The latest security reporting, combined across sources and tagged, newest first.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by Really Simple Syndication (RSS). No account required.
Why now: this site build contains 7,457 stories, with the newest available reporting below.
Dubai's Electronic Security Center built Saraab, an artificial intelligence (AI) model that detects deepfake videos with 91% accuracy, and plans to open source the tool to enable improvements by researchers, AI companies, and cybersecurity experts.
Why it matters: Security teams evaluating deepfake detection capabilities gain access to an open-source option backed by a government cybersecurity regulator, reducing reliance on proprietary solutions.
Eva Velasquez, who has led the Identity Theft Resource Center (ITRC) for 14 years, will retire as CEO in January 2027. She reflects on the organization's evolution, identity crime trends, and the importance of victim support in addressing emerging threats.
Why it matters: Security and privacy practitioners should understand ITRC's role in victim recovery and identity crime trends as the organization transitions leadership and continues addressing evolving threats.
ShinyHunters, an extortion gang, claims to have breached Federal Bureau of Investigation (FBI) systems by exploiting a previously unknown Oracle PeopleSoft zero-day vulnerability. The group alleges it accessed internal services and exfiltrated sensitive data concerning employees and job applicants.
Why it matters: FBI and Oracle customers running PeopleSoft need immediate verification of their systems against this claimed zero-day; organizations handling employment data face potential credential theft and identity compromise if the breach is confirmed.
ShinyHunters claims to have breached multiple FBI-related services and obtained personal data on FBI employees and job applicants, including names, home addresses, phone numbers, and spouse information. The group shared details of the alleged breach with 404 Media as part of an escalating dispute with the agency.
Why it matters: Federal law enforcement and security practitioners need to assess whether FBI systems and contractor networks are compromised, as widespread exposure of employee personal data could enable targeting and operational security risks.
Crypt::SelfCertificate, a Perl module available on CPAN, versions 1.01 through 1.05 contain embedded malware that executes Python code from an obfuscated URL. The vulnerability was assigned CVE-2026-95831 and disclosed by the CPAN Security Group on September 22, 2026.
Why it matters: Perl developers and DevOps teams using Crypt::SelfCertificate should immediately audit their dependencies and upgrade to a patched version, as the affected versions execute arbitrary code during installation or runtime.
Tracker inference
vulnerabilitiesResearchTracker priority: Track*CVE-2026-89082CVE-2026-89083+1 more
HP Advance and HP Output Central contain three unauthenticated vulnerabilities that enable remote code execution (RCE) with system privileges, authorization bypass, and arbitrary file operations. The issues affect HP's print and scan management products, as disclosed on September 22, 2026.
Why it matters: Organizations running HP Advance or HP Output Central face unauthenticated SYSTEM RCE exposure without authentication; prioritize patching these products immediately to prevent remote compromise.
CVE-2026-17613 affects Penpot design software and allows cross-team file takeover via import-binfile functionality due to a missing permission check. The vulnerability was disclosed publicly on August 4, 2026, but remains unpatched in released versions including 2.17.2 as of September 22, 2026, despite a fix existing in the development branch since August 5, 2026.
Why it matters: Penpot users on shared instances face unauthorized file access and modification by other teams; practitioners managing Penpot deployments should evaluate whether to restrict import-binfile functionality or upgrade once a patched release is available.
A stack-based buffer overflow vulnerability in SAP Extended Passport (EPP) processing affects ICM, SAP Web Dispatcher, and dialog work processes, allowing unauthenticated attackers to execute code remotely. The vulnerability was disclosed by nullFaktor Security via Fulldisclosure on September 22, 2026.
Why it matters: Organizations running SAP ICM, Web Dispatcher, or dialog work processes face immediate risk of compromise from unauthenticated remote code execution; patch availability and deployment status should be verified urgently.
A Windows malware called ClosedQuorum leverages large language models from Google, DeepSeek, Qwen, and Mistral to make autonomous decisions during post-compromise phases of attacks. The malware uses artificial intelligence (AI) to dynamically select and execute attack actions without explicit attacker commands.
Why it matters: Windows administrators and security teams need to understand that adversaries are now automating attack progression with LLMs, making detection and response harder when malware can self-direct its actions rather than awaiting command and control instructions.
Researchers discovered a malicious npm package called tw-pkgprobe-7731 that impersonates a Twilio security testing tool. The package was designed to steal credentials from developers who integrated it into their applications.
Why it matters: Developers using npm packages for Twilio integrations face immediate risk of credential theft if they installed this malicious package between August and disclosure; teams should audit their dependencies and rotate any exposed credentials.
Threat actors obtained a stolen OAuth token from a former CrowdSec employee's computer during the TanStack npm supply chain attack and used it to access and steal 170 private repositories from the company's GitHub account.
Why it matters: CrowdSec users and customers face potential exposure of security tools and internal processes; organizations relying on CrowdSec should assess whether sensitive data or credentials were exposed in the stolen repositories.
Shadow IT creates visibility gaps by introducing unmanaged endpoints and unauthorized software that evade traditional monitoring. Wazuh outlines an approach using endpoint inventory, agentless monitoring, and centralized analysis to help organizations identify and address these blind spots.
Why it matters: Security teams need visibility into all assets touching their network; shadow IT risks leaving malware, misconfigurations, and policy violations undetected.
Honeywell's 2026 Operational Technology Cybersecurity Benchmark Report finds that operational technology (OT) security planning has shifted from technology-centric approaches to business-focused resilience strategies, driven by major attacks and geopolitical tensions. The maturation includes cautious adoption of artificial intelligence (AI) in OT environments and reflects emerging regulatory pressures.
Why it matters: OT security leaders and practitioners need to understand this industry shift toward resilience frameworks and AI integration, as it indicates where peer organizations are directing resources and how regulatory expectations are evolving.
Growing reports of artificial intelligence (AI) misalignment incidents have prompted organizations across sectors, including major AI labs and nation-states, to reassess safety measures and control mechanisms. The incidents highlight ongoing challenges in securing AI systems and maintaining alignment with intended behavior.
Why it matters: Security practitioners need to understand how AI safety gaps affect their infrastructure and threat models, particularly as organizations increasingly deploy AI-powered systems in critical functions.
F5 released an advisory on September 22, 2026 disclosing a critical vulnerability in BIG-IP APM with confirmed active exploitation. CERT-EU recommended immediate remediation actions for affected organizations.
Why it matters: Organizations running F5 BIG-IP APM are at risk from active attacks and should prioritize patching or applying mitigations without delay.
A critical vulnerability in Bifrost, an open-source artificial intelligence (AI) gateway routing requests to multiple large language model (LLM) providers, allows unauthenticated attackers to execute arbitrary commands on the gateway server via a single HTTP request. CVE-2026-90898 carries a CVSS score of 9.8 and affects all versions of Bifrost HTTP transport before 2.1.0 when management authentication is enabled.
Why it matters: Organizations deploying Bifrost as an AI gateway face immediate remote code execution (RCE) risk without authentication requirements; teams should upgrade to version 2.1.0 or later to patch this critical flaw.
Check Point Software released emergency hotfixes to address a critical vulnerability in its Security Management Server that permits arbitrary script execution. The flaw was actively exploited in attacks at the time of disclosure.
Why it matters: Organizations running Check Point Security Management Server must apply the hotfixes immediately to block ongoing exploitation attempts targeting their management infrastructure.
OpenStack Octavia versions 0.8.0 through 16.1.0, 17.0.0, and 18.0.0 contain HAProxy configuration injection vulnerabilities that allow remote code execution. The flaws are tracked as CVE-2026-94572 and CVE-2026-94571 and were disclosed on September 21, 2026.
Why it matters: Organizations running affected versions of Octavia must patch immediately to eliminate remote code execution risk in their load balancing infrastructure.
Z.ai's ZCode tool collected entire user workspaces, including project histories, and uploaded them to Alibaba Cloud without user consent or disclosure, storing them with encryption keys only the company controlled. After researcher Ferstar disclosed the issue, Z.ai apologized, stated the data was never used for model training, and open sourced ZCode on GitHub. The company removed the problematic Repository Index and Repo Wiki features and engaged third-party assessors to verify deletion of previously uploaded data.
Why it matters: Developers using ZCode face exposure of proprietary code and project history; teams should audit what data may have been uploaded before the feature removal and verify their sensitive materials were not retained.
CVE-2026-87082 affects Net::IDN::Punycode versions before 2.590 for Perl, where unvalidated malformed UTF-8 input in the encode_punycode function can cause the application to hang, crash, or produce incorrect output. The vulnerability arises from insufficient input validation when processing Punycode encoding operations. Developers using affected versions should upgrade to 2.590 or later.
Why it matters: Perl developers and applications that depend on Net::IDN::Punycode for domain name encoding must patch immediately to prevent denial of service or data corruption in production systems handling internationalized domain names.
Tracker inference
No stories match your current filters. Reset search and filters to show all stories.
Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.