2026-09-22
Ars Technica Security
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
The Citizen Lab
UN Reports Citing Citizen Lab Submissions Published
The Citizen Lab
Submission to the Immigration and Refugee Board of Canada
Malwarebytes
Some cheap smart glasses are a security disaster
Microsoft Security
Unmasking EvilTokens: Getting to the root of device code phishing
MIT Technology Review
Roundtables: The Deadly Failures of The Virtual Border Wall
GitGuardian
GitHub App Private Keys: 474 Leaked Keys Exposed
Cloudflare
Introducing Worker Previews: Isolated preview environments for every change your agent makes
MIT Technology Review
The Download: why AI’s latest breakthroughs and fears may be more hype than reality
CISA Alerts & Advisories
Siemens Siveillance Control
CISA Alerts & Advisories
lwIP (Lightweight IP)
CISA Alerts & Advisories
Siemens Industrial Edge Management
CISA Alerts & Advisories
OpenPLC Runtime v3
CISA Alerts & Advisories
Siemens WTV676 and WTV776
CISA Alerts & Advisories
Siemens SIPLUS and SIMATIC Products
Dark Reading
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
CISA Alerts & Advisories
Siemens Desigo CC family
CISA Alerts & Advisories
Siemens SIMOVE Fleetmanager and SIPLANT
CISA Alerts & Advisories
lwIP TCP/IP Stack MQTT Client Application
MIT Technology Review
Don’t be fooled by this summer of AI hype
Schneier on Security
GPT-6 Astra Breaks an Old Enigma Message
Talos Intelligence
The Closed Quorum: Inside the first reported autonomous AI C2 implant
Talos Intelligence
Introducing CAIRN: Frontier tracking for AI-integrated malware
Malwarebytes
Researchers used Claude to hack OpenAI
2026-09-21
Ars Technica Security
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Meta Security
Open-Sourcing Rebalancer: A Generic, High-Performance Library for Solving Assignment Problems
Amazon Security
Transforming Bedrock Guardrails events into OCSF with CloudWatch
Schneier on Security
Reverse-Engineering Flock Cameras
Offensive Security
10 Lessons Reshaping Security After Black Hat and DEF CON 2026
Cloudflare
Python Workers are now generally available
MIT Technology Review
The Download: investigating deaths at the US border’s “virtual wall”
MIT Technology Review
She died at the San Diego border. A surveillance camera was in plain sight
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
MIT Technology Review
The US spent billions on border surveillance. Why can’t it catch people before they die?
MIT Technology Review
4 ways to address the failures we found along the US border’s “virtual wall”
MIT Technology Review
How we made the first comprehensive map of deaths along the US border’s “virtual wall”
Trail of Bits
SAML: A fractal of bad design
Malwarebytes
A week in security (September 14 – September 20)
Rosecurify
Seclog - #196
Auth0
Building Secure AI Agents with Microsoft Agent Framework and Auth0: Human-in-the-Loop Approval
Elastic Security Labs
Cloud Threat Emulation on Autopilot: Context is Everything
2026-09-20
Artem Golubin
Real attackers don't think in bug bounty scopes
Ars Technica Security
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
MaskRay's Blog
Linker I/O tricks and their downsides
2026-09-19
Accomplish
Guest to host: escaping Docker's hypervisor
Joshua Rogers
Being silly is the whole point
2026-09-18
Schneier on Security
Friday Squid Blogging: On Squid Egg Sacs
Socket
Happy Birthday, Shai-Hulud
Dark Reading
MFA Won't Save You From OAuth Consent Abuse
Ars Technica Security
Researchers used Claude to hack OpenAI
Bishop Fox Security
From Fork to Framework: What Modifying Apollo Taught Us About Agent Invasion
MIT Technology Review
The Download: AI’s extinction risk and bioweapons threat
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
MIT Technology Review
Could AI really kill us all? Your questions, answered.
Schneier on Security
Are AIs Still Struggling with CAPTCHAs?
Trail of Bits
Auditing in the age of (good enough) AI
Elastic Security Labs
One SOC, 100 projects: running centralized alert triage on Elastic Security Serverless
2026-09-17
Malwarebytes
Flock cameras are tracking people as well as cars
Ars Technica Security
LLMs respond differently to harmful prompts when AI watermarking is used
Talos Intelligence
Should you care about an “AI slowdown?”
Microsoft Security
From guidance to action: Security fundamentals that materially reduce risk
Malwarebytes
Revolut phishing texts appear days after data breach
Bishop Fox Security
MikroTrick: Inside the RouterOS Takeover Chain
CISA Alerts & Advisories
Hitachi Energy FACTS Control Platform (FCP)
CISA Alerts & Advisories
Bransys ELD
CISA Alerts & Advisories
Mitsubishi Electric GX Works3 and Motion Control Settings
CISA Alerts & Advisories
ABB Ability Edgenius
CISA Alerts & Advisories
Schneider Electric NetBotz 5 750/755
CISA Alerts & Advisories
Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
CISA Alerts & Advisories
Schneider Electric PowerChute Serial Shutdown
CISA Alerts & Advisories
Schneider Electric Modicon M340 Controller and Communication Modules
Schneier on Security
How Candidates Could Use AI for Good
Talos Intelligence
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Ars Technica Security
Hackers reveal how Flock cameras really track cars and people
TrustedSec
Unpacking a laZzzy Donut
Praetorian
Credentials Are Still the Shortest Path In
2026-09-16
Ars Technica Security
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
Zero Day Initiative
The Apple Security Update Review for September 2026
Krebs on Security
Data Broker Radaris Loses Domains in Privacy Fight
Dark Reading
Fighting Your Dragons Through Tough Tech Times
ReversingLabs
Memory-safe programming goes from advocacy to adoption
CISA Alerts & Advisories
Using Cyber Decoys to Strengthen Detection and Response
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA News
New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity
Schneier on Security
Fake CAPTCHA Scams
core-jmp
Red Heron Exploits Gitea n-day CVE-2026-60004, Exposing JITTERLY and the SIXZUT Linux Rootkit
Talos Intelligence
Securing the unpatchable in an age of AI-driven vulnerabilities
Datadog HQ
Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines
Sansec Threat Research
Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware