2026-09-18
Schneier on Security
Friday Squid Blogging: On Squid Egg Sacs
Socket
Happy Birthday, Shai-Hulud
Dark Reading
MFA Won't Save You From OAuth Consent Abuse
Ars Technica Security
Researchers used Claude to hack OpenAI
Bishop Fox Security
From Fork to Framework: What Modifying Apollo Taught Us About Agent Invasion
MIT Technology Review
The Download: AI’s extinction risk and bioweapons threat
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
MIT Technology Review
Could AI really kill us all? Your questions, answered.
Schneier on Security
Are AIs Still Struggling with CAPTCHAs?
Trail of Bits
Auditing in the age of (good enough) AI
MIT Technology Review
The specter of AI-enabled bioweapons is a wake-up call for biotech
Palo Alto Networks
Defining the Standard for AI Security
Elastic Security Labs
One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless
2026-09-17
Malwarebytes
Flock cameras are tracking people as well as cars
Ars Technica Security
LLMs respond differently to harmful prompts when AI watermarking is used
Talos Intelligence
Should you care about an “AI slowdown?”
Microsoft Security
From guidance to action: Security fundamentals that materially reduce risk
Malwarebytes
Revolut phishing texts appear days after data breach
Bishop Fox Security
MikroTrick: Inside the RouterOS Takeover Chain
MIT Technology Review
The Download: mice with part-human brains and climate tech innovators
CISA Alerts & Advisories
ABB Ability Edgenius
CISA Alerts & Advisories
Schneider Electric Modicon M340 Controller and Communication Modules
CISA Alerts & Advisories
Bransys ELD
CISA Alerts & Advisories
Schneider Electric NetBotz 5 750/755
CISA Alerts & Advisories
Hitachi Energy FACTS Control Platform (FCP)
CISA Alerts & Advisories
Mitsubishi Electric GX Works3 and Motion Control Settings
CISA Alerts & Advisories
Schneider Electric PowerChute Serial Shutdown
CISA Alerts & Advisories
Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
Schneier on Security
How Candidates Could Use AI for Good
Talos Intelligence
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
MIT Technology Review
Meet the innovators under 35 shaping climate tech
Ars Technica Security
Hackers reveal how Flock cameras really track cars and people
TrustedSec
Unpacking a laZzzy Donut
Praetorian
Credentials Are Still the Shortest Path In
2026-09-16
Ars Technica Security
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
Zero Day Initiative
The Apple Security Update Review for September 2026
Krebs on Security
Data Broker Radaris Loses Domains in Privacy Fight
Dark Reading
Fighting Your Dragons Through Tough Tech Times
ReversingLabs
Memory-safe programming goes from advocacy to adoption
MIT Technology Review
Meet a mouse whose brain cortex is made up of human cells
MIT Technology Review
Building the materials foundation for AI
MIT Technology Review
The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid
CISA News
New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Using Cyber Decoys to Strengthen Detection and Response
Schneier on Security
Fake CAPTCHA Scams
core-jmp
Red Heron Exploits Gitea n-day CVE-2026-60004, Exposing JITTERLY and the SIXZUT Linux Rootkit
Talos Intelligence
Securing the unpatchable in an age of AI-driven vulnerabilities
Datadog HQ
Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines
Sansec Threat Research
Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
2026-09-15
MIT Technology Review
Roundtables: Could AI really kill us all?
Amazon Security
Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline
Malwarebytes
How to opt out of AI chatbot training
ReversingLabs
AI coding puts Secure by Design in the spotlight
MIT Technology Review
The Download: AI doomers, whistleblowing agents, and de-aged livers
CISA Alerts & Advisories
Siemens Reyrolle 7SR5
CISA Alerts & Advisories
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
CISA Alerts & Advisories
CareCam CM2507
CISA Alerts & Advisories
mySCADA myPRO Manager
CISA Alerts & Advisories
Schneider Electric SCADAPack x70 Products
CISA Alerts & Advisories
Siemens Mendix SAML
CISA Alerts & Advisories
Wärtsilä FOS-Onboard
CISA Alerts & Advisories
Digital Watchdog VMAX DVR and NVR Product Lineups
CISA Alerts & Advisories
Siemens Teamcenter
Schneier on Security
25 Years of Mass Surveillance Is Enough
Trail of Bits
1Password's AI patching benchmark is misleading
Schneier on Security
On the NSA’s Supercomputer from the 1960s
CrankySec
Appeal to deez nutz
Accomplish
Escaping the OpenAI Codex sandbox, twice
2026-09-14
Schneier on Security
Upcoming Speaking Engagements
Palo Alto Networks
FedRAMP Moderate Authorization for Palo Alto Networks Quantum-Safe Security
Schneier on Security
Using AI for Weapons Development
Aikido
Dependabot vs Renovate
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Schneier on Security
Microsoft’s Patching
Malwarebytes
A week in security (September 7 – September 13)
Rosecurify
Seclog - #195
Datadog HQ
Datadog named the Company to Beat for observability platforms in 2026 Gartner® AI Vendor Race report
Elastic Security Labs
The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions