Monday, September 21, 2026
Cybersecurity News
Industry News
Expert Insights
Webinars
Learning Center
Topics
About
Sponsor
Cybersecurity News
Industry News
Expert Insights
Webinars
Learning Center
Topics
About
Sponsor
Combing the world for the cybersecurity stories you need to know.
Cybersecurity News
Fileless Rootkit Hides Malicious Script on F5 Servers
September 21, 2026
New research from Sophos X-Ops dismantles a core assumption behind years of web shell detection: that malicious code must eventually touch disk. That assumption went out the door when Sophos X-Ops discovered a Linux rootkit…
Read More >
Researchers Uncover New Attack That Steals Data From AI Workflows
September 20, 2026
Recent research from Noma Security’s Noma Labs has revealed a newly discovered attack leveraging legitimate, authorized use of AI workflows to obtain sensitive data. It starts with an attacker sending an ordinary message to a…
Read More >
CISA Eliminates Six Free Cybersecurity Assessments for Critical Infrastructure
September 16, 2026
The Cybersecurity and Infrastructure Security Agency has ended six free assessment programs that helped critical infrastructure operators find weaknesses in their cyber defenses, according to Cybersecurity Dive. The programs paired CISA’s Cyber Security Evaluation Tool,…
Read More >
500 Breaches Later, Medusa Ransomware Is Still Outrunning Its Warnings
September 14, 2026
The Medusa ransomware-as-a-service variant, first identified in June 2021, has been The United States Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) released an advisory concerning Medusa ransomware on March 12th,…
Read More >
Just One Website Visit Silently Hijacks NVIDIA AI Agent
September 13, 2026
It wasn’t phishing or a stolen credential. It was just a browser tab opened by a researcher. That’s all it took to seize control of a sandboxed NVIDIA AI coding agent. Recently disclosed by Oasis…
Read More >
UK Power Plant Cyberattack Comes Amid Wider OT Security Warnings
September 09, 2026
Hackers believed to be linked to Iran took a small British power generator offline for four days in July, in what is believed to be the first successful cyberattack to shut down a UK power…
Read More >
AI Agents Autonomously Breached Taiwan Government Networks in Four Days
September 08, 2026
In July 2026, government cybersecurity monitors began to flag anomalous activity on Taiwanese government infrastructure. The discovery was traced back to a 160-megabyte archive of agentic AI operational logs, and researchers quickly realized they were…
Read More >
ToxicPanda 2.0 Turns Wireless Debugging Into a Master Key for Android Banking Fraud
September 07, 2026
First discovered in late 2024 by cybersecurity company Cleafy, ToxicPanda has built up a known history in the past few years as an Android banking trojan with operations focused in Europe. Recently, Zimperium’s zLabs team…
Read More >
AI-Powered Vulnerability Hunting Is Outpacing Microsoft's Ability to Patch
September 04, 2026
A blog post published on August 13th by Microsoft’s Exchange Team outlines a further delay in the release of Exchange SE Cumulative Update 1 (CU1). The update was initially expected in the first half of…
Read More >
U.S. Deputizes Private Companies for Offensive Cyber Operations Against Criminal Networks
September 02, 2026
On August 12th, 2026, a presidential memorandum was published authorizing Participating Companies—vetted private contractors—to conduct government-directed cyber operations. The new program covers both Cyber Surveillance Operations and Cyber Effects Operations. While Surveillance Operations include intelligence…
Read More >
New Python Implant Uses Microsoft Services to Hide C2 Traffic
September 01, 2026
A newly identified Python malware framework uses Microsoft services to conceal its command-and-control (C2) activity, according to researchers at Ontinue. Dubbed TWINLOOT, the malware routes traffic through SharePoint and Teams infrastructure and uses a headless…
Read More >
OpenAI Can't Rule Out Astra Has Reached Critical Cyber Capability
August 31, 2026
OpenAI’s Astra model has been flagged for possible critical cyber capability, as the company states that it “cannot rule out” the possibility under its current Preparedness Framework. This is the first model to approach the…
Read More >
Gunra Ransomware Altered MFA to Maintain Access
August 26, 2026
Attackers using the Gunra ransomware altered a victim’s authentication system to create a persistent way around multi-factor authentication, according to a new joint U.S.-South Korean government advisory. The Aug. 10 warning from the FBI, CISA,…
Read More >
Google Cloud Maps Migration for Post-Quantum Cryptography
August 25, 2026
Securing infrastructure and services against the cryptographically relevant quantum computer of the future presents a major concern for the IT industry. Every encrypted connection will present a liability. The nation-state adversaries and organized threat actors…
Read More >
Paperclip Vulnerabilities Show How AI Agent Configuration Becomes Code
August 24, 2026
Open-source AI company Paperclip plays a significant role in orchestrating autonomous AI agents at scale, enabling organizations to centrally manage a company of AI agents. A design choice causes Paperclip to treat agent configuration as…
Read More >
Open Secure AI Alliance Targets Security Risks Exposed by Hugging Face Breach
August 21, 2026
NVIDIA says it and more than 100 organizations, including Microsoft, IBM, CrowdStrike, Dell Technologies, Palo Alto Networks, HPE, Red Hat, and Hugging Face, have formed the Open Secure AI Alliance to develop and share open…
Read More >
Research Finds Most Attacks Exploit Identity Trust, Not Bugs
August 17, 2026
BeyondTrust’s Phantom Labs was founded in 2025 to conduct research and share intelligence pertinent to the company’s security efforts. The recently released Phantom Labs Research Index explores the fruits of the first year of Phantom…
Read More >
AI Agents Approving Transactions Enterprises Can't See
August 14, 2026
Enterprise AI has quietly crossed a threshold. What began as a productivity layer for summarizing data and drafting reports has evolved into a class of digital workers with real authority, according to new research from…
Read More >
Subscribe for the Latest News
Webinars
Tuesday, Sep. 22
1pm ET / 10am PT
Beyond the Prompt: Securing AI to Unleash Innovation
Wednesday, Sep. 23
1pm ET / 10am PT
Unified Resilience: Consolidating Protection Across Data, Identity, and AI
Tuesday, Sep. 29
1pm ET / 10am PT
Unit 42 Insights: A Blueprint for Defending at the Speed of AI