Wednesday, September 30, 2026
Cybersecurity News
Industry News
Expert Insights
Webinars
Learning Center
Topics
About
Sponsor
Cybersecurity News
Industry News
Expert Insights
Webinars
Learning Center
Topics
About
Sponsor
Combing the world for the cybersecurity stories you need to know.
Cybersecurity News
65% of Companies Have Had an AI Agent Act Outside its Scope
September 30, 2026
Enterprise Management Associates (EMA) recently published a research report prepared for Cequence Security, “Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise.” The report reveals a number of alarming statistics, with an initial…
Read More >
CISA Updates Insider Threat Guide for AI, Remote Work, and Employee Departures
September 29, 2026
CISA updated its Insider Threat Mitigation Guide on Sept. 9, expanding a framework first published in 2020 to account for how much the workplace has changed. The update gives more attention to remote work and…
Read More >
OpenAI Agents Turned German Wiki Into Message Board
September 23, 2026
Independent researchers recently uncovered a previously undisclosed incident in which OpenAI agents used an obscure German-language programming wiki as a message board. The agents shared answers to evaluation tasks and notes about their operating environment,…
Read More >
Fake IT Support Calls on Microsoft Teams Breached 150 Employees
September 22, 2026
A recent publication from Palo Alto Networks’ Unit 42 research team offers insight into Microsoft Teams voice phishing (vishing) campaigns. This activity, dubbed Spring Ring, ran from January through April 2026 and was discovered based…
Read More >
Fileless Rootkit Hides Malicious Script on F5 Servers
September 21, 2026
New research from Sophos X-Ops dismantles a core assumption behind years of web shell detection: that malicious code must eventually touch disk. That assumption went out the door when Sophos X-Ops discovered a Linux rootkit…
Read More >
Researchers Uncover New Attack That Steals Data From AI Workflows
September 20, 2026
Recent research from Noma Security’s Noma Labs has revealed a newly discovered attack leveraging legitimate, authorized use of AI workflows to obtain sensitive data. It starts with an attacker sending an ordinary message to a…
Read More >
CISA Eliminates Six Free Cybersecurity Assessments for Critical Infrastructure
September 16, 2026
The Cybersecurity and Infrastructure Security Agency has ended six free assessment programs that helped critical infrastructure operators find weaknesses in their cyber defenses, according to Cybersecurity Dive. The programs paired CISA’s Cyber Security Evaluation Tool,…
Read More >
500 Breaches Later, Medusa Ransomware Is Still Outrunning Its Warnings
September 14, 2026
The Medusa ransomware-as-a-service variant, first identified in June 2021, has been The United States Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) released an advisory concerning Medusa ransomware on March 12th,…
Read More >
Just One Website Visit Silently Hijacks NVIDIA AI Agent
September 13, 2026
It wasn’t phishing or a stolen credential. It was just a browser tab opened by a researcher. That’s all it took to seize control of a sandboxed NVIDIA AI coding agent. Recently disclosed by Oasis…
Read More >
UK Power Plant Cyberattack Comes Amid Wider OT Security Warnings
September 09, 2026
Hackers believed to be linked to Iran took a small British power generator offline for four days in July, in what is believed to be the first successful cyberattack to shut down a UK power…
Read More >
AI Agents Autonomously Breached Taiwan Government Networks in Four Days
September 08, 2026
In July 2026, government cybersecurity monitors began to flag anomalous activity on Taiwanese government infrastructure. The discovery was traced back to a 160-megabyte archive of agentic AI operational logs, and researchers quickly realized they were…
Read More >
ToxicPanda 2.0 Turns Wireless Debugging Into a Master Key for Android Banking Fraud
September 07, 2026
First discovered in late 2024 by cybersecurity company Cleafy, ToxicPanda has built up a known history in the past few years as an Android banking trojan with operations focused in Europe. Recently, Zimperium’s zLabs team…
Read More >
AI-Powered Vulnerability Hunting Is Outpacing Microsoft's Ability to Patch
September 04, 2026
A blog post published on August 13th by Microsoft’s Exchange Team outlines a further delay in the release of Exchange SE Cumulative Update 1 (CU1). The update was initially expected in the first half of…
Read More >
U.S. Deputizes Private Companies for Offensive Cyber Operations Against Criminal Networks
September 02, 2026
On August 12th, 2026, a presidential memorandum was published authorizing Participating Companies—vetted private contractors—to conduct government-directed cyber operations. The new program covers both Cyber Surveillance Operations and Cyber Effects Operations. While Surveillance Operations include intelligence…
Read More >
New Python Implant Uses Microsoft Services to Hide C2 Traffic
September 01, 2026
A newly identified Python malware framework uses Microsoft services to conceal its command-and-control (C2) activity, according to researchers at Ontinue. Dubbed TWINLOOT, the malware routes traffic through SharePoint and Teams infrastructure and uses a headless…
Read More >
OpenAI Can't Rule Out Astra Has Reached Critical Cyber Capability
August 31, 2026
OpenAI’s Astra model has been flagged for possible critical cyber capability, as the company states that it “cannot rule out” the possibility under its current Preparedness Framework. This is the first model to approach the…
Read More >
Gunra Ransomware Altered MFA to Maintain Access
August 26, 2026
Attackers using the Gunra ransomware altered a victim’s authentication system to create a persistent way around multi-factor authentication, according to a new joint U.S.-South Korean government advisory. The Aug. 10 warning from the FBI, CISA,…
Read More >
Google Cloud Maps Migration for Post-Quantum Cryptography
August 25, 2026
Securing infrastructure and services against the cryptographically relevant quantum computer of the future presents a major concern for the IT industry. Every encrypted connection will present a liability. The nation-state adversaries and organized threat actors…
Read More >
Subscribe for the Latest News
Webinars
Thursday, Oct. 1
1pm ET / 10am PT
When Prevention Failed: Real Recovery Stories from the Trenches
Wednesday, Oct. 14
1pm ET / 10am PT
Exposure to Response: A Continuous Security Model for the AI era
Wednesday, Oct. 14
1pm ET / 10am PT
Stopping Exposure Before It Becomes a Breach Risk