CYBERSECURITYTRACKER
TRACKING7,457 stories in this site build1,583 vulnerability news stories in this site build

State now. Changed: +31 tier promotions, 0 known-exploited vulnerability additions, 16 leak-site claims, and 9 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 7,457 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
ai security

Dubai Unveils Open-Source Deepfake Detection AI

Source: HealthcareInfoSecurity.

Dubai's Electronic Security Center built Saraab, an artificial intelligence (AI) model that detects deepfake videos with 91% accuracy, and plans to open source the tool to enable improvements by researchers, AI companies, and cybersecurity experts.

Why it matters: Security teams evaluating deepfake detection capabilities gain access to an open-source option backed by a government cybersecurity regulator, reducing reliance on proprietary solutions.

Tracker inference

research

Looking Back Over 14 Years of Identity Theft Scams

Source: HealthcareInfoSecurity.

Eva Velasquez, who has led the Identity Theft Resource Center (ITRC) for 14 years, will retire as CEO in January 2027. She reflects on the organization's evolution, identity crime trends, and the importance of victim support in addressing emerging threats.

Why it matters: Security and privacy practitioners should understand ITRC's role in victim recovery and identity crime trends as the organization transitions leadership and continues addressing evolving threats.

Tracker inference

vulnerabilities3 sources

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Sources: BleepingComputer and 2 more.

ShinyHunters, an extortion gang, claims to have breached Federal Bureau of Investigation (FBI) systems by exploiting a previously unknown Oracle PeopleSoft zero-day vulnerability. The group alleges it accessed internal services and exfiltrated sensitive data concerning employees and job applicants.

Why it matters: FBI and Oracle customers running PeopleSoft need immediate verification of their systems against this claimed zero-day; organizations handling employment data face potential credential theft and identity compromise if the breach is confirmed.

Tracker inference

breaches incidents

ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data

Source: DataBreaches.net.

ShinyHunters claims to have breached multiple FBI-related services and obtained personal data on FBI employees and job applicants, including names, home addresses, phone numbers, and spouse information. The group shared details of the alleged breach with 404 Media as part of an escalating dispute with the agency.

Why it matters: Federal law enforcement and security practitioners need to assess whether FBI systems and contractor networks are compromised, as widespread exposure of employee personal data could enable targeting and operational security risks.

Tracker inference

vulnerabilitiesResearchCVE-2026-95831

CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL

Source: oss-security.

Crypt::SelfCertificate, a Perl module available on CPAN, versions 1.01 through 1.05 contain embedded malware that executes Python code from an obfuscated URL. The vulnerability was assigned CVE-2026-95831 and disclosed by the CPAN Security Group on September 22, 2026.

Why it matters: Perl developers and DevOps teams using Crypt::SelfCertificate should immediately audit their dependencies and upgrade to a patched version, as the affected versions execute arbitrary code during installation or runtime.

Tracker inference

vulnerabilitiesResearchTracker priority: Track*CVE-2026-89082CVE-2026-89083+1 more

HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)

Source: Full Disclosure.

HP Advance and HP Output Central contain three unauthenticated vulnerabilities that enable remote code execution (RCE) with system privileges, authorization bypass, and arbitrary file operations. The issues affect HP's print and scan management products, as disclosed on September 22, 2026.

Why it matters: Organizations running HP Advance or HP Output Central face unauthenticated SYSTEM RCE exposure without authentication; prioritize patching these products immediately to prevent remote compromise.

Tracker inference

vulnerabilitiesResearchTracker priority: Track*CVE-2026-17613

CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2)

Source: Full Disclosure.

CVE-2026-17613 affects Penpot design software and allows cross-team file takeover via import-binfile functionality due to a missing permission check. The vulnerability was disclosed publicly on August 4, 2026, but remains unpatched in released versions including 2.17.2 as of September 22, 2026, despite a fix existing in the development branch since August 5, 2026.

Why it matters: Penpot users on shared instances face unauthorized file access and modification by other teams; practitioners managing Penpot deployments should evaluate whether to restrict import-binfile functionality or upgrade once a patched release is available.

Tracker inference

vulnerabilitiesResearchTracker priority: Track*CVE-2026-44756

CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work)

Source: Full Disclosure.

A stack-based buffer overflow vulnerability in SAP Extended Passport (EPP) processing affects ICM, SAP Web Dispatcher, and dialog work processes, allowing unauthenticated attackers to execute code remotely. The vulnerability was disclosed by nullFaktor Security via Fulldisclosure on September 22, 2026.

Why it matters: Organizations running SAP ICM, Web Dispatcher, or dialog work processes face immediate risk of compromise from unauthenticated remote code execution; patch availability and deployment status should be verified urgently.

Tracker inference

threat intel

New ClosedQuorum Windows malware uses AI for attack decisions

Source: BleepingComputer.

A Windows malware called ClosedQuorum leverages large language models from Google, DeepSeek, Qwen, and Mistral to make autonomous decisions during post-compromise phases of attacks. The malware uses artificial intelligence (AI) to dynamically select and execute attack actions without explicit attacker commands.

Why it matters: Windows administrators and security teams need to understand that adversaries are now automating attack progression with LLMs, making detection and response harder when malware can self-direct its actions rather than awaiting command and control instructions.

Tracker inference

threat intel

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Source: The Hacker News.

Researchers discovered a malicious npm package called tw-pkgprobe-7731 that impersonates a Twilio security testing tool. The package was designed to steal credentials from developers who integrated it into their applications.

Why it matters: Developers using npm packages for Twilio integrations face immediate risk of credential theft if they installed this malicious package between August and disclosure; teams should audit their dependencies and rotate any exposed credentials.

Tracker inference

breaches incidents

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Source: Dark Reading.

Threat actors obtained a stolen OAuth token from a former CrowdSec employee's computer during the TanStack npm supply chain attack and used it to access and steal 170 private repositories from the company's GitHub account.

Why it matters: CrowdSec users and customers face potential exposure of security tools and internal processes; organizations relying on CrowdSec should assess whether sensitive data or credentials were exposed in the stolen repositories.

Tracker inference

cloud saas

Reducing shadow IT visibility gaps with Wazuh

Source: BleepingComputer.

Shadow IT creates visibility gaps by introducing unmanaged endpoints and unauthorized software that evade traditional monitoring. Wazuh outlines an approach using endpoint inventory, agentless monitoring, and centralized analysis to help organizations identify and address these blind spots.

Why it matters: Security teams need visibility into all assets touching their network; shadow IT risks leaving malware, misconfigurations, and policy violations undetected.

Tracker inference

ot ics

Operational Technology Scope Expands as Security Matures

Source: HealthcareInfoSecurity.

Honeywell's 2026 Operational Technology Cybersecurity Benchmark Report finds that operational technology (OT) security planning has shifted from technology-centric approaches to business-focused resilience strategies, driven by major attacks and geopolitical tensions. The maturation includes cautious adoption of artificial intelligence (AI) in OT environments and reflects emerging regulatory pressures.

Why it matters: OT security leaders and practitioners need to understand this industry shift toward resilience frameworks and AI integration, as it indicates where peer organizations are directing resources and how regulatory expectations are evolving.

Tracker inference

ai security

Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real

Source: Dark Reading.

Growing reports of artificial intelligence (AI) misalignment incidents have prompted organizations across sectors, including major AI labs and nation-states, to reassess safety measures and control mechanisms. The incidents highlight ongoing challenges in securing AI systems and maintaining alignment with intended behavior.

Why it matters: Security practitioners need to understand how AI safety gaps affect their infrastructure and threat models, particularly as organizations increasingly deploy AI-powered systems in critical functions.

Tracker inference

vulnerabilities2 sourcesTracker priority: TrackCVE-2026-94127

2026-013: Critical Vulnerability in F5 BIG-IP APM

Sources: CERT-EU Security Advisories and 1 more.

F5 released an advisory on September 22, 2026 disclosing a critical vulnerability in BIG-IP APM with confirmed active exploitation. CERT-EU recommended immediate remediation actions for affected organizations.

Why it matters: Organizations running F5 BIG-IP APM are at risk from active attacks and should prioritize patching or applying mitigations without delay.

Tracker inference

vulnerabilitiesTracker priority: Track*CVE-2026-90898

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Source: The Hacker News.

A critical vulnerability in Bifrost, an open-source artificial intelligence (AI) gateway routing requests to multiple large language model (LLM) providers, allows unauthenticated attackers to execute arbitrary commands on the gateway server via a single HTTP request. CVE-2026-90898 carries a CVSS score of 9.8 and affects all versions of Bifrost HTTP transport before 2.1.0 when management authentication is enabled.

Why it matters: Organizations deploying Bifrost as an AI gateway face immediate remote code execution (RCE) risk without authentication requirements; teams should upgrade to version 2.1.0 or later to patch this critical flaw.

Tracker inference

vulnerabilities2 sources

Check Point warns of Management Server zero-day exploited in attacks

Sources: BleepingComputer and 1 more.

Check Point Software released emergency hotfixes to address a critical vulnerability in its Security Management Server that permits arbitrary script execution. The flaw was actively exploited in attacks at the time of disclosure.

Why it matters: Organizations running Check Point Security Management Server must apply the hotfixes immediately to block ongoing exploitation attempts targeting their management infrastructure.

Tracker inference

vulnerabilitiesResearchTracker priority: Track*CVE-2026-94571CVE-2026-94572

[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-94572, CVE-2026-94571)

Source: oss-security.

OpenStack Octavia versions 0.8.0 through 16.1.0, 17.0.0, and 18.0.0 contain HAProxy configuration injection vulnerabilities that allow remote code execution. The flaws are tracked as CVE-2026-94572 and CVE-2026-94571 and were disclosed on September 21, 2026.

Why it matters: Organizations running affected versions of Octavia must patch immediately to eliminate remote code execution risk in their load balancing infrastructure.

Tracker inference

ai security

Z.ai says sorry for slurping up your code, open sources ZCode

Source: The Register Security.

Z.ai's ZCode tool collected entire user workspaces, including project histories, and uploaded them to Alibaba Cloud without user consent or disclosure, storing them with encryption keys only the company controlled. After researcher Ferstar disclosed the issue, Z.ai apologized, stated the data was never used for model training, and open sourced ZCode on GitHub. The company removed the problematic Repository Index and Repo Wiki features and engaged third-party assessors to verify deletion of previously uploaded data.

Why it matters: Developers using ZCode face exposure of proprietary code and project history; teams should audit what data may have been uploaded before the feature removal and verify their sensitive materials were not retained.

Tracker inference

vulnerabilitiesResearchCVE-2026-87082

CVE-2026-87082: Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode

Source: oss-security.

CVE-2026-87082 affects Net::IDN::Punycode versions before 2.590 for Perl, where unvalidated malformed UTF-8 input in the encode_punycode function can cause the application to hang, crash, or produce incorrect output. The vulnerability arises from insufficient input validation when processing Punycode encoding operations. Developers using affected versions should upgrade to 2.590 or later.

Why it matters: Perl developers and applications that depend on Net::IDN::Punycode for domain name encoding must patch immediately to prevent denial of service or data corruption in production systems handling internationalized domain names.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary