2026-10-01
Red Siege InfoSec Blog
This is not the Access Policy you’re looking for
Talos Intelligence
Give yourself room to be human
ReversingLabs
Why the smartest LLMs are not-so-smart pen testers
Microsoft Security
Insights from the 2026 Microsoft Digital Defense Report
Microsoft Security
Preparing governments for an era of interconnected cyber risk
Palo Alto Networks
Observability’s AI Moment
Cloudflare
AI Search is now generally available
MIT Technology Review
The Download: AI “mind-reading” and creative uses for small batteries
CISA Alerts & Advisories
ABB Protection and Control IED Manager PCM600
CISA Alerts & Advisories
CISA Malcolm
CISA Alerts & Advisories
Johnson Controls EasyIO Neo Series EC and CW Controllers
CISA Alerts & Advisories
Meari IoT Cloud Platform OpenAPI Service
CISA Alerts & Advisories
Armatura LLC Armatura One
CISA Alerts & Advisories
Monta monta.app
CISA Alerts & Advisories
Johnson Controls EasyIO Neo Series EC and CW Controllers
Schneier on Security
Connected Cars Are a Surveillance Platform
MIT Technology Review
An AI “mind-reading” tool can reconstruct what you’re looking at from a brain scan
Talos Intelligence
The Fine Art of Frustrating the Adversary
MIT Technology Review
How smaller, distributed batteries could help the grid
Resecurity
Session Cookie Authentication Bypass: Predictable Signing Secret Enableds Account Impersonations
Accomplish
Thinking Inside the Box
2026-09-30
Embrace The Red
From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)
Dark Reading
Trump, Tech Giants Strike Voluntary AI Safety Accord
Ars Technica Security
Attackers have been exploiting critical Zimbra flaw to steal emails
Dark Reading
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
Step Security
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes
White Knight Labs
Automating AI Hacking with Tree of Attack
Microsoft Security
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Cloudflare
Identify AI model overuse with User Insights
Cloudflare
Simplifying domains for people and agents
Bishop Fox Security
Separating Signal from Slop: Triaging CVEs in the Age of AI Security Research
Cloudflare
The Internet has a second audience
MIT Technology Review
The Download: OpenAI’s chief research officer explains its hacking response
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Ars Technica Security
Cloudflare plans to issue quantum-safe TLS certificates
Schneier on Security
I Want Better Reporting on AI Genie Behavior
MIT Technology Review
“We’re not going to shoot ourselves in the foot” over hack fallout, says OpenAI’s chief research officer
Talos Intelligence
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Palo Alto Networks
“SASE Gateway” provided by KDDI : How SP Interconnect Simplifies Closed Network Zero Trust
Datadog HQ
How we built an async-aware Python profiler
2026-09-29
Microsoft Security
Phishing Abuses RMM Tools for Persistent Access
Palo Alto Networks
Introducing CLARA Agent: Instant Cloud & AI Risk Insights Available on Google Cloud Gemini Enterprise
Microsoft Security
Beyond source code: A path to the keys to the kingdom
ReversingLabs
Can advanced math make AI systems safer?
Bishop Fox Security
Zilliz / Attu | 2.6.5
MIT Technology Review
The Download: climate tech companies to watch and AI’s discovery problem
CISA Alerts & Advisories
VIVOTEK Camera Firmware
CISA Alerts & Advisories
Viidure Dashcam Android Application
CISA Alerts & Advisories
MikroTik RouterOS
CISA Alerts & Advisories
Lantronix G520 Series Cellular Gateway
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
Anjvision YSSD-RTMP-H5
CISA Alerts & Advisories
Toptech TMS7 and TopHAT
CISA Alerts & Advisories
Baicells Nova 430H
Schneier on Security
Using Device Linking to Eavesdrop on WhatsApp and Signal
MIT Technology Review
Coming soon: Our 2026 list of Climate Tech Companies to Watch
MIT Technology Review
Making AI an asset, not an expense
Talos Intelligence
Securing the keys to the kingdom: Announcing Executive Threat Detection
Shielder Blog
louis-rs Security Audit
Palo Alto Networks
Why OT Resilience Is Now a Boardroom Imperative
Voidstar Security Research Blog
A Hacker's Guide to ARM Tracing - ETM, ITM, and the TPIU
Elastic Security Labs
No MDM for Linux? A 68-line Elastic workflow keeps every endpoint's config current
Rosecurify
Seclog - #197
2026-09-28
MIT Technology Review
Roundtables: The Deadly Failures of The Virtual Border Wall
Github Security Blog
How we found 24 Android vulnerabilities using our open source AI security agent
MIT Technology Review
When can we say AI made a scientific discovery?
Offensive Security
CVE-2026-85706: GitLab Unauthenticated Arbitrary File Read via the Repository Commits API
Krebs on Security
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Microsoft Security
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
GitGuardian
GitHub Copilot Security and Privacy Concerns: Understanding the Risks and Best Practices
Schneier on Security
New Attack Against RSA
watchTowr Labs
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)
Palo Alto Networks
Securing AI Agents at Scale with NVIDIA
Malwarebytes
A week in security (September 21 – September 27)
Elastic Security Labs
Quarantined isn't contained: Agentic phishing response with Elastic and Sublime
2026-09-27
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
2026-09-26
2026-09-25
Krebs on Security
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
Schneier on Security
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Ars Technica Security
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
Eye Security Research
Rise of the Jev-Clones
Bishop Fox Security
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
Malwarebytes
Criminals turn placeholder domain into ClickFix trap
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Schneier on Security
On Anthropic’s AI Misuse Report
Trail of Bits
Don't let TEEs break your MPC
Teleport Blog
How to Eliminate Shared Production Kubeconfigs