CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build

State now. Changed: +157 tier promotions, 0 known-exploited vulnerability additions, 68 leak-site claims, and 8 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 7,931 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
vulnerabilitiesTracker priority: TrackCVE-2026-86950

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)

Source: SANS Internet Storm Center.

Apple released emergency patches for iOS 26, macOS 26, and macOS 15 to address CVE-2026-86950, reported by Meta Product Security. The current iOS and macOS 27 branches are unaffected and received only functional updates. Apple stated it is aware of reports regarding this vulnerability and noted potential exploitation in sophisticated attacks targeting specific individuals on older iOS versions.

Why it matters: Organizations supporting iOS 26 and macOS 26/15 devices must deploy patches immediately, as the vulnerability status and exploitation details remain unclear; teams should verify their device inventory and prioritize updates for targeted users.

Tracker inference

ai security

Between Two Nerds: The AI crime machine

Source: Risky Business News.

Security researchers Tom Uren and The Grugq discuss the emergence of fully automated large language model (LLM)-driven hacking campaigns deployed by both criminal actors and state-sponsored groups. The episode explores how artificial intelligence (AI) adoption in attacks, particularly through autonomous AI agents, enables faster exploitation with lower operational friction. A move-fast approach using AI tools has proven profitable for attackers targeting online retailers and government agencies.

Why it matters: Security teams and enterprise defenders must understand how autonomous AI hacking tools amplify attacker speed and scale, especially across retail and government sectors where hundreds of organizations face LLM-powered intrusions.

Tracker inference

regulatoryResearch

A Threat-Sharing Law Slides Into December. A CIRCIA Reporting Mandate Does Not

Source: Halcyon.

The Cybersecurity Information Sharing Act (CISA) 2015 threat-sharing protections are receiving another short-term extension into December, while the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) 72-hour incident reporting requirement becomes permanent this month. The divergent treatment reflects ongoing congressional debate over balancing information sharing incentives with mandatory disclosure requirements.

Why it matters: Critical infrastructure operators and their security teams must immediately align incident response procedures with CIRCIA's permanent 72-hour reporting deadline to avoid penalties, while monitoring whether CISA 2015 protections remain available to encourage future threat intelligence sharing.

Tracker inference

ot ics

One Packet Can Crash OT Servers in Industrial Sectors

Source: Dark Reading.

A high-severity zero-day vulnerability in the TDengine time-series database can crash operational technology (OT) servers across industrial, internet of things (IoT), energy, and automotive environments with a single malicious packet.

Why it matters: Industrial, energy, and automotive operators running TDengine need to assess exposure and apply patches immediately, as the vulnerability enables denial of service attacks on critical systems.

Tracker inference

ransomware

Japan's Keio confirms ransomware attack disrupted business systems

Source: BleepingComputer.

Keio Corporation, a major private railway operator in Japan, disclosed that a ransomware attack over the weekend of September 27-28 disrupted some of its business systems. The incident affected the company's network infrastructure and operational capabilities.

Why it matters: Transportation operators and their customers face service disruptions and data exposure risks; practitioners should assess whether critical infrastructure dependencies are backed by ransomware response and recovery plans.

Tracker inference

breaches incidents

Times Car confirms data breach affecting 6.6 million user accounts

Source: BleepingComputer.

Times Car, a Japanese car-sharing service, confirmed a cyberattack that compromised approximately 6.6 million user accounts. The breach was disclosed late in the previous week. The company has begun notifying affected users of the incident.

Why it matters: Users of Times Car and organizations relying on the service face credential exposure and potential identity theft; practitioners should assess whether their organizations or employees use this platform and monitor for phishing or account takeover attempts.

Tracker inference

ai security

Trust, Not Hype, Will Decide How Far Enterprise AI Can Scale

Source: HealthcareInfoSecurity.

A HumanX executive argues that artificial intelligence (AI) adoption in enterprises will remain limited unless organizations build sufficient trust in AI systems, comparing the needed confidence level to utilities like electricity and water. The piece addresses AI governance and regulatory challenges as factors shaping enterprise AI deployment.

Why it matters: Enterprise decision-makers need to assess whether their organizations have established the governance, transparency, and risk controls required to move AI beyond pilot projects into production workflows.

Tracker inference

vulnerabilities

Linux security advisory (AV26-970)

Source: Canadian Centre for Cyber Security, Communications Security Establishment Canada.

A Linux kernel vulnerability affects multiple versions prior to specified patches, as of September 25, 2026. The advisory identifies impacted kernel versions from 4.7 through 7.2 and directs users and administrators to apply available updates.

Why it matters: Linux kernel maintainers and system administrators must prioritize patching their kernel versions to the specified fixed releases to close the vulnerability and reduce exposure.

Tracker inference

vulnerabilities

ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns

Source: The Record.

ShinyHunters, a prolific hacking group that claimed responsibility for an FBI jobs site attack, is exploiting a vulnerability in Oracle PeopleSoft in a new campaign, according to Mandiant. The group is using workarounds to bypass protections related to the bug.

Why it matters: Organizations running Oracle PeopleSoft must patch this vulnerability urgently, as ShinyHunters is actively exploiting it in attacks and has demonstrated capability against high-profile targets including federal systems.

Tracker inference

vulnerabilitiesTracker priority: TrackCVE-2026-86950

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Source: The Hacker News.

Apple released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting iOS, iPadOS, and macOS. The flaw may have been exploited in targeted attacks and could allow arbitrary code execution when processing a malicious file.

Why it matters: Organizations managing Apple devices should prioritize patching iOS, iPadOS, and macOS systems to address this potentially exploited vulnerability.

Tracker inference

cloud saas

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Source: BleepingComputer.

Researchers discovered over 16,000 misconfigured Supabase databases with publicly readable tables containing personally identifiable information, passwords, and authentication tokens. The exposure stemmed from insecure default configurations or inadequate access controls on the backend-as-a-service platform.

Why it matters: Development teams using Supabase should immediately audit their database configurations and access policies to ensure sensitive data is not exposed; customers of affected services may have credentials and personal data at risk.

Tracker inference

ai security

AI Agents Are Privileged Users; Who Is Auditing Their Access?

Source: Dark Reading.

Enterprises deploy autonomous artificial intelligence (AI) agents with broad system privileges but lack adequate monitoring mechanisms for their actions. Unlike human employees subject to rigorous access controls and auditing, these agents operate with minimal oversight, creating potential insider threat exposure.

Why it matters: Security teams and system administrators need audit and logging mechanisms for AI agent activity today, as unmonitored privileged access by agents could enable data theft, unauthorized changes, or lateral movement without detection.

Tracker inference

threat intel

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Source: The Hacker News.

Microsoft identified a malware family called NeedyMantis used by attackers to maintain persistent access in already-compromised networks across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware has appeared in a limited number of targeted intrusions dating back at least several years.

Why it matters: Organizations in telecommunications, higher education, healthcare, government, and intergovernmental sectors should assess whether NeedyMantis persists in their networks, as attackers leverage it for long-term access after initial breaches.

Tracker inference

ai security2 sources

As AI world debates security, NVIDIA releases open source tools for agents

Sources: CyberScoop and 1 more.

NVIDIA released the Open Agent Safety Platform, an open source security framework for artificial intelligence (AI) agents with tools including OpenShell for sandbox testing and monitoring capabilities, backed by commitments from over 100 organizations. The platform emphasizes containment, sandboxing, and out-of-band monitoring to address concerns that advanced AI systems may escape safety protections, with NVIDIA arguing that agent security is an engineering problem rather than an inherent limitation.

Why it matters: Security teams building or deploying AI agents need to evaluate sandbox and containment strategies as organizations race to productionize autonomous systems that previous high-profile models escaped during testing.

Tracker inference

identity access

IAM for AI agents: A Practical Enterprise Framework

Source: The Hacker News.

The article outlines identity and access management (IAM) concepts specific to artificial intelligence (AI) agents that operate within enterprise environments with delegated permissions. It addresses gaps in traditional provisioning methods, identifies key architectural components, and establishes criteria for assessing and validating agent behavior at runtime.

Why it matters: Enterprise security teams deploying AI agents need practical IAM frameworks to control what those agents can authenticate, invoke, and execute across systems, and to detect when they exceed intended scope.

Tracker inference

breaches incidents

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Source: The Hacker News.

Bitget reported that attackers stole approximately $388 million from the cryptocurrency exchange by exploiting a vulnerability in a third-party security product. The attackers used the flaw to acquire privileged internal credentials, then issued fraudulent withdrawal commands to Bitget's wallet system on September 24.

Why it matters: Cryptocurrency exchange operators and any organization relying on third-party security tools must urgently audit their security product deployments for similar flaws and credential exposure risks.

Tracker inference

threat intel

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Source: The Hacker News.

RatHat is an Android banking trojan operated through a web console where individual customers run separate deployments. Cleafy identified nearly 100 instances of this console since April 2026, operating under a malware-as-a-service model, and documented the console's use of Google's Gemini to prioritize victims by financial value.

Why it matters: Financial institutions and users of Android banking apps face direct theft risk from RatHat's distributed operation; security teams should monitor for indicators of this malware family and related infrastructure.

Tracker inference

ai security

Modulate Raises $25 Million to Advance Deepfake Detection

Source: SecurityWeek.

Modulate secured $25 million in funding to develop technology for real-time detection and intervention of artificial intelligence (AI)-generated voice misuse. The company aims to address growing threats from AI-generated audio abuse.

Why it matters: Security teams protecting enterprises and users from deepfake audio attacks need detection tools as AI voice generation becomes more sophisticated and accessible.

Tracker inference

vulnerabilitiesResearchCVE-2026-85644

CVE-2026-85644: XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference

Source: oss-security.

CVE-2026-85644 affects XS::Parse::Infix versions 0.40 through 0.49 for Perl, where the module incorrectly treats a number as an array reference. The vulnerability is tracked in the CPAN Security Group.

Why it matters: Perl developers using the affected XS::Parse::Infix versions should upgrade immediately, as this type conversion error could lead to unexpected behavior or code execution in dependent applications.

Tracker inference

vulnerabilitiesResearchCVE-2026-88816

CVE-2026-88816: DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName

Source: oss-security.

CVE-2026-88816 affects Perl's DBI module in versions before 1.654, where numeric values are incorrectly treated as strings in the FetchHashKeyName feature. The vulnerability allows unintended behavior when fetching database results into hash structures with numeric keys.

Why it matters: Perl developers using DBI to fetch query results into hashes must upgrade to version 1.654 or later to prevent type handling errors that could affect application logic or data integrity.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary