2026-10-06
Ars Technica Security
Hackers obtain counterfeit TLS certificates for Google and other large services
PortSwigger
The model isn't cooperating
watchTowr Labs
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
MIT Technology Review
Weight-loss drugs show signs of slowing biological aging, say drugmakers
Amazon Security
Identity-aware AI data agents with AWS Lake Formation and Trusted Identity Propagation
Meta Security
NTS: Authenticated Time at Meta
Microsoft Security
CISO perspectives on managing vulnerability risks in the age of AI
Mozilla Security
Strengthen your online security for free with Firefox
Malwarebytes
ASOS “hackers” send push notifications to customers
Wiz
Introducing Wiz AI SAST: Application Security that Understands Your Code and Your Infrastructure
Bishop Fox Security
Why the AI Attack Surface Extends Your Stack
Ars Technica Security
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
Malwarebytes
Facebook Marketplace scam uses your name and number
MIT Technology Review
The Download: 10 climate tech companies to watch
CISA Alerts & Advisories
Savannah lwIP SMTP client
CISA Alerts & Advisories
Hitachi Energy RTU500
CISA Alerts & Advisories
Hitachi Energy REB500
CISA Alerts & Advisories
Hitachi Energy Asset Suite
CISA Alerts & Advisories
Johnson Controls EasyIO FG
CISA Alerts & Advisories
Hitachi Energy SOI
Schneier on Security
Possible Vulnerability in Apple’s Automatic Reboot
MIT Technology Review
Form Energy and its iron batteries
MIT Technology Review
Brimstone and its one-stop process for making cleaner cement and critical minerals
MIT Technology Review
X-energy and its helium-cooled nuclear reactors
MIT Technology Review
WaveSave and its portable rubber dam
MIT Technology Review
Energy Dome and its carbon dioxide batteries
MIT Technology Review
WeLion New Energy and its semi-solid-state batteries
MIT Technology Review
Here’s how our climate team picked 10 promising companies to watch
MIT Technology Review
2026 Climate Tech Companies to Watch
Zero Day Initiative
Pwn2Own Ireland 2026 - Day One Results
TrustedSec
Logging is a Discipline, Not a Switch
Yunus Aydın
Mage AI git config’inde command injection
Yunus Aydın
Command injection in Mage AI’s git config
2026-10-05
Ars Technica Security
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Amazon Security
AWS Continuum sets a new standard in autonomous code security
Zero Day Initiative
Pwn2Own Ireland 2026 - The Full Schedule
The Citizen Lab
Fixer, Financier, Spymaster: How the UAE’s Sheikh Tahnoon is Setting His Sights on AI Dominance
Cloudflare
One year later: the power of 1.1.1.1 interns
Schneier on Security
Another Historic Cipher Falls to AI
Malwarebytes
A week in security (September 28 – October 4)
ISC SANS
ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
Elastic Security Labs
Behind the tags: How Elastic SIEM grades 1,781 detection rules on noise, speed, and threat coverage
2026-10-04
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Troy Hunt
Weekly Update 524: Live From Copenhagen
2026-10-03
2026-10-02
Ars Technica Security
Apple changes full-disk access permissions to curb abuse from AI agents
Schneier on Security
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
Cloudflare
8 major updates to Cloudflare Observability
Schneier on Security
Unidentified Flock Cameras in Florida
Dark Reading
Vulnerability Backlogs Are an Ownership Problem
Cloudflare
Introducing Web Search API via AI Gateway
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Schneier on Security
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
Trail of Bits
SequenceHash: multihashing for the rest of us
Compass Security Blog
Pwn2Own Ireland 2025 – Home Assistant
core-jmp
Static Devirtualization of Tencent VM: ACE Kernel Drivers, CET, SEH, and Guided Symbolic Execution
core-jmp
Bypassing EDR with Local AI
Binary Security
Azure’s Weakest Link - Five Full Cross-Tenant Compromises
Socket
Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX
ISC SANS
ISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120, (Fri, Oct 2nd)
Datadog HQ
Monitor Databricks with Datadog
Datadog HQ
Databricks’ native monitoring resources
Datadog HQ
Key metrics for monitoring Databricks
2026-10-01
Dark Reading
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Ars Technica Security
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Talos Intelligence
Give yourself room to be human
ReversingLabs
Why the smartest LLMs are not-so-smart pen testers
Microsoft Security
Insights from the 2026 Microsoft Digital Defense Report
Microsoft Security
Preparing governments for an era of interconnected cyber risk
Palo Alto Networks
Observability’s AI Moment
Cloudflare
AI Search is now generally available
Bishop Fox Security
One Port to Root: Weaponizing Check Point Management CVE-2026-93616
CISA Alerts & Advisories
CISA Malcolm
CISA Alerts & Advisories
Monta monta.app
CISA Alerts & Advisories
Meari IoT Cloud Platform OpenAPI Service
CISA Alerts & Advisories
ABB Protection and Control IED Manager PCM600
CISA Alerts & Advisories
Armatura LLC Armatura One
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
Johnson Controls EasyIO Neo Series EC and CW Controllers
CISA Alerts & Advisories
Johnson Controls EasyIO Neo Series EC and CW Controllers
Schneier on Security
Connected Cars Are a Surveillance Platform
Talos Intelligence
The Fine Art of Frustrating the Adversary
Resecurity
Session Cookie Authentication Bypass: Predictable Signing Secret Enableds Account Impersonations
Teleport Blog
SSO-Backed kubectl Access Across Many Clusters
Accomplish
Thinking Inside the Box
2026-09-30
Embrace The Red
From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)
Dark Reading
Trump, Tech Giants Strike Voluntary AI Safety Accord
Ars Technica Security
Attackers have been exploiting critical Zimbra flaw to steal emails
Dark Reading
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
Step Security
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes
White Knight Labs
Automating AI Hacking with Tree of Attack
Jericho
September: The Screen Critic
Microsoft Security
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Bishop Fox Security
Separating Signal from Slop: Triaging CVEs in the Age of AI Security Research
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Ars Technica Security
Cloudflare plans to issue quantum-safe TLS certificates
Schneier on Security
I Want Better Reporting on AI Genie Behavior
Talos Intelligence
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Palo Alto Networks
“SASE Gateway” provided by KDDI : How SP Interconnect Simplifies Closed Network Zero Trust
Datadog HQ
How we built an async-aware Python profiler
2026-09-29
Microsoft Security
Phishing Abuses RMM Tools for Persistent Access
Palo Alto Networks
Introducing CLARA Agent: Instant Cloud & AI Risk Insights Available on Google Cloud Gemini Enterprise