Cyber Sec

TheHackerNews: Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shad  (28 September 2026)
TheHackerNews: Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Her  (28 September 2026)
TheHackerNews: JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete A  (28 September 2026)
TheHackerNews: CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Glob  (28 September 2026)
TheHackerNews: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploita  (27 September 2026)
TheHackerNews: Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Br  (26 September 2026)
TheHackerNews: Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shel  (26 September 2026)
TheHackerNews: Zero Trust for AI Agents Starts With Fixing Zero Visibility  (26 September 2026)
TheHackerNews: Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Craft  (26 September 2026)
TheHackerNews: SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild  (26 September 2026)
TheHackerNews: Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cy  (26 September 2026)
SEI/CERT: VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen  (25 September 2026)
SEI/CERT: VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vul  (25 September 2026)
TheHackerNews: Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai  (25 September 2026)
TheHackerNews: PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Pe  (25 September 2026)
TheHackerNews: The SOC Doesn't Need to Start Over with Every Alert  (25 September 2026)
TheHackerNews: Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Comp  (25 September 2026)
TheHackerNews: Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild  (25 September 2026)
TheHackerNews: Cloudflare Fixes Flaw That Let One Container Read Another Customer's L  (25 September 2026)
TheHackerNews: WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV  (25 September 2026)
sysdig: AI adoption is a security survival metric  (25 September 2026)
TheHackerNews: Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permis  (24 September 2026)
TheHackerNews: ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Co  (24 September 2026)
SEI/CERT: VU#676317: Norwegian Cruise Line door access controller contains an improper aut  (24 September 2026)
TheHackerNews: Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Ser  (24 September 2026)
TheHackerNews: Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic  (24 September 2026)
TheHackerNews: Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Call  (24 September 2026)
sysdig: Why are SBOMs failing to stop supply chain attacks?  (24 September 2026)
TheHackerNews: Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignor  (24 September 2026)
TheHackerNews: 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps:   (24 September 2026)
TheHackerNews: OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Pub  (24 September 2026)
TheHackerNews: TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Defa  (24 September 2026)
TheHackerNews: Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure  (24 September 2026)
SEI/CERT: VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Ko  (23 September 2026)
SEI/CERT: VU#273940: Enterprise Access Management EAM does not rotate RSA keys  (23 September 2026)
TheHackerNews: Attackers Use Malicious Terraform Providers to Deliver Go Malware via Hashi  (23 September 2026)
TheHackerNews: A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs a  (23 September 2026)
SEI/CERT: VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization con  (23 September 2026)
TheHackerNews: MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Passwor  (23 September 2026)
TheHackerNews: This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next   (23 September 2026)
TheHackerNews: Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and  (23 September 2026)
TheHackerNews: New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server C  (23 September 2026)
TheHackerNews: 545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent  (23 September 2026)
TheHackerNews: Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Test  (23 September 2026)
TheHackerNews: Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Contain  (23 September 2026)
TheHackerNews: F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE o  (23 September 2026)
TheHackerNews: Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP M  (23 September 2026)
TheHackerNews: Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via C  (23 September 2026)
TheHackerNews: ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applic  (23 September 2026)
SEI/CERT: VU#889462: Casdoor authentication server is vulnerable to authorization bypass  (22 September 2026)