Cyber Security
Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Gabby Lee
September 29, 2026
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
Application Security
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
Mitchell Langley
September 29, 2026
Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Mitchell Langley
September 29, 2026
OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Gabby Lee
September 29, 2026
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Mitchell Langley
September 29, 2026
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Cybersecurity
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
Mitchell Langley
September 29, 2026
A 24-year-old man was arrested in Amsterdam in early September as part of an investigation into the prolific ShinyHunters hacking group.
Application Security
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
Andrew Doyle
September 29, 2026
Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.
Cybersecurity
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
Mitchell Langley
September 29, 2026
Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.
Application Security
Bitget Attributes $388M Theft to Third-Party Security Product Flaw
Mitchell Langley
September 29, 2026
Bitget disclosed that attackers exploited a third-party security product vulnerability to steal $388 million on September 24. North Korean actors suspected.
Cybersecurity
RatHat Android Trojan Uses Gemini AI to Identify High-Value Victims
Mitchell Langley
September 29, 2026
RatHat malware-as-a-service banking trojan analyzes stolen Android data with Google Gemini AI to prioritize victims with higher financial value.
Cybersecurity
Infostealer Logs Expose AI Credentials from 80,000+ Organizations
Mitchell Langley
September 29, 2026
Stolen infostealer data exposed AI service credentials from over 80,000 corporate domains, enabling account takeover and LLMjacking attacks.
Cybersecurity
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
Gabby Lee
September 29, 2026
Cameron John Wagenius sentenced to 70 months in prison for hacking 10 U.S. technology and telecommunications companies while on active duty.
Application Security
Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI
Mitchell Langley
September 29, 2026
Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified 39-line prompt.
Application Security
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Andrew Doyle
September 29, 2026
Washington D.C. Department of Health Care Finance exposed approximately 400,000 Medicaid beneficiary records through a misconfigured web portal accessible without authentication.
Cybersecurity
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
Mitchell Langley
September 25, 2026
Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to North Korean hackers.
Application Security
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Mitchell Langley
September 25, 2026
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Application Security
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
Mitchell Langley
September 25, 2026
Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers' previous containers, violating tenant isolation controls.
Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
Mitchell Langley
September 25, 2026
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
Application Security
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
Andrew Doyle
September 25, 2026
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Gabby Lee
September 29, 2026
Application Security
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
Mitchell Langley
September 29, 2026
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Mitchell Langley
September 29, 2026
TOP CYBERSECURITY HEADLINES
This Week’s Security Spotlight
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Mitchell Langley
September 29, 2026
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Gabby Lee
September 29, 2026
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Andrew Doyle
September 25, 2026
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Mitchell Langley
September 25, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Ransomware Attack Disrupts Keio Corporation Business Systems
September 29, 2026
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
September 29, 2026
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
September 29, 2026
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
September 29, 2026
A 24-year-old man was arrested in Amsterdam in early September as part of an investigation into the prolific ShinyHunters hacking group.
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
September 29, 2026
Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
September 29, 2026
Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.
Bitget Attributes $388M Theft to Third-Party Security Product Flaw
September 29, 2026
Bitget disclosed that attackers exploited a third-party security product vulnerability to steal $388 million on September 24. North Korean actors suspected.
RatHat Android Trojan Uses Gemini AI to Identify High-Value Victims
September 29, 2026
RatHat malware-as-a-service banking trojan analyzes stolen Android data with Google Gemini AI to prioritize victims with higher financial value.
Infostealer Logs Expose AI Credentials from 80,000+ Organizations
September 29, 2026
Stolen infostealer data exposed AI service credentials from over 80,000 corporate domains, enabling account takeover and LLMjacking attacks.
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
September 29, 2026
Cameron John Wagenius sentenced to 70 months in prison for hacking 10 U.S. technology and telecommunications companies while on active duty.
Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI
September 29, 2026
Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified 39-line prompt.
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
September 29, 2026
Washington D.C. Department of Health Care Finance exposed approximately 400,000 Medicaid beneficiary records through a misconfigured web portal accessible without authentication.
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
September 25, 2026
Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to North Korean hackers.
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
September 25, 2026
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
September 25, 2026
Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers' previous containers, violating tenant isolation controls.
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
September 25, 2026
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
September 25, 2026
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
MacSync Malware Variant Uses iCloud Calendars for Command and Control
September 25, 2026
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
September 25, 2026
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
September 25, 2026
Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO devices. Unpatched.






















