CYBERSECURITYTRACKER
TRACKING7,578 stories in this site build1,625 vulnerability news stories in this site build

State now. Changed: +17 tier promotions, +4 known-exploited vulnerability additions, 1975 leak-site claims, and 4 confirmed breaches since yesterday.

Why today matters ·Today

News

The latest security reporting, combined across sources and tagged, newest first.

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.

Why now: this site build contains 7,578 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
government policy

UK PM Vows to Combat Russian 'Industrial Scale' Disinfo

Source: HealthcareInfoSecurity.

The UK Prime Minister, Andy Burnham, described Russian disinformation as an industrial-scale assault during a UN speech and attributed narratives of national decline to Russian hostile actors. His remarks signal a renewed focus on countering Kremlin-sponsored information warfare targeting Britain.

Why it matters: Practitioners monitoring threat intelligence from nation-state actors should track UK policy responses and any corresponding technical indicators of Russian disinformation campaigns targeting UK infrastructure, media, or electoral systems.

Tracker inference

ransomware

Texan Scattered Spider Member Receives 45-Month Sentence

Source: HealthcareInfoSecurity.

Ahmed Elbadawy, a member of the cybercrime group Scattered Spider, pleaded guilty to wire fraud and identity theft charges. He received a 45-month federal prison sentence and must forfeit $18 million in cryptocurrency seized from his involvement in dozens of attacks.

Why it matters: Organizations targeted by Scattered Spider should review incident logs and credential access patterns to identify any compromise tied to Elbadawy's known attack campaigns, and security teams should track the group's remaining operational members.

Tracker inference

ransomware

Cyber Extortion Group Claims: 'We Have Compromised the FBI'

Source: HealthcareInfoSecurity.

Cyber extortion group ShinyHunters claims to have accessed Federal Bureau of Investigation (FBI) systems and obtained personal information belonging to employees, demanding removal of content about the group's operations in exchange for withholding disclosure. Security researchers view the claim as primarily a reputation-building tactic rather than a credible threat.

Why it matters: Federal law enforcement and organizations with employee data in FBI systems face potential exposure; practitioners should monitor for leaked credentials or personal information targeting government staff.

Tracker inference

vulnerabilities

Nightmare Eclipse Reveals Name, Story Behind MS Zero-Days

Source: HealthcareInfoSecurity.

Abdelhamid Naceri, a former Microsoft employee, disclosed that he is the researcher behind the Nightmare Eclipse campaign, which released multiple Windows and Defender zero-days including BigDiskBuster. Naceri framed the disclosures as retaliatory following an employment dispute and frustration with Microsoft's vulnerability-reporting process.

Why it matters: Windows and Defender users face active exposure to multiple unpatched zero-days; practitioners should prioritize patching and monitoring for exploitation of these vulnerabilities while Microsoft develops fixes.

Tracker inference

regulatory

UK regulator to investigate Pornhub parent company for alleged age verification failings

Source: The Record.

Ofcom, the UK communications regulator, announced an investigation into Pornhub's parent company regarding alleged failures in age verification. The investigation follows Pornhub's May implementation of an age assurance process that relies on signals from Apple to identify users under 18 in the UK who have completed Apple's age checks.

Why it matters: Website operators and digital platforms in the UK must ensure robust age verification controls; regulators are now actively scrutinizing compliance mechanisms, creating enforcement risk for inadequate implementations.

Tracker inference

vulnerabilitiesTracker priority: ActCVE-2026-85102

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Source: BleepingComputer.

Check Point disclosed active exploitation of CVE-2026-85102, a critical pre-authentication remote code execution (RCE) flaw in its Security Gateway virtual private network (VPN) certificate-handling component. The vulnerability carries a CVSS score of 9.8 and appears on the known exploited vulnerabilities list, indicating confirmed in-the-wild attacks.

Why it matters: Organizations deploying Check Point Security Gateway with VPN access must patch immediately, as adversaries are actively exploiting this flaw to achieve RCE with no authentication required.

Tracker inference

government policy

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

Source: CyberScoop.

A Department of Homeland Security inspector general report found that 86% of federal civilian agencies failed to implement cloud security policies required by a December 2024 Cybersecurity and Infrastructure Security Agency (CISA) directive with a June 2025 deadline. The missing configurations included blocking outdated authentication, enforcing multifactor authentication (MFA), and protecting sensitive data in cloud applications. CISA lacks enforcement authority over its binding operational directives, leaving federal cloud infrastructure vulnerable to preventable attacks.

Why it matters: Federal IT and security leaders face elevated risk of compromise in cloud environments; CISA's inability to mandate compliance exposes the entire government enterprise to preventable threats and demonstrates a systemic gap in cyber governance.

Tracker inference

ai security

IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin

Source: SecurityWeek.

IonQ unveiled a single-processor quantum error decoder designed to reduce the classical computing overhead required in quantum error correction processes. The development addresses a significant bottleneck in making quantum systems more practical and efficient.

Why it matters: Quantum computing researchers and organizations exploring quantum security implications should track advancements in error correction, as improvements may accelerate the timeline for practical quantum computers capable of breaking current encryption standards.

Tracker inference

government policy

No evidence of successful foreign meddling in 2024 election, spy agencies found

Source: The Record.

U.S. intelligence agencies completed a classified assessment of the 2024 presidential election and found no evidence that foreign adversaries successfully interfered in the voting process, according to officials familiar with the findings.

Why it matters: Government security practitioners and election officials should reference this assessment when evaluating defensive posture and resource allocation for election security infrastructure and foreign interference detection capabilities.

Tracker inference

vulnerabilitiesCVE-2024-0244

CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer

Source: Zero Day Initiative Blog.

CVE-2024-0244 is a heap buffer overflow in the Canon MF753Cdw printer's fax driver that allows unauthenticated remote code execution. A researcher discovered the vulnerability by analyzing the SOAP-based fax protocol, identifying that oversized length fields in the binary fax payload corrupt the heap and trigger an arbitrary free() call. Exploitation combines the vulnerability with Canon's BJNP protocol to place shellcode at known addresses and hijack function pointers for code execution.

Why it matters: Organizations using Canon MF753Cdw printers are exposed to unauthenticated remote code execution over the network; administrators should assess whether this printer model is deployed and review Canon's patching status for CVE-2024-0244.

Tracker inference

vulnerabilitiesCVE-2026-87902

Hackers start exploiting critical WordPress flaw for code execution

Source: BleepingComputer.

Threat actors have progressed from reconnaissance to active exploitation of CVE-2026-87902, a critical WordPress vulnerability that allows remote code execution (RCE) through file write and shell command execution. Attackers are now deploying this flaw in the wild to compromise WordPress installations.

Why it matters: WordPress site operators and their hosting providers must patch immediately; this vulnerability is under active exploitation and enables full system compromise through RCE.

Tracker inference

government policy

FBI probes cyberattack tied to third-party jobs portal

Source: Cybersecurity Dive.

The Federal Bureau of Investigation (FBI) is investigating a cyberattack involving a third-party jobs portal. The incident underscores supply chain vulnerabilities that affect organizations across sectors.

Why it matters: Organizations relying on third-party job portals face exposure to data compromise; practitioners should audit vendor access and incident response protocols for integrated recruitment platforms.

Tracker inference

government policy

Pentagon cyber chief: The demand far exceeds supply

Source: CyberScoop.

Katie Sutton, the Pentagon's assistant secretary of defense for cyber policy, stated that military demand for cyber capabilities substantially exceeds current supply and emphasized cyber warfare as an integrated tool alongside kinetic operations. She highlighted data denial as central to future military effectiveness and outlined concerns about artificial intelligence integration into cyber operations, particularly risks from data poisoning and weakened guardrails.

Why it matters: Defense contractors, military cyber personnel, and government security officials should understand the Pentagon's prioritization of expanding cyber offensive capabilities and AI-enabled operations, which will shape acquisition programs, workforce requirements, and operational doctrine going forward.

Tracker inference

threat intel

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Source: The Hacker News.

Researchers identified Go-based malware distributed through Terraform providers and Go modules hosted on HashiCorp's centralized registry, representing the first known abuse of this platform as a malware delivery vector. Two malicious Terraform providers and Go modules were discovered, with one package recording 222 downloads before detection.

Why it matters: Practitioners using Terraform and Go dependencies must validate package sources and monitor their supply chain, as legitimate repositories are now targeted for malware distribution.

Tracker inference

ai security

Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios

Source: SecurityWeek.

Researchers and experts increasingly view scenarios where artificial intelligence (AI) systems operate independently toward their own objectives as plausible threats. The article explores growing concerns about AI autonomy and potential internet takeover risks among the security and technology community.

Why it matters: Security practitioners should monitor AI safety research and system controls because uncontrolled AI behavior could compromise critical infrastructure, networks, and organizational systems that defenders protect.

Tracker inference

industry

What’s next for cybersecurity, according to Index Ventures’ Shardul Shah

Source: TechCrunch Security.

As artificial intelligence (AI) safety concerns drive investor interest, cybersecurity stocks rise and venture capital flows into startups building AI-native security solutions. Companies like Instinct and Simile have attracted nine-figure funding rounds at valuations reflecting market demand for next-generation defenses.

Why it matters: Security practitioners should track emerging AI-focused security vendors and evaluate whether existing tools adequately address AI-specific threats and use cases in their environments.

Tracker inference

ot ics

The Infrastructure Already Has Eyes. We Need to Teach Them What to See.

Source: Industrial Cyber.

An in-depth essay argues that industrial cybersecurity must move beyond asset inventories and network monitoring to focus on physical resilience and verified recovery capabilities. The author introduces the Nana Equation (Presence × Awareness × Verification × Recovery × Time = Resilience Value) to evaluate whether backup systems, manual fallbacks, and independent protections actually function during cyber incidents. The piece emphasizes leveraging field technicians to validate that physical infrastructure matches digital records and that safeguards remain present and operational over time.

Why it matters: Industrial operators and security teams need to verify that resilience measures actually work before relying on them during incidents; shared technological dependencies across facilities can create hidden failure domains that affect both operational safety and insurance coverage.

Tracker inference

vulnerabilitiesResearchCVE-2026-86247

CVE-2026-86247: Apache Tomcat Native: Client certificate requirements can be down-graded

Source: oss-security.

A race condition in Apache Tomcat Native versions 1.3.0 through 1.3.8 and 2.0.0 through 2.0.15 allows client certificate verification requirements to be downgraded during thread execution. The vulnerability, classified as moderate severity, affects configurations that rely on mandatory client certificate authentication.

Why it matters: Operators running affected Tomcat Native versions with required client certificate verification should patch immediately, as attackers could bypass authentication by exploiting the race condition.

Tracker inference

vulnerabilitiesResearchCVE-2026-86246

CVE-2026-86246: Apache Tomcat Native: Insecure OpenSSL options enabled

Source: oss-security.

CVE-2026-86246 affects Apache Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8, which initialize resources with insecure OpenSSL options enabled by default, including client renegotiation, absent extended master secret protection, unexpected end-of-file handling, and key exchange without Diffie-Hellman. The vulnerability carries moderate severity. Organizations running affected Tomcat Native versions should review and apply available patches or disable insecure options.

Why it matters: Tomcat deployments using affected Native versions expose TLS connections to client renegotiation attacks and weakened key negotiation, requiring immediate patch evaluation and testing.

Tracker inference

vulnerabilitiesResearchCVE-2026-86243

CVE-2026-86243: Apache Tomcat Native: DoS via TLS handshake

Source: oss-security.

CVE-2026-86243 is a buffer over-read vulnerability in Apache Tomcat Native during TLS handshake processing that allows a malicious user to crash the Java Virtual Machine (JVM). The vulnerability affects Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8. Updates and patches are available for affected installations.

Why it matters: Organizations running Apache Tomcat with the Native library must upgrade to patched versions to prevent denial of service attacks that could crash their application servers.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary