Washignton, DC, USA, 30th September 2026, CyberNewswire
Category: Global Security News
Global Security News
Tech CEOs Privately Questioned Amodei for Sounding AI Alarm Bells
Nvidia CEO Jensen Huang was among the executives at Tuesday’s White House event who called out the Anthropic leader for his warnings about the technology’s capabilities.
Global Security News
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
Global Security News
Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed “RedFlick” to deploy its signature CosmicPulse backdoor. […]
Global Security News
Before Deploying Microsoft Copilot, SMBs Must Secure Data
Microsoft Copilot and AI agents are opening new opportunities for small and midsize businesses — but adoption also creates new questions around security, data governance, compliance and cost. Channel Insider Managing Editor Victoria Durgin speaks with Bruno Lecoq, Co-Founder, CEO & CISO at BEMO, a Microsoft-focused cybersecurity and compliance firm, about what SMBs and their…
Global Security News
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. […]
Global Security News
WatchGuard fixes critical Fireware OS flaw allowing remote code execution
WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with…
Global Security News
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,…
Global Security News
OpenAI takes on Microsoft and Google with office productivity push
OpenAI unveiled its long-rumored productivity software suite Tuesday with the launch of Pages, a collaborative document editor for ChatGPT. A slides app is also on the way, the company announced at its DevDay event. The Pages app is accessed via a new Space tab, which OpenAI describes as a “new home for your team to…
Global Security News
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.
Global Security News
GTT Defense Halo Brings AI into Network Security
GTT Communications is expanding its security portfolio with Defense Halo, a new network defense platform that embeds AI-driven threat detection and remediation capabilities into the company’s global network infrastructure. Converging network, cloud, and security operations GTT Defense Halo is an AI-native network defense platform, built on GTT’s AI factory and deployed as a dedicated instance…
Global Security News
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform’s security measures to prevent accidental leaks of sensitive data. […]
Global Security News
openSUSE Leap adds a new security layer: Immutable mode
One of the more secure Linux distributions has added another feature to help further lock it down.
Global Security News
A Vulnerability in Cisco Catalyst SD-WAN Manager Could Allow for Authentication Bypass
A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow for authentication bypass. Cisco Catalyst SD-WAN Manager is the centralized dashboard used to monitor and manage SD-WAN fabric devices, in some deployments up to several thousand devices from a single console. An attacker could exploit this vulnerability by sending…
Global Security News
A Vulnerability in Apple Products Could Allow for Arbitrary Code Execution
A vulnerability has been discovered in Apple products that could allow for arbitrary code execution. macOS Sequoia (macOS 15) is an operating system version for Mac computers released by Apple in late 2024. macOS Tahoe (macOS 26) is an operating system version for Mac computers released by Apple in late 2025. iOS is Apple’s mobile…
Global Security News
FTC Opens Investigation of Anthropic and OpenAI
Agency aims to use its consumer-protection powers to examine whether AI labs have misled the public about dangers from the technology.
Global Security News
AI Governance on AWS: The Runtime Control Loop: AI Governance on AWS: Four Functions, One Loop, and a Deadline That Already Passed
Answer this without checking: how many AI agents are running in your environment right now? Most security leaders give an estimate and a shrug. That is a fair response, because agents get spun up by an engineer solving a problem on a Tuesday afternoon, through a path that puts them on nobody’s radar. In August…
Global Security News
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management…
Global Security News
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. “Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
Global Security News
OneTrust Brings Policy Enforcement into AI Agent Workflows
OneTrust is launching CORIE, a new AI governance layer designed to enforce enterprise policies as AI agents operate, as the company expands its platform to address governance challenges created by increasingly autonomous AI systems. Announced as part of TrustWeek 2026, CORIE—short for Contextual Orchestration for Reasoning, Intelligence and Evidence—draws on an organization’s existing privacy, consent,…
Global Security News
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. […]
Global Security News
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
New with iOS 27 (and iPadOS 27) is a setting called Impersonation Risk Detection that aims to warn you of suspicious activity that could trap you in a scam.
Global Security News
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Global Security News
Hackers steal protective order and foster care records from Arizona courts
“Arizona’s court system was targeted by a cyber attack from criminal hackers or their bots.” This is how the Arizona Supreme Court announced that hackers had attacked the state’s court system and stolen the personal information of “many Arizonans.” The court says the attack began with a phishing email containing a malicious link that a…
Global Security News
Microsoft Opens Dragon Copilot Specialization for Healthcare Partners
Healthcare AI gives partners a deployment challenge that extends beyond getting the software running: helping clinicians use it in their daily work. Microsoft announced on September 22 that eligible partners can earn its new Clinical Applications specialization starting September 30. The recognition covers proven expertise in deploying Dragon Copilot for healthcare customers and can open…
Global Security News
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager’s API as the admin user. Fixed releases are available, and there is…
Global Security News
Russia’s Star Blizzard Ditches ClickFix to Widen Phishing Net
The APT actor is using a new tactic, dubbed “RedFlick,” against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
Global Security News
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have…
Global Security News
Logitech CEO Scouring the Globe to Beat Chip Shortage
Hanneke Faber on “begging and borrowing” her way through the AI-drive squeeze and applying the lessons learned at Unilever and P&G to tech.
Global Security News
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. […]
Global Security News
Legit Security launches agentic remediation for open-source dependency vulnerabilities
Tel Aviv, Israel, 30th September 2026, CyberNewswire
Global Security News
OpenAI Marketplace Lets Enterprises Spend AI Commitments on Partner Software
OpenAI is giving enterprise customers another place to put money they have already committed to AI. The company launched OpenAI Marketplace at DevDay 2026, allowing eligible enterprise customers to apply part of their existing OpenAI commitment toward qualifying software from approved partners. The initial roster includes 32 vendors spanning cybersecurity, customer experience, development, legal technology,…
Global Security News
Trump’s answer to AI’s image problem: Industry self-regulation and a new name
US President Donald Trump has ordered the federal government to call artificial intelligence “Super Intelligence,” while keeping the technology’s legal definition unchanged and relying on industry to set the rules for its use. In an executive order, the White House administration said modern systems “far exceed what was envisioned when the term ‘Artificial Intelligence’ first…
Global Security News
AI’s Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. […]
Global Security News
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise
Global Security News
Unsloth’s model picker had a code-execution problem
True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the…
Global Security News
Apple issues urgent iOS patch as it navigates the spyware arms race
If you’ve not done so recently, you should update your Apple systems now as the company continues to fight sophisticated, targeted hacks. The latest patch protects against what the company called “an extremely sophisticated attack against specific targeted individuals.” Apple recently published an emergency security patch for users on iOS 26 and iPadOS 26 to fix…
Global Security News
Microsoft to block Entra ID script injection attacks starting October
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. […]
Global Security News
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments
DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last week’s Justice Department indictment of Oxygen Forensics looked, at first, like an American procurement scandal. CEO Lee Reiber and Russian co-founder Oleg Davydov stand accused of hiding that the company was Russian-owned…
Global Security News
Sherweb Rebrands MicroWarehouse, Names Ireland EMEA HQ
Sherweb is bringing Irish IT solutions provider MicroWarehouse fully under its brand and making Ireland its European headquarters as the Canadian cloud distributor expands its MSP business across Ireland and the UK. The move follows Sherweb’s 2024 acquisition of MicroWarehouse, which continued operating under its existing name while gaining access to Sherweb’s broader resources. Sherweb…
Global Security News
Trump, Six AI Giants Sign ‘Super Intelligence’ Safety Accord
Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight
Global Security News
ESET Revamps Channel Security Portfolio for the AI Era
ESET has revamped its ESET PROTECT portfolio with three new security tiers designed to help channel partners shift from selling standalone cybersecurity products toward recurring, service-based security offerings. The updated portfolio combines MDR, AI security, ransomware and phishing protection, and additional services, including guided onboarding, cybersecurity awareness training, and a cyber warranty that provides up…
Global Security News
Auvik, Acronis Bring Network Management Into RMM
Auvik and Acronis are partnering to bring network monitoring and management directly into Acronis RMM, expanding the platform’s capabilities as MSPs look to consolidate more of their IT management stack. Under the OEM partnership announced Sept. 30, Auvik’s network management capabilities will be natively integrated into Acronis RMM, the remote monitoring and management offering within…
Global Security News
OpenAI’s New Agent Delivers a Reality Check for the Enterprise
Plus, three questions for Toshiba America’s CIO
Global Security News
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two recently disclosed NetScaler vulnerabilities that have been exploited as zero-days, says Mandiant CTO Charles Carmakal. Mandiant and Google Threat Intelligence Group (GTIG) know of dozens of impacted organizations across North America and Europe,…
Global Security News
Pearson’s Workera deal targets a big workplace problem: No time to AI upskill
Pearson has agreed to acquire Workera to help businesses assess employees’ AI skills and target training where it’s needed most.
Global Security News
TeamViewer urges users to patch severe flaws “as soon as possible”
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. […]
Global Security News
AI Boosts SOC Analyst Capacity but Limits Skill Development
Swimlane finds that AI is reducing repetitive work for SOC teams but some feel their careers may suffer
Global Security News
Know Your Enemy: Browser-Based Attack Techniques in 2026
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous…
Global Security News
AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it, according to Glow Labs. Diagram showing how AI agents leak screenshots to public repos (Source: Glow Labs) The researchers found more than 13,000 internal images published openly on GitHub…
Global Security News
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat…
Global Security News
Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware
Cybersecurity researchers at Huntress identify campaign to deliver potent trojan which targets users searching for ChatGPT via Google
Global Security News
Your car’s app could be telling Big Tech who you are and where you go
A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data. Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come…
Global Security News
Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
An Amazon Prime phishing campaign is using fake payment alerts to steal account logins, personal data and complete credit or debit card details from unsuspecting customers.
Global Security News
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. […]
Global Security News
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
Global Security News
OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. OpenInfra Europe’s security incident notice “Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove…
Global Security News
Pentagon personnel database breach exposes personal data of millions
A Pentagon personnel database was breached for nine months without anyone noticing. Over three million people are affected. Read more in my article on the Hot for Security blog.
Global Security News
SHARED INTEL Q&A: AI finds flaws faster — defenders still need to fix what attackers exploit
Security teams are being told they have hours to patch. Related: AI agents have a Lord of the Flies problem The warning has a real basis. In June, Anthropic’s frontier red team demonstrated an AI model building working exploits from freshly patched Firefox and Windows kernel vulnerabilities, one of them in 31 minutes. Meanwhile ZeroDayClock,…
Global Security News
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. Talos first observed UAT-11587 activity in September 2025. By July 2026, Talos had identified at least 16…
Global Security News
WaterISAC reckons with range of threats after summer of cyberattacks
The computers that automate water treatment systems across the country were built for durability, not for an internet-connected world. Many still accomplish their fundamental function, but as cyberattacks on the sector mounted this summer, water industry officials say those aging systems, especially internet-exposed operational technology and programmable logic controllers, remain among the easiest ways for…
Global Security News
The MFA you have isn’t the MFA you think you have
For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason — adding a second factor to a password login closed off an enormous share of…
Global Security News
Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Product Updates
Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response. It also ties up analyst capacity…
Global Security News
Your guide to Google Messages’ new hidden gestures
One of the most rewarding parts of being a Certified Android Explorer™ is the geeky pleasure that comes with uncovering a hidden shortcut Google snuck somewhere into its smartphone software. One of the most exhausting parts, in contrast, is realizing that Google randomly changed a bunch of the shortcuts you’d found and developed the muscle…
Global Security News
Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore
Signal users who switch from an Android phone to an iPhone, or the other way around, can take their message history with them, and backups can be restored on Android, iOS, Linux, macOS and Windows. The option is part of a set of backup updates the company finished rolling out with Signal for iOS version…
Global Security News
Now We’re All Starting to Talk Like AI Chatbots Too
In team meetings, group texts and over lattes, people are catching themselves using ‘prompt speak.’
Global Security News
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a GPT) is essentially a version of ChatGPT…
Global Security News
Can we jail a superintelligence?
AI containment is essential, but security leaders should assume every boundary can fail once an agent can communicate, use tools, and act on real systems. On September 17, podcaster Steven Bartlett asked four AI experts an unusual question: Could you build a jail for a digital Einstein? The panel on The Diary of a CEO…
Global Security News
8 Top Red Teaming Service Providers for Enterprise Adversary Emulation
Compare 8 top red teaming providers for enterprise adversary emulation, from DeepSeas and Mandiant to CrowdStrike, IBM, SpecterOps, TrustedSec and NCC Group.
Global Security News
Apple Patches CoreGraphics Zero Day Exploited in Attacks
Apple has patched CVE-2026-86950, a zero-day bug in the iOS CoreGraphics engine
Global Security News
Whatever happened to the 36-month IT security roadmap?
Insight Global’s John Dickson had a problem familiar to many CISOs today. Employees were embracing AI tools faster than his security team could track them, and new AI agents and service integrations spread rapidly across the environment alongside them. Dickson and his security org had plans to build visibility into those non-human identities (NHIs), tracking…
Global Security News
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
Global Security News
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such…
Global Security News
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS…
Global Security News
Former US Air Force members behind million-dollar BEC scheme head to prison
Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison. According to public documents and evidence presented at sentencing, Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, both from Delaware, spent nearly two years sending spam and…
Global Security News
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been…
Global Security News
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
Global Security News
Genea brings AI agents to access control with role-based permissions
Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform. Onboarding a new hire, setting up a contractor for two weeks, or unlocking the loading dock now takes one sentence instead of a dozen clicks. Genea is one of the…
Global Security News
Security tools can now scan Claude Enterprise chats and uploads for sensitive data
More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already uses. CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare and Zscaler are among them. For a Claude Enterprise customer, the feed includes the conversations themselves, the files people…
Global Security News
OWASP Noir: Open-source static analysis tool
OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow APIs, the endpoints that live in the code but never made it…
Global Security News
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that’s rooted…
Global Security News
DigiCert Supports NVIDIA Open Agent Safety Platform with Verifiable Identity for Agents
DigiCert AI Trust Manager brings cryptographic identity, authority, and an enforceable kill switch for autonomous agents running in NVIDIA OpenShell.
Global Security News
SAS named a Leader in worldwide decision intelligence platforms
SAS has been named a Leader in the IDC MarketScape: Worldwide Decision Intelligence Platforms 2026 Vendor Assessment.
Global Security News
EU Cyber Resilience Act requirements for containers and Kubernetes
Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026, with full enforcement kicking in on Dec. 11, 2027. The CRA brings new requirements for teams working…
Global Security News
In this new SME cybersecurity service, the AI assists and the consultants decide
BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized enterprises (SMEs) access to its specialist consultants, supported by a proprietary AI tool for analysis, evidence review, regulatory mapping and reporting. Ireland and the UK come first, with the Nordic countries and other…
Global Security News
Most open critical and high flaws are over 90 days old
Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old. Of the critical and high-severity vulnerabilities open at the time of the snapshot, 97% in the Nordics had been exposed for more than…
Global Security News
WSL containers are generally available on Windows
Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls images from. WSL containers run Linux containers on Windows through the Windows Subsystem for Linux. They install with wsl –update or from Microsoft’s GitHub releases page. If your developers work on Windows…
Global Security News
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes. Cisco says…
Global Security News
Post-quantum website certificates from Cloudflare are scheduled for early 2027
Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and prove who they are. The company said that its CA will issue conventional certificates and a post-quantum type called Merkle Tree Certificates (MTCs), with production MTC issuance scheduled for the first quarter of…
Global Security News
Essential Eight Maturity Model: What Applies Now and What ASD Is Changing
The Essential Eight maturity model, last updated in November 2023, is still the current framework Australian organisations are assessed against. ASD consulted in June and July…
Global Security News
TrendAI™ extends the NVIDIA Agent Safety Platform with threat intelligence and full AI factory security
TrendAI Vision One™ pairs hardware-level detection on NVIDIA BlueField DPUs and network security with Zero Day Initiative™ threat intelligence, helping enterprises safely move…
Global Security News
ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
Kinetic IT named a Leader in ISG Provider Lens® 2026 Public Sector Services and Solutions study
Independent recognition reflects Kinetic IT’s deep public sector experience and expanding technology capabilities.
Global Security News
The Future of Managed Cloud Services: AI, Automation, and Beyond
Managed cloudhttps://andersenlab.com/services/managed-cloud services are an operational model in which a specialized provider continuously manages, secures, monitors, and…
Global Security News
How to Search the Dark Web Safely: What an .onion Search Engine Actually Indexes
In this post, I will show you how to search the Dark Web safely and what an .onion search engine actually indexes. “Dark web” is a technical description, not a moral one. The name covers anything reachable only through an anonymity network: .onion services on Tor, eepsites on I2P, and the smaller networks beside them.…
Global Security News
8 Companies Delivering CVE-Free Container Images in 2026
In this post, I will show you 8 companies delivering CVE-Free container images in 2026. Key Takeaways “CVE-free” can mean zero at delivery, zero under contract, or zero beyond the base layer, and only the last two hold up over time. Echo is the top pick, extending CVE-free coverage from the base image to application…
Global Security News
Wall Street’s Hopes for a Blockbuster IPO Season Are Starting to Fade
Investors were clamoring for newly issued shares a few months ago, but a recent string of delayed offerings illustrates how quickly investors’ enthusiasm for shares of risky new companies can cool.
Global Security News
5 Best virtual CISO companies of 2026
Key Takeaways – A virtual CISO should function as a security leader, not simply as an external compliance consultant. – Effective engagements usually begin with an assessment…
Global Security News
Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
Meta is once again repositioning itself to target the enterprise market. This week, the company announced the Meta Enterprise Platform, which it says will evolve its AI stack into products and services that enterprises can deploy into operations, rather than just using them for advertising and social media campaigns. While the company provided few details…
Global Security News
Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. […]
