Cyber Security
CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Mitchell Langley
October 1, 2026
Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
Cybersecurity
MetaMask Discloses Incident, Exits Ethereum Validators
Gabby Lee
October 1, 2026
MetaMask disclosed a security incident affecting its staking infrastructure and is proactively exiting Ethereum validators it runs through the Lido protocol.
CVE Vulnerability Alerts
TeamViewer Patches Critical Access-Control Bypass Flaw
Andrew Doyle
October 1, 2026
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
CVE Vulnerability Alerts
WatchGuard Patches Critical Root Code Execution Flaw
Gabby Lee
October 1, 2026
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CVE Vulnerability Alerts
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
Gabby Lee
October 1, 2026
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Gabby Lee
October 1, 2026
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Cybersecurity
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
Andrew Doyle
October 1, 2026
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
CVE Vulnerability Alerts
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
Gabby Lee
October 1, 2026
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Andrew Doyle
October 1, 2026
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Application Security
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Andrew Doyle
October 1, 2026
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
Gabby Lee
September 30, 2026
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
Cybersecurity
France Tax Agency Breached Seven Weeks via Stolen Passwords
Mitchell Langley
September 30, 2026
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
CVE Vulnerability Alerts
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Gabby Lee
September 30, 2026
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
Cybersecurity
FBI Tells ShinyHunters Members to Turn Themselves In
Gabby Lee
September 30, 2026
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Cybersecurity
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Gabby Lee
September 30, 2026
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Cybersecurity
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Mitchell Langley
September 30, 2026
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Application Security
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
Gabby Lee
September 30, 2026
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
Application Security
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Mitchell Langley
September 30, 2026
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Cybersecurity
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Gabby Lee
September 30, 2026
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Application Security
101 Malicious npm Packages Add Developers to WhatsApp Groups
Gabby Lee
September 30, 2026
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Mitchell Langley
October 1, 2026
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Mitchell Langley
September 29, 2026
TOP CYBERSECURITY HEADLINES
CVE Vulnerability Alerts
WatchGuard Patches Critical Root Code Execution Flaw
CVE Vulnerability Alerts
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Cybersecurity
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
This Week’s Security Spotlight
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Mitchell Langley
September 29, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
WatchGuard Patches Critical Root Code Execution Flaw
October 1, 2026
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
October 1, 2026
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
October 1, 2026
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
October 1, 2026
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
October 1, 2026
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
October 1, 2026
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Chrome, Firefox Patch Over 100 Flaws in Joint Update
October 1, 2026
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Pentagon Records Agency Breach Exposes Data on 3 Million
September 30, 2026
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
France Tax Agency Breached Seven Weeks via Stolen Passwords
September 30, 2026
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
September 30, 2026
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
FBI Tells ShinyHunters Members to Turn Themselves In
September 30, 2026
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
September 30, 2026
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
September 30, 2026
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
September 30, 2026
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
September 30, 2026
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
September 30, 2026
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
101 Malicious npm Packages Add Developers to WhatsApp Groups
September 30, 2026
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
Glow Security Finds 13,000 Exposed AI Agent Screenshots
September 30, 2026
Glow Security found over 13,000 sensitive screenshots from AI coding agents publicly exposed on GitHub across 343 companies in a finding called PixelLeak.
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
September 30, 2026
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
September 30, 2026
Two former US Air Force members received a combined 189-month federal prison sentence for running a multi-year business email compromise and phishing scheme.























