2026-10-09
Dark Reading
AI Scramble Drives Cybersecurity M&A Boom
Cloudflare
Introducing Clef-omni with full multimodality, plus a faster Clef and a cheaper Clef-flash
Dark Reading
What We Missed: FBI Strikes Back at ShinyHunters
Step Security
GhostAction Returns: Malicious “Security Audit” Workflows Now Mine Credentials from Entire Git Histories
Dark Reading
Social Engineering AI Agents: The New BEC for 2026
Cloudflare
Introducing on-demand CPU and memory profiling with flamegraphs for Workers and Durable Objects
Cloudflare
Deno is joining Cloudflare
MIT Technology Review
The Download: AI’s refusal problem and weight-loss drug side effects
Socket
New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials
MIT Technology Review
We’re putting too much faith in AI’s ability to say no
MIT Technology Review
Job titles of the future: Delivery drone air traffic controller
MIT Technology Review
We’re still figuring out the side effects of GLP-1 weight-loss drugs
ISC SANS
ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)
MIT Technology Review
Roundtables: A Conversation With the Creator of AI-Designed Viruses
Semgrep
The End Is Nigh for Code Review
2026-10-08
Microsoft Security
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Ars Technica Security
Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027
Step Security
StepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines
Talos Intelligence
Making sure the checks get printed
Github Security Blog
How one bug bounty researcher chooses the features they investigate
Jericho
Concert Review: Tricky
Google Safety & Security
Sign in quickly and securely with passkeys.
The Citizen Lab
The Secrets of a US Spyware King
Malwarebytes
Amazon has an uncomfortably personal profile on you
MIT Technology Review
The Download: AI roadblocks for humanoids and portable rubber dams
Dark Reading
Writing the Next Chapter
CISA Alerts & Advisories
Grid Protection Alliance openPDC and openHistorian
CISA Alerts & Advisories
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
CISA Alerts & Advisories
Satel Netco Design
CISA Alerts & Advisories
Red Lion Controls N-Tron 700 Series
Schneier on Security
How Technology Empowers—and Imperils—Dictators
Zero Day Initiative
Pwn2Own Ireland 2026 - Day Three Results & Master of Pwn
Talos Intelligence
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Talos Intelligence
Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
MIT Technology Review
Why we’re watching these climate tech companies
MIT Technology Review
AI breakthroughs in robotics won’t change your life any time soon
MIT Technology Review
Building a safer path to autonomous industrial AI
Step Security
Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It
Teleport Blog
How to Tie Kubernetes Audit Logs to Individual Engineers
Simon Koeck
A Single POST Freezes Any Next.js Server
Elastic Security Labs
Introducing AlertZero: Inbox zero for your alert queue
2026-10-07
Amazon Security
Building your AI vulnerability harness, Part 1
Dark Reading
OpenAI Agent Escape Causes Wikimedia Service Outage
Talos Intelligence
Microsoft, Adobe, Apple, and Foxit vulnerabilities
Eclypsium
BTS #83 - AI's Impact on Cybersecurity
Amazon Security
Part 1 – Cybersecurity journeys: I didn’t plan this
Microsoft Security
3 lessons from frontier AI vulnerability research
ReversingLabs
CRA compliance will be judged by the binary you ship
Jericho
Colfax
Google Safety & Security
We're making it easier to identify AI-generated content globally.
Krebs on Security
ShinyHunters Extorted Boeing Spin-off Prior to Arrests
MIT Technology Review
The Download: weight-loss drugs slowing aging and carbon dioxide batteries
Schneier on Security
Apple’s Verified Photography System
Malwarebytes
Another ShinyHunters suspect arrested
Talos Intelligence
One breach, please, and make no mistakes
Zero Day Initiative
Pwn2Own Ireland 2026 - Day Two Results
Infernux Blog
Log Baseline 0.5.0 and the log baseline explorer
2026-10-06
Dark Reading
Critical Healthcare Systems Aren't Quantum-Ready
Ars Technica Security
Hackers obtain counterfeit TLS certificates for Google and other large services
PortSwigger
The model isn't cooperating
watchTowr Labs
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
Amazon Security
Identity-aware AI data agents with AWS Lake Formation and Trusted Identity Propagation
Meta Security
NTS: Authenticated Time at Meta
Microsoft Security
CISO perspectives on managing vulnerability risks in the age of AI
Mozilla Security
Strengthen your online security for free with Firefox
Malwarebytes
ASOS “hackers” send push notifications to customers
Wiz
Introducing Wiz AI SAST: Application Security that Understands Your Code and Your Infrastructure
Bishop Fox Security
Why the AI Attack Surface Extends Your Stack
Ars Technica Security
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
Malwarebytes
Facebook Marketplace scam uses your name and number
CISA Alerts & Advisories
Johnson Controls EasyIO FG
CISA Alerts & Advisories
Savannah lwIP SMTP client
CISA Alerts & Advisories
Hitachi Energy RTU500
CISA Alerts & Advisories
Hitachi Energy SOI
CISA Alerts & Advisories
Hitachi Energy Asset Suite
CISA Alerts & Advisories
Hitachi Energy REB500
Schneier on Security
Possible Vulnerability in Apple’s Automatic Reboot
Zero Day Initiative
Pwn2Own Ireland 2026 - Day One Results
TrustedSec
Logging is a Discipline, Not a Switch
Teleport Blog
How to Reduce Overprivileged Kubernetes Service Accounts
Yunus Aydın
Mage AI git config’inde command injection
Yunus Aydın
Command injection in Mage AI’s git config
2026-10-05
Ars Technica Security
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Amazon Security
AWS Continuum sets a new standard in autonomous code security
Zero Day Initiative
Pwn2Own Ireland 2026 - The Full Schedule
Red Siege InfoSec Blog
Trust, But Verify: What Clients Should Know Before a Mobile Application Assessment
The Citizen Lab
Fixer, Financier, Spymaster: How the UAE’s Sheikh Tahnoon is Setting His Sights on AI Dominance
Cloudflare
One year later: the power of 1.1.1.1 interns
Schneier on Security
Another Historic Cipher Falls to AI
Malwarebytes
A week in security (September 28 – October 4)
ISC SANS
ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
Elastic Security Labs
Behind the tags: How Elastic SIEM grades 1,781 detection rules on noise, speed, and threat coverage
2026-10-04
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Troy Hunt
Weekly Update 524: Live From Copenhagen
2026-10-03
2026-10-02
Ars Technica Security
Apple changes full-disk access permissions to curb abuse from AI agents
Schneier on Security
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing