2026-09-24
Github Security Blog
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
Red Siege InfoSec Blog
Red Siege at Wild West Hackin’ Fest Deadwood 2026: What to Expect
Talos Intelligence
Trust and the enticing consultancy offer
Microsoft Security
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Microsoft Security
What’s new in Microsoft Security: September 2026
Dark Reading
3 Cyber Threats That Defined the Summer of 2026
Dark Reading
Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
Bishop Fox Security
Unified Code, Unified Risks: Uncovering Vulnerabilities in .NET MAUI Applications
MIT Technology Review
The Download: a bid to scrap the virtual wall and AI hits Climate Week
CISA Alerts & Advisories
Siemens Mendix Runtime (Update A)
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Botslab G980H Dashcams
CISA Alerts & Advisories
Eufy Omni C20, Omni X10 Pro
Ars Technica Security
There's a new way to break RSA that's faster than anything we've seen before
Schneier on Security
Malicious npm Packages That Evade Defenses
MIT Technology Review
AI is dominating the conversation at Climate Week
TrustedSec
What's New in hate_crack Since 2.0
Project Black
Bypassing EDR with Local AI
Project Black
Bypassing EDR with Local AI
Accomplish
Escaping the Cloudflare sandbox
Meta Security
Bringing Private Processing to Meta AI Glasses
2026-09-23
watchTowr Labs
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Amazon Security
ICYMI: August 2026 @AWS Security
Ars Technica Security
FBI rushes to investigate if ShinyHunters hack of thousands of employees is real
Zero Day Initiative
CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer
MIT Technology Review
A congressional representative just proposed killing America’s border tower program
Microsoft Security
Reimagining the SOC for the agentic era in Microsoft Defender
Amazon Security
Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
Step Security
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes
Eye Security Research
AI vulnerability discovery using the Kitten process: How we found CVE-2026-75754
MIT Technology Review
The Download: India’s smart glasses menace and AI’s trillion-dollar gamble
CISA Alerts & Advisories
Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
Schneier on Security
Research on Models Engaging in Genie-Like Behavior
MIT Technology Review
The AI Hype Index: AI loves cheating
MIT Technology Review
Smart glasses are already causing havoc in India
Voidstar Security Research Blog
Extending Scapy for Hardware Reverse Engineering
Arch Cloud Labs
Testing BTRFS w/ Release Candidate Kernels on Arch Linux
Datadog HQ
Configure RUM SDKs remotely from Datadog
2026-09-22
Ars Technica Security
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
The Citizen Lab
UN Reports Citing Citizen Lab Submissions Published
The Citizen Lab
Submission to the Immigration and Refugee Board of Canada
Malwarebytes
Some cheap smart glasses are a security disaster
Microsoft Security
Unmasking EvilTokens: Getting to the root of device code phishing
MIT Technology Review
Roundtables: The Deadly Failures of The Virtual Border Wall
GitGuardian
GitHub App Private Keys: 474 Leaked Keys Exposed
Cloudflare
Introducing Worker Previews: Isolated preview environments for every change your agent makes
MIT Technology Review
The Download: why AI’s latest breakthroughs and fears may be more hype than reality
CISA Alerts & Advisories
Siemens SIPLUS and SIMATIC Products
CISA Alerts & Advisories
lwIP (Lightweight IP)
CISA Alerts & Advisories
Siemens Industrial Edge Management
CISA Alerts & Advisories
Siemens Siveillance Control
Dark Reading
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
CISA Alerts & Advisories
Siemens Desigo CC family
CISA Alerts & Advisories
OpenPLC Runtime v3
CISA Alerts & Advisories
Siemens WTV676 and WTV776
CISA Alerts & Advisories
Siemens SIMOVE Fleetmanager and SIPLANT
CISA Alerts & Advisories
lwIP TCP/IP Stack MQTT Client Application
CISA Alerts & Advisories
CISA Adds Four Known Exploited Vulnerabilities to Catalog
Palo Alto Networks
Introducing Unit 42 Continuous Frontier AI Defense
MIT Technology Review
Don’t be fooled by this summer of AI hype
Schneier on Security
GPT-6 Astra Breaks an Old Enigma Message
Talos Intelligence
The Closed Quorum: Inside the first reported autonomous AI C2 implant
Talos Intelligence
Introducing CAIRN: Frontier tracking for AI-integrated malware
Malwarebytes
Researchers used Claude to hack OpenAI
Project Black
Should I Azure AD Sync/Entra Cloud Sync Domain Admins?
Project Black
Should I Azure AD Sync/Entra Cloud Sync Domain Admins?
2026-09-21
Ars Technica Security
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Meta Security
Open-Sourcing Rebalancer: A Generic, High-Performance Library for Solving Assignment Problems
Amazon Security
Transforming Bedrock Guardrails events into OCSF with CloudWatch
Schneier on Security
Reverse-Engineering Flock Cameras
Offensive Security
10 Lessons Reshaping Security After Black Hat and DEF CON 2026
Cloudflare
Python Workers are now generally available
MIT Technology Review
The Download: investigating deaths at the US border’s “virtual wall”
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Trail of Bits
SAML: A fractal of bad design
Malwarebytes
A week in security (September 14 – September 20)
Rosecurify
Seclog - #196
Auth0
Building Secure AI Agents with Microsoft Agent Framework and Auth0: Human-in-the-Loop Approval
Elastic Security Labs
Cloud Threat Emulation on Autopilot: Context is Everything
2026-09-20
Artem Golubin
Real attackers don't think in bug bounty scopes
Ars Technica Security
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
MaskRay's Blog
Linker I/O tricks and their downsides
2026-09-19
Joshua Rogers
Being silly is the whole point
Accomplish
Guest to host: escaping Docker's hypervisor
2026-09-18
Schneier on Security
Friday Squid Blogging: On Squid Egg Sacs
Socket
Happy Birthday, Shai-Hulud
Dark Reading
MFA Won't Save You From OAuth Consent Abuse
Ars Technica Security
Researchers used Claude to hack OpenAI
Bishop Fox Security
From Fork to Framework: What Modifying Apollo Taught Us About Agent Invasion
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Schneier on Security
Are AIs Still Struggling with CAPTCHAs?
Trail of Bits
Auditing in the age of (good enough) AI