The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 7,578 stories, with the newest available reporting below.
The UK Prime Minister, Andy Burnham, described Russian disinformation as an industrial-scale assault during a UN speech and attributed narratives of national decline to Russian hostile actors. His remarks signal a renewed focus on countering Kremlin-sponsored information warfare targeting Britain.
Why it matters: Practitioners monitoring threat intelligence from nation-state actors should track UK policy responses and any corresponding technical indicators of Russian disinformation campaigns targeting UK infrastructure, media, or electoral systems.
Ahmed Elbadawy, a member of the cybercrime group Scattered Spider, pleaded guilty to wire fraud and identity theft charges. He received a 45-month federal prison sentence and must forfeit $18 million in cryptocurrency seized from his involvement in dozens of attacks.
Why it matters: Organizations targeted by Scattered Spider should review incident logs and credential access patterns to identify any compromise tied to Elbadawy's known attack campaigns, and security teams should track the group's remaining operational members.
Cyber extortion group ShinyHunters claims to have accessed Federal Bureau of Investigation (FBI) systems and obtained personal information belonging to employees, demanding removal of content about the group's operations in exchange for withholding disclosure. Security researchers view the claim as primarily a reputation-building tactic rather than a credible threat.
Why it matters: Federal law enforcement and organizations with employee data in FBI systems face potential exposure; practitioners should monitor for leaked credentials or personal information targeting government staff.
Abdelhamid Naceri, a former Microsoft employee, disclosed that he is the researcher behind the Nightmare Eclipse campaign, which released multiple Windows and Defender zero-days including BigDiskBuster. Naceri framed the disclosures as retaliatory following an employment dispute and frustration with Microsoft's vulnerability-reporting process.
Why it matters: Windows and Defender users face active exposure to multiple unpatched zero-days; practitioners should prioritize patching and monitoring for exploitation of these vulnerabilities while Microsoft develops fixes.
Ofcom, the UK communications regulator, announced an investigation into Pornhub's parent company regarding alleged failures in age verification. The investigation follows Pornhub's May implementation of an age assurance process that relies on signals from Apple to identify users under 18 in the UK who have completed Apple's age checks.
Why it matters: Website operators and digital platforms in the UK must ensure robust age verification controls; regulators are now actively scrutinizing compliance mechanisms, creating enforcement risk for inadequate implementations.
Check Point disclosed active exploitation of CVE-2026-85102, a critical pre-authentication remote code execution (RCE) flaw in its Security Gateway virtual private network (VPN) certificate-handling component. The vulnerability carries a CVSS score of 9.8 and appears on the known exploited vulnerabilities list, indicating confirmed in-the-wild attacks.
Why it matters: Organizations deploying Check Point Security Gateway with VPN access must patch immediately, as adversaries are actively exploiting this flaw to achieve RCE with no authentication required.
A Department of Homeland Security inspector general report found that 86% of federal civilian agencies failed to implement cloud security policies required by a December 2024 Cybersecurity and Infrastructure Security Agency (CISA) directive with a June 2025 deadline. The missing configurations included blocking outdated authentication, enforcing multifactor authentication (MFA), and protecting sensitive data in cloud applications. CISA lacks enforcement authority over its binding operational directives, leaving federal cloud infrastructure vulnerable to preventable attacks.
Why it matters: Federal IT and security leaders face elevated risk of compromise in cloud environments; CISA's inability to mandate compliance exposes the entire government enterprise to preventable threats and demonstrates a systemic gap in cyber governance.
IonQ unveiled a single-processor quantum error decoder designed to reduce the classical computing overhead required in quantum error correction processes. The development addresses a significant bottleneck in making quantum systems more practical and efficient.
Why it matters: Quantum computing researchers and organizations exploring quantum security implications should track advancements in error correction, as improvements may accelerate the timeline for practical quantum computers capable of breaking current encryption standards.
U.S. intelligence agencies completed a classified assessment of the 2024 presidential election and found no evidence that foreign adversaries successfully interfered in the voting process, according to officials familiar with the findings.
Why it matters: Government security practitioners and election officials should reference this assessment when evaluating defensive posture and resource allocation for election security infrastructure and foreign interference detection capabilities.
CVE-2024-0244 is a heap buffer overflow in the Canon MF753Cdw printer's fax driver that allows unauthenticated remote code execution. A researcher discovered the vulnerability by analyzing the SOAP-based fax protocol, identifying that oversized length fields in the binary fax payload corrupt the heap and trigger an arbitrary free() call. Exploitation combines the vulnerability with Canon's BJNP protocol to place shellcode at known addresses and hijack function pointers for code execution.
Why it matters: Organizations using Canon MF753Cdw printers are exposed to unauthenticated remote code execution over the network; administrators should assess whether this printer model is deployed and review Canon's patching status for CVE-2024-0244.
Threat actors have progressed from reconnaissance to active exploitation of CVE-2026-87902, a critical WordPress vulnerability that allows remote code execution (RCE) through file write and shell command execution. Attackers are now deploying this flaw in the wild to compromise WordPress installations.
Why it matters: WordPress site operators and their hosting providers must patch immediately; this vulnerability is under active exploitation and enables full system compromise through RCE.
The Federal Bureau of Investigation (FBI) is investigating a cyberattack involving a third-party jobs portal. The incident underscores supply chain vulnerabilities that affect organizations across sectors.
Why it matters: Organizations relying on third-party job portals face exposure to data compromise; practitioners should audit vendor access and incident response protocols for integrated recruitment platforms.
Katie Sutton, the Pentagon's assistant secretary of defense for cyber policy, stated that military demand for cyber capabilities substantially exceeds current supply and emphasized cyber warfare as an integrated tool alongside kinetic operations. She highlighted data denial as central to future military effectiveness and outlined concerns about artificial intelligence integration into cyber operations, particularly risks from data poisoning and weakened guardrails.
Why it matters: Defense contractors, military cyber personnel, and government security officials should understand the Pentagon's prioritization of expanding cyber offensive capabilities and AI-enabled operations, which will shape acquisition programs, workforce requirements, and operational doctrine going forward.
Researchers identified Go-based malware distributed through Terraform providers and Go modules hosted on HashiCorp's centralized registry, representing the first known abuse of this platform as a malware delivery vector. Two malicious Terraform providers and Go modules were discovered, with one package recording 222 downloads before detection.
Why it matters: Practitioners using Terraform and Go dependencies must validate package sources and monitor their supply chain, as legitimate repositories are now targeted for malware distribution.
Researchers and experts increasingly view scenarios where artificial intelligence (AI) systems operate independently toward their own objectives as plausible threats. The article explores growing concerns about AI autonomy and potential internet takeover risks among the security and technology community.
Why it matters: Security practitioners should monitor AI safety research and system controls because uncontrolled AI behavior could compromise critical infrastructure, networks, and organizational systems that defenders protect.
As artificial intelligence (AI) safety concerns drive investor interest, cybersecurity stocks rise and venture capital flows into startups building AI-native security solutions. Companies like Instinct and Simile have attracted nine-figure funding rounds at valuations reflecting market demand for next-generation defenses.
Why it matters: Security practitioners should track emerging AI-focused security vendors and evaluate whether existing tools adequately address AI-specific threats and use cases in their environments.
An in-depth essay argues that industrial cybersecurity must move beyond asset inventories and network monitoring to focus on physical resilience and verified recovery capabilities. The author introduces the Nana Equation (Presence × Awareness × Verification × Recovery × Time = Resilience Value) to evaluate whether backup systems, manual fallbacks, and independent protections actually function during cyber incidents. The piece emphasizes leveraging field technicians to validate that physical infrastructure matches digital records and that safeguards remain present and operational over time.
Why it matters: Industrial operators and security teams need to verify that resilience measures actually work before relying on them during incidents; shared technological dependencies across facilities can create hidden failure domains that affect both operational safety and insurance coverage.
A race condition in Apache Tomcat Native versions 1.3.0 through 1.3.8 and 2.0.0 through 2.0.15 allows client certificate verification requirements to be downgraded during thread execution. The vulnerability, classified as moderate severity, affects configurations that rely on mandatory client certificate authentication.
Why it matters: Operators running affected Tomcat Native versions with required client certificate verification should patch immediately, as attackers could bypass authentication by exploiting the race condition.
CVE-2026-86246 affects Apache Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8, which initialize resources with insecure OpenSSL options enabled by default, including client renegotiation, absent extended master secret protection, unexpected end-of-file handling, and key exchange without Diffie-Hellman. The vulnerability carries moderate severity. Organizations running affected Tomcat Native versions should review and apply available patches or disable insecure options.
Why it matters: Tomcat deployments using affected Native versions expose TLS connections to client renegotiation attacks and weakened key negotiation, requiring immediate patch evaluation and testing.
CVE-2026-86243 is a buffer over-read vulnerability in Apache Tomcat Native during TLS handshake processing that allows a malicious user to crash the Java Virtual Machine (JVM). The vulnerability affects Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8. Updates and patches are available for affected installations.
Why it matters: Organizations running Apache Tomcat with the Native library must upgrade to patched versions to prevent denial of service attacks that could crash their application servers.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.