling assumptions.

Tracker inference

vulnerabilities

NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

Source: NCSC Netherlands Advisories.

Cisco patched a vulnerability in Secure Email Gateway caused by insufficient validation of incoming email messages in AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL instructions to execute arbitrary SQL commands and subsequently gain root-level command execution on the underlying operating system. Active exploitation has been observed in the wild.

Why it matters: Organizations running Cisco Secure Email Gateway must apply this patch urgently and audit systems for signs of compromise, as exploitation is already occurring.

Tracker inference

threat intel

ClickFix attacks are tricking Mac and Windows users into hacking themselves

Source: TechCrunch Security.

ClickFix attacks use fake advertisements on social media platforms to deceive users into downloading malicious software that compromises their systems. The campaign has recently targeted Mac and Windows users through fraudulent HBO Max ads posted on Reddit.

Why it matters: Mac and Windows users are at immediate risk of system compromise if they click on deceptive ads on Reddit and other platforms; security teams should alert users to verify sources before downloading software from ads.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary