CYBERSECURITYTRACKER
TRACKING7,933 stories in this site build1,729 vulnerability news stories in this site build

State now. Changed: +31 tier promotions, 0 known-exploited vulnerability additions, 16 leak-site claims, and 2 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 7,933 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
ai securityResearch

A Win for Defenders: CrowdStrike and NVIDIA Extend Security Across the AI Stack

Source: CrowdStrike.

CrowdStrike and NVIDIA announced an extension of security capabilities across the artificial intelligence (AI) stack. The partnership aims to strengthen security posture for organizations deploying AI infrastructure and workloads.

Why it matters: Defenders using CrowdStrike and NVIDIA solutions gain integrated security coverage for AI environments, reducing fragmentation and potential gaps in threat detection and response across their infrastructure.

Tracker inference

vulnerabilitiesResearchCVE-2026-46675

libpng 1.6.59: Use-after-free vulnerability fixed: CVE-2026-46675

Source: oss-security.

libpng 1.6.59 addresses a medium-severity use-after-free vulnerability (CVE-2026-46675) in the sequential reader that has existed since version 1.6.0. The flaw affects applications calling png_read_end without first beginning to read image rows, and occurs during processing of incomplete zTXt, iTXt, or iCCP chunks. Users should upgrade to 1.6.59 or apply the published fix.

Why it matters: Developers and distributors of applications using libpng should patch or update immediately to prevent denial of service or potential code execution from untrusted PNG files.

Tracker inference

vulnerabilitiesTracker priority: ActCVE-2026-86950

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)

Source: SANS Internet Storm Center.

Apple released emergency patches for iOS 26, macOS 26, and macOS 15 addressing CVE-2026-86950, a vulnerability already being exploited in sophisticated attacks against targeted individuals. The current iOS and macOS 27 branches are unaffected, and the separate 27.1 update addresses functional issues and will support the upcoming foldable iPhone. Meta Product Security reported the vulnerability.

Why it matters: Organizations and individuals running iOS 26, macOS 26, or macOS 15 should apply these patches immediately given active exploitation of CVE-2026-86950 in the wild.

Tracker inference

ai security

Between Two Nerds: The AI crime machine

Source: Risky Business News.

Security researchers Tom Uren and The Grugq discuss the emergence of fully automated large language model (LLM)-driven hacking campaigns deployed by both criminal actors and state-sponsored groups. The episode explores how artificial intelligence (AI) adoption in attacks, particularly through autonomous AI agents, enables faster exploitation with lower operational friction. A move-fast approach using AI tools has proven profitable for attackers targeting online retailers and government agencies.

Why it matters: Security teams and enterprise defenders must understand how autonomous AI hacking tools amplify attacker speed and scale, especially across retail and government sectors where hundreds of organizations face LLM-powered intrusions.

Tracker inference

regulatoryResearch

A Threat-Sharing Law Slides Into December. A CIRCIA Reporting Mandate Does Not

Source: Halcyon.

The Cybersecurity Information Sharing Act (CISA) 2015 threat-sharing protections are receiving another short-term extension into December, while the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) 72-hour incident reporting requirement becomes permanent this month. The divergent treatment reflects ongoing congressional debate over balancing information sharing incentives with mandatory disclosure requirements.

Why it matters: Critical infrastructure operators and their security teams must immediately align incident response procedures with CIRCIA's permanent 72-hour reporting deadline to avoid penalties, while monitoring whether CISA 2015 protections remain available to encourage future threat intelligence sharing.

Tracker inference

ot ics

One Packet Can Crash OT Servers in Industrial Sectors

Source: Dark Reading.

A high-severity zero-day vulnerability in the TDengine time-series database can crash operational technology (OT) servers across industrial, internet of things (IoT), energy, and automotive environments with a single malicious packet.

Why it matters: Industrial, energy, and automotive operators running TDengine need to assess exposure and apply patches immediately, as the vulnerability enables denial of service attacks on critical systems.

Tracker inference

ransomware

Japan's Keio confirms ransomware attack disrupted business systems

Source: BleepingComputer.

Keio Corporation, a major private railway operator in Japan, disclosed that a ransomware attack over the weekend of September 27-28 disrupted some of its business systems. The incident affected the company's network infrastructure and operational capabilities.

Why it matters: Transportation operators and their customers face service disruptions and data exposure risks; practitioners should assess whether critical infrastructure dependencies are backed by ransomware response and recovery plans.

Tracker inference

breaches incidents

Times Car confirms data breach affecting 6.6 million user accounts

Source: BleepingComputer.

Times Car, a Japanese car-sharing service, confirmed a cyberattack that compromised approximately 6.6 million user accounts. The breach was disclosed late in the previous week. The company has begun notifying affected users of the incident.

Why it matters: Users of Times Car and organizations relying on the service face credential exposure and potential identity theft; practitioners should assess whether their organizations or employees use this platform and monitor for phishing or account takeover attempts.

Tracker inference

ai security

Trust, Not Hype, Will Decide How Far Enterprise AI Can Scale

Source: HealthcareInfoSecurity.

A HumanX executive argues that artificial intelligence (AI) adoption in enterprises will remain limited unless organizations build sufficient trust in AI systems, comparing the needed confidence level to utilities like electricity and water. The piece addresses AI governance and regulatory challenges as factors shaping enterprise AI deployment.

Why it matters: Enterprise decision-makers need to assess whether their organizations have established the governance, transparency, and risk controls required to move AI beyond pilot projects into production workflows.

Tracker inference

vulnerabilities

Linux security advisory (AV26-970)

Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.

A Linux kernel vulnerability affects multiple versions prior to specified patches, as of September 25, 2026. The advisory identifies impacted kernel versions from 4.7 through 7.2 and directs users and administrators to apply available updates.

Why it matters: Linux kernel maintainers and system administrators must prioritize patching their kernel versions to the specified fixed releases to close the vulnerability and reduce exposure.

Tracker inference

vulnerabilities

ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns

Source: The Record.

ShinyHunters, a prolific hacking group that claimed responsibility for an FBI jobs site attack, is exploiting a vulnerability in Oracle PeopleSoft in a new campaign, according to Mandiant. The group is using workarounds to bypass protections related to the bug.

Why it matters: Organizations running Oracle PeopleSoft must patch this vulnerability urgently, as ShinyHunters is actively exploiting it in attacks and has demonstrated capability against high-profile targets including federal systems.

Tracker inference

vulnerabilitiesTracker priority: ActCVE-2026-86950

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Source: The Hacker News.

Apple released security updates addressing CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting iOS, iPadOS, and macOS that could enable arbitrary code execution. The flaw may have been exploited in targeted attacks.

Why it matters: Users of older iOS, iPadOS, and macOS versions should apply these updates promptly, especially those at risk of targeted attacks, to prevent potential code execution via maliciously crafted files.

Tracker inference

cloud saas

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Source: BleepingComputer.

Researchers discovered over 16,000 misconfigured Supabase databases with publicly readable tables containing personally identifiable information, passwords, and authentication tokens. The exposure stemmed from insecure default configurations or inadequate access controls on the backend-as-a-service platform.

Why it matters: Development teams using Supabase should immediately audit their database configurations and access policies to ensure sensitive data is not exposed; customers of affected services may have credentials and personal data at risk.

Tracker inference

ai security

AI Agents Are Privileged Users; Who Is Auditing Their Access?

Source: Dark Reading.

Enterprises deploy autonomous artificial intelligence (AI) agents with broad system privileges but lack adequate monitoring mechanisms for their actions. Unlike human employees subject to rigorous access controls and auditing, these agents operate with minimal oversight, creating potential insider threat exposure.

Why it matters: Security teams and system administrators need audit and logging mechanisms for AI agent activity today, as unmonitored privileged access by agents could enable data theft, unauthorized changes, or lateral movement without detection.

Tracker inference

threat intel

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Source: The Hacker News.

Microsoft identified a malware family called NeedyMantis used by attackers to maintain persistent access in already-compromised networks across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware has appeared in a limited number of targeted intrusions dating back at least several years.

Why it matters: Organizations in telecommunications, higher education, healthcare, government, and intergovernmental sectors should assess whether NeedyMantis persists in their networks, as attackers leverage it for long-term access after initial breaches.

Tracker inference

ai security2 sources

As AI world debates security, NVIDIA releases open source tools for agents

Sources: CyberScoop and 1 more.

NVIDIA released the Open Agent Safety Platform, an open source security framework for artificial intelligence (AI) agents with tools including OpenShell for sandbox testing and monitoring capabilities, backed by commitments from over 100 organizations. The platform emphasizes containment, sandboxing, and out-of-band monitoring to address concerns that advanced AI systems may escape safety protections, with NVIDIA arguing that agent security is an engineering problem rather than an inherent limitation.

Why it matters: Security teams building or deploying AI agents need to evaluate sandbox and containment strategies as organizations race to productionize autonomous systems that previous high-profile models escaped during testing.

Tracker inference

identity access

IAM for AI agents: A Practical Enterprise Framework

Source: The Hacker News.

The article outlines identity and access management (IAM) concepts specific to artificial intelligence (AI) agents that operate within enterprise environments with delegated permissions. It addresses gaps in traditional provisioning methods, identifies key architectural components, and establishes criteria for assessing and validating agent behavior at runtime.

Why it matters: Enterprise security teams deploying AI agents need practical IAM frameworks to control what those agents can authenticate, invoke, and execute across systems, and to detect when they exceed intended scope.

Tracker inference

breaches incidents

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Source: The Hacker News.

Bitget reported that attackers stole approximately $388 million from the cryptocurrency exchange by exploiting a vulnerability in a third-party security product. The attackers used the flaw to acquire privileged internal credentials, then issued fraudulent withdrawal commands to Bitget's wallet system on September 24.

Why it matters: Cryptocurrency exchange operators and any organization relying on third-party security tools must urgently audit their security product deployments for similar flaws and credential exposure risks.

Tracker inference

threat intel

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Source: The Hacker News.

RatHat is an Android banking trojan operated through a web console where individual customers run separate deployments. Cleafy identified nearly 100 instances of this console since April 2026, operating under a malware-as-a-service model, and documented the console's use of Google's Gemini to prioritize victims by financial value.

Why it matters: Financial institutions and users of Android banking apps face direct theft risk from RatHat's distributed operation; security teams should monitor for indicators of this malware family and related infrastructure.

Tracker inference

ai security

Modulate Raises $25 Million to Advance Deepfake Detection

Source: SecurityWeek.

Modulate secured $25 million in funding to develop technology for real-time detection and intervention of artificial intelligence (AI)-generated voice misuse. The company aims to address growing threats from AI-generated audio abuse.

Why it matters: Security teams protecting enterprises and users from deepfake audio attacks need detection tools as AI voice generation becomes more sophisticated and accessible.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary