Source context

Why this day matters

  • Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.
  • Google Cloud published “Cloud CISO Perspectives: How cybersecurity startups can win CISOs”. Follow the canonical source link to read the original publication.
Validated article intelligence

Enriched source records

Expand a row to inspect claims and citations

Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.

Luna-enriched source article · helpnetsecurity

Most open critical and high flaws are over 90 days old

Detectify analyzed exposure data from 1,293 customers in the US, UK, and Nordics and found that most serious flaws still open on internet-facing systems were months old.

2 retained claims2 cited excerpts

Source published Sep 30, 2026, 4:00 AM UTC · Evidence retrieved Sep 30, 2026, 8:51 AM UTC

What happened

Detectify analyzed exposure data from 1,293 customers in the US, UK, and Nordics and found that most serious flaws still open on internet-facing systems were months old. [1]

Among critical and high-severity vulnerabilities open at the snapshot, more than 90 days of exposure was reported for 97% in the Nordics, 92% in the UK, and 86% in the US. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old.
  2. [2]
    Of the critical and high-severity vulnerabilities open at the time of the snapshot, 97% in the Nordics had been exposed for more than 90 days, along with 92% in the UK and 86% in the US.

Read the original article →

Luna-enriched source article · helpnetsecurity

In this new SME cybersecurity service, the AI assists and the consultants decide

BH Consulting launched BH Haven, an ongoing service giving Irish SMEs access to specialist consultants supported by a proprietary AI tool for analysis, evidence review, regulatory mapping, and reporting.

3 retained claims3 cited excerpts

Source published Sep 30, 2026, 4:30 AM UTC · Evidence retrieved Sep 30, 2026, 8:51 AM UTC

What happened

BH Consulting launched BH Haven, an ongoing service giving Irish SMEs access to specialist consultants supported by a proprietary AI tool for analysis, evidence review, regulatory mapping, and reporting. [1]

The service targets companies subject to GDPR, the NIS2 Directive, and the EU AI Act. [2]

Why it matters

The service is initially available in Ireland and the UK, with Nordic countries and other EU markets identified for later expansion. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized enterprises (SMEs) access to its specialist consultants, supported by a proprietary AI tool for analysis, evidence review, regulatory mapping and reporting.
  2. [2]
    The companies it targets answer to GDPR, the NIS2 Directive, the EU AI Act and the … More → The post In this new SME cybersecurity service, the AI assists and the consultants decide appeared first on Help Net Security .
  3. [3]
    Ireland and the UK come first, with the Nordic countries and other EU markets to follow.

Read the original article →

Luna-enriched source article · helpnetsecurity

EU Cyber Resilience Act requirements for containers and Kubernetes

The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, establishes mandatory cybersecurity requirements for products with digital elements sold in EU markets.

3 retained claims6 cited excerpts

Source published Sep 30, 2026, 5:00 AM UTC · Evidence retrieved Sep 30, 2026, 8:51 AM UTC

What happened

The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, establishes mandatory cybersecurity requirements for products with digital elements sold in EU markets. [1]

The CRA introduces requirements for teams working with containers and Kubernetes covering how cloud-native applications are built, distributed, and maintained throughout their lifecycle. [2]

Why it matters

The article states that the CRA will take effect on December 10, 2024, with reporting obligations beginning September 11, 2026, and full enforcement beginning December 11, 2027. [3] [4] [5] [6]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets.
  2. [2]
    The CRA brings new requirements for teams working with containers and Kubernetes regarding how cloud native applications are built, distributed, and maintained throughout their lifecycle.
  3. [3]
    Starting in full force on Dec.
  4. [4]
    Reporting obligations will begin on Sept.
  5. [5]
    11, 2026, with full enforcement kicking in on Dec.
  6. [6]
    11, 2027.

Read the original article →

Luna-enriched source article · the hacker news

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Researchers disclosed technical details of a recently patched critical vulnerability in Citrix NetScaler ADC and Gateway that is under active exploitation in the wild.

2 retained claims2 cited excerpts

Source published Sep 30, 2026, 5:30 AM UTC · Evidence retrieved Sep 30, 2026, 7:23 AM UTC

What happened

Researchers disclosed technical details of a recently patched critical vulnerability in Citrix NetScaler ADC and Gateway that is under active exploitation in the wild. [1]

The vulnerability is identified as CVE-2026-88772, has a CVSS score of 9.5, and is described as a memory overflow bug in NetScaler’s DTLS protocol handling. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.
  2. [2]
    The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Read the original article →

Luna-enriched source article · helpnetsecurity

OWASP Noir: Open-source static analysis tool

OWASP Noir is an open-source static analysis tool that reads application source code and inventories exposed endpoints, including paths, HTTP methods, parameters, headers, cookies, and the originating file and line.

2 retained claims2 cited excerpts

Source published Sep 30, 2026, 5:30 AM UTC · Evidence retrieved Sep 30, 2026, 8:51 AM UTC

What happened

OWASP Noir is an open-source static analysis tool that reads application source code and inventories exposed endpoints, including paths, HTTP methods, parameters, headers, cookies, and the originating file and line. [1]

Why it matters

The inventory includes shadow APIs—endpoints present in code but absent from documentation—as well as deprecated routes and undocumented handlers. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from.
  2. [2]
    Shadow APIs, the endpoints that live in the code but never made it into any documentation, show up in Noir’s inventory right next to everything else, along with deprecated routes and undocumented handlers.

Read the original article →

Luna-enriched source article · helpnetsecurity

Security tools can now scan Claude Enterprise chats and uploads for sensitive data

More than 100 security and compliance vendors integrate with the Claude Compliance API, allowing companies to send Claude activity to their existing monitoring tools.

4 retained claims4 cited excerpts

Source published Sep 30, 2026, 6:31 AM UTC · Evidence retrieved Sep 30, 2026, 8:51 AM UTC

What happened

More than 100 security and compliance vendors integrate with the Claude Compliance API, allowing companies to send Claude activity to their existing monitoring tools. [1]

Named integrations include CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare and Zscaler. [2]

For Claude Enterprise customers, the feed includes conversations, uploaded files and projects. [3]

The feed also covers Cowork and Claude Code sessions, including prompts, responses and tool calls. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already uses.
  2. [2]
    CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare and Zscaler are among them.
  3. [3]
    For a Claude Enterprise customer, the feed includes the conversations themselves, the files people upload and their projects.
  4. [4]
    It also covers Cowork and Claude Code sessions, down to prompts, responses and tool calls, plus … More → The post Security tools can now scan Claude Enterprise chats and uploads for sensitive data appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Genea brings AI agents to access control with role-based permissions

Genea announced Genea MCP, an MCP server connecting AI agents directly to the Genea Access Control platform.

4 retained claims4 cited excerpts

Source published Sep 30, 2026, 6:49 AM UTC · Evidence retrieved Sep 30, 2026, 8:51 AM UTC

What happened

Genea announced Genea MCP, an MCP server connecting AI agents directly to the Genea Access Control platform. [1]

The announcement describes onboarding a new hire, setting up a contractor for two weeks, or unlocking the loading dock as tasks that can be performed with one sentence instead of a dozen clicks. [2]

Why it matters

Genea says it is one of the first access control providers to launch a native MCP server. [3]

Known limitations

The supplied evidence does not specify the role-based permission model, supported commands, deployment requirements, or security controls. [1] [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform.
  2. [2]
    Onboarding a new hire, setting up a contractor for two weeks, or unlocking the loading dock now takes one sentence instead of a dozen clicks.
  3. [3]
    Genea is one of the first access control providers to launch a native MCP server.
  4. [4]
    Most access control work isn’t hard, but it can be … More → The post Genea brings AI agents to access control with role-based permissions appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Former US Air Force members behind million-dollar BEC scheme head to prison

Two former U.S. Air Force members who ran business email compromise and phishing campaigns against U.S. businesses were sentenced to a combined 189 months in federal prison.

2 retained claims2 cited excerpts

Source published Sep 30, 2026, 7:42 AM UTC · Evidence retrieved Sep 30, 2026, 8:51 AM UTC

What happened

Two former U.S. Air Force members who ran business email compromise and phishing campaigns against U.S. businesses were sentenced to a combined 189 months in federal prison. [1]

According to public documents and sentencing evidence, the defendants and co-conspirators spent nearly two years sending spam and phishing emails to businesses nationwide to steal usernames and passwords for employee email accounts. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison.
  2. [2]
    According to public documents and evidence presented at sentencing, Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, both from Delaware, spent nearly two years sending spam and phishing emails to businesses around the US to steal usernames and passwords for employee email accounts.

Read the original article →

Luna-enriched source article · the hacker news

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

OpenSSL said a high-severity DTLS flaw can leak heap memory to the other side of a DTLS connection or crash the program; it released fixes on September 29.

3 retained claims3 cited excerpts

Source published Sep 30, 2026, 8:09 AM UTC · Evidence retrieved Sep 30, 2026, 1:23 PM UTC

What happened

OpenSSL said a high-severity DTLS flaw can leak heap memory to the other side of a DTLS connection or crash the program; it released fixes on September 29. [1]

DTLS is the TLS variant used for UDP traffic and resends a handshake message when no reply arrives before its timer expires. [2]

The leak or crash can occur when a resend begins while a larger handshake message is stuck part-way. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes.
  2. [2]
    DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires.
  3. [3]
    The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

Read the original article →

Luna-enriched source article · helpnetsecurity

Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore

Signal users switching between Android and iPhone can transfer their message history, and backups can be restored on Android, iOS, Linux, macOS, and Windows.

3 retained claims3 cited excerpts

Source published Sep 30, 2026, 9:31 AM UTC · Evidence retrieved Sep 30, 2026, 2:51 PM UTC

What happened

Signal users switching between Android and iPhone can transfer their message history, and backups can be restored on Android, iOS, Linux, macOS, and Windows. [1]

The backup updates were fully rolled out with Signal for iOS version 8.30. [2]

The changes build on Signal Secure Backups, an optional end-to-end encrypted backup service introduced in September 2025. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Signal users who switch from an Android phone to an iPhone, or the other way around, can take their message history with them, and backups can be restored on Android, iOS, Linux, macOS and Windows.
  2. [2]
    The option is part of a set of backup updates the company finished rolling out with Signal for iOS version 8.30.
  3. [3]
    The changes build on Signal Secure Backups, an optional end-to-end encrypted backup service introduced in September 2025.

Read the original article →

Luna-enriched source article · the hacker news

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses; 51% of submissions came from the United States.

3 retained claims3 cited excerpts

Source published Sep 30, 2026, 10:45 AM UTC · Evidence retrieved Sep 30, 2026, 1:23 PM UTC

What happened

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses; 51% of submissions came from the United States. [1]

Technology, manufacturing, government, and consulting organizations showed the highest exposure in the reported campaign. [2]

Why it matters

The campaign combined Microsoft 365 session theft with remote-access tool deployment, which the source says can turn a phishing incident into broader account compromise and fraud. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States.
  2. [2]
    Technology, manufacturing, government, and consulting organizations showed the highest exposure.
  3. [3]
    By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

Read the original article →

Luna-enriched source article · the hacker news

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Glow said AI coding agents asked to share screenshots of code changes for review put internal company images in public GitHub repositories.

3 retained claims3 cited excerpts

Source published Sep 30, 2026, 11:30 AM UTC · Evidence retrieved Sep 30, 2026, 1:23 PM UTC

What happened

Glow said AI coding agents asked to share screenshots of code changes for review put internal company images in public GitHub repositories. [1]

Glow researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of unreleased features. [2]

Why it matters

The exposed images were in most cases stored under developers' personal accounts, according to the supplied report. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said.
  2. [2]
    Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released.
  3. [3]
    In most cases, they sat under developers' personal accounts

Read the original article →

Luna-enriched source article · helpnetsecurity

AI coding agents leaked 13,000 internal company screenshots to public GitHub repos

Glow Labs reported that, when developers ask AI coding agents to prove a user-interface fix works, some agents post the evidence where anyone can find it.

3 retained claims3 cited excerpts

Source published Sep 30, 2026, 11:52 AM UTC · Evidence retrieved Sep 30, 2026, 2:51 PM UTC

What happened

Glow Labs reported that, when developers ask AI coding agents to prove a user-interface fix works, some agents post the evidence where anyone can find it. [1]

Researchers found more than 13,000 internal images published openly on GitHub by developers at over 300 organizations. [2]

Why it matters

The images were spread across more than 900 code repositories and included customer billing records. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it, according to Glow Labs.
  2. [2]
    Diagram showing how AI agents leak screenshots to public repos (Source: Glow Labs) The researchers found more than 13,000 internal images published openly on GitHub by developers at over 300 organizations.
  3. [3]
    The images, spread over more than 900 code repositories, include customer billing records and … More → The post AI coding agents leaked 13,000 internal company screenshots to public GitHub repos appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

Mandiant CTO Charles Carmakal said advanced and suspected state-sponsored threat actors likely conducted initial targeted intrusions exploiting NetScaler vulnerability CVE-2026-88772, described as one of two recently disclosed NetScaler zero-days.

2 retained claims2 cited excerpts

Source published Sep 30, 2026, 12:33 PM UTC · Evidence retrieved Sep 30, 2026, 2:51 PM UTC

What happened

Mandiant CTO Charles Carmakal said advanced and suspected state-sponsored threat actors likely conducted initial targeted intrusions exploiting NetScaler vulnerability CVE-2026-88772, described as one of two recently disclosed NetScaler zero-days. [1]

Why it matters

Mandiant and Google Threat Intelligence Group reported knowing of dozens of impacted organizations across North America and Europe, including government, financial services, education, telecommunications, and legal and professional services organizations. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    “Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two recently disclosed NetScaler vulnerabilities that have been exploited as zero-days, says Mandiant CTO Charles Carmakal.
  2. [2]
    Mandiant and Google Threat Intelligence Group (GTIG) know of dozens of impacted organizations across North America and Europe, he added, “including in the government, financial services, education, telecommunications, and legal and professional services sectors.” Two NetScaler zero-days exploited … More → The post Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · securityaffairs

Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments

The U.S. Justice Department charged Oxygen Forensics’ CEO and a Russian co-founder with concealing Russian ownership, control, and software development while selling forensic tools to U.S. agencies.

8 retained claims20 cited excerpts

Source published Sep 30, 2026, 1:26 PM UTC · Evidence retrieved Sep 30, 2026, 2:51 PM UTC

What happened

The U.S. Justice Department charged Oxygen Forensics’ CEO and a Russian co-founder with concealing Russian ownership, control, and software development while selling forensic tools to U.S. agencies. [1] [2] [3] [4]

According to documents reviewed by Politico, Oxygen was consulted on two EU-funded digital-evidence projects: EVIDENCE, funded with more than €1.9 million from 2014 to 2016, and INSPECTr, which continued until 2023. [4] [5] [6] [7]

The European Commission said Oxygen was not a formal consortium member or direct EU-funding recipient, and that Russian entities were excluded from Horizon Europe projects after the war began. [8] [9]

EU tender records reportedly show police agencies in Germany, Spain, Italy, and Poland accredited or purchased Oxygen products; additional reported users included Hungary, Romania, and Latvia. [10] [11] [12]

Why it matters

The article reports that the same five people secretly owning Oxygen also controlled Russian company MKO Systems, which sold the same underlying technology to the FSB and Russia’s Interior Ministry. [13]

Disclose reportedly found Oxygen software supplied to Moroccan authorities through an EU-funded border-management program, with EU-funded training delivered by Oxygen employees. [14] [15] [16]

Access Now’s Natalia Krapiva said use of Russian-made software for EU criminal-evidence databases would raise a serious possibility that sensitive information was compromised or accessed by Russian authorities. [17] [18]

Known limitations

The article states that stopping use does not change data that may already have been extracted with the software, while other contacted national police agencies did not respond. [19] [20]

Some generated claims did not pass validation and were omitted. Only retained claims are shown.

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    CEO Lee Reiber and Russian co-founder Oleg Davydov stand accused of hiding that the company was Russian-owned and its software built in Russia, while it sold forensic tools to the Pentagon, the Secret Service, and other US agencies.
  2. [2]
    “The CEO of a Virginia-based software company and a Russian national have been arrested on a federal criminal complaint charging them with concealing from U.S.
  3. [3]
    government agencies that their company was owned and controlled by Russian nationals and that its software was developed in Russia, the Justice Department announced today.” DoJ states .
  4. [4]
    “Reiber allegedly represented to the government that the company had no foreign ownership or control and that its software was developed in the United States, when in fact five Russian nationals, including Davydov, owned and controlled the company and its software was developed in Russia.” According to documents reviewed by Politico, Oxygen Forensics was involved in two EU-funded projects designed to improve how European investigators collect and share digital evidence.
  5. [5]
    The first, EVIDENCE, ran from 2014 to 2016 and received more than €1.9 million in EU funding.
  6. [6]
    The second project, INSPECTr, was funded through Horizon 2020.
  7. [7]
    The project continued until 2023, after Russia’s invasion of Ukraine.
  8. [8]
    “Although both of those EU-backed projects were launched well before Russia’s February 2022 full-scale invasion of Ukraine and subsequent European sanctions, INSEPCTr continued to operate until 2023.” The European Commission said Oxygen was not a formal member of either consortium and did not receive direct EU funding.
  9. [9]
    It also noted that Russian entities have been excluded from Horizon Europe projects since the war began.
  10. [10]
    Police agencies in Germany, Spain, Italy, and Poland accredited or purchased Oxygen’s products, according to EU tender records.
  11. [11]
    Hungary’s police signed a contract worth roughly €27,000 in December 2024, running through the end of last year.
  12. [12]
    Romania and Latvia bought in as recently as this September, days before the arrests.
  13. [13]
    The same five people who secretly owned Oxygen Forensics also controlled MKO Systems, a Russian company selling the same underlying technology to the FSB and Russia’s Interior Ministry.
  14. [14]
    There is also a more worrying case outside the EU.
  15. [15]
    French outlet Disclose reported that Oxygen’s software was provided to Moroccan authorities through an EU-funded border management program covering the Maghreb.
  16. [16]
    The EU also paid for training courses where Oxygen employees trained Moroccan police to use the software.
  17. [17]
    “Reiber then wrote to Davydov and two other Russian owners that public reporting on the connection “could destroy this entire opportunity,” referring to a pending contract with the National Computer Forensics Institute, and that the “current existence of this company hangs in the balance.”” Natalia Krapiva at Access Now put the stakes about as plainly as they can be put: civil society groups had flagged Oxygen’s Russian links for years, and this case just confirmed what they’d been saying.
  18. [18]
    “If in fact Russian-made software designed for the FSB and Investigative Committee was used for handling EU Commission criminal evidence database, it raises a serious possibility of sensitive information being compromised and accessed by Russian authorities,” Krapiva told Politico.
  19. [19]
    However, this does not change any data that may already have been extracted using the software.
  20. [20]
    Other national police agencies contacted by Politico did not respond.

Read the original article →

Published records

Additional source records

Expand a row to inspect provenance
Material developments

Build a multi-agent music production pipeline on Amazon Bedrock AgentCore Runtime Instances

Amazon Web Services published a source item for review.

1 source recordAuthoritative source

What happened

Amazon Web Services published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

AI-Found Vulnerabilities More Likely to Enable RCE, Google Says

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

TeamViewer urges users to patch severe flaws “as soon as possible”

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Know Your Enemy: Browser-Based Attack Techniques in 2026

The Hacker News published a source item for review.

1 source recordContext source

What happened

The Hacker News published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

ShinyHunters Defiant After FBI Calls on Members to Come Forward

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

WaterISAC reckons with range of threats after summer of cyberattacks

Cyberscoop published a source item for review.

1 source recordContext source

What happened

Cyberscoop published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT

Securityaffairs published a source item for review.

1 source recordContext source

What happened

Securityaffairs published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

glm 5 3 and the spread of advanced cyber capabilities

Anthropic published a source item for review.

1 source recordAuthoritative source

What happened

Anthropic published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

The Hacker News published a source item for review.

1 source recordContext source

What happened

The Hacker News published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

Spectre bug is back, this time to haunt JIT engines

Theregister Security published a source item for review.

1 source recordContext source

What happened

Theregister Security published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

July 2026 Security Updates

Microsoft Security Response Center published a source item for review.

1 source recordAuthoritative source

What happened

Microsoft Security Response Center published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Mobile malware warning from Ukrainian researchers includes iPhone exploit kit

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Vulnerability Discovery and Exploitation Trends in the AI Era

Mandiant published a source item for review.

1 source recordAuthoritative source

What happened

Mandiant published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft published details for CVE-2026-73570.

1 source recordAuthoritative source

What happened

Microsoft published details for CVE-2026-73570.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-73570 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-73570.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Securityweek published details for CVE-2026-88771, CVE-2026-88772.

1 source recordContext source

What happened

Securityweek published details for CVE-2026-88771, CVE-2026-88772.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-88771 mentionedCVE-2026-88772 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-88771, CVE-2026-88772.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters

Therecord Media published a source item for review.

1 source recordContext source

What happened

Therecord Media published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Bitget hacked via zero-day in third-party security products

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Apple Patches CoreGraphics Zero Day Exploited in Attacks

Infosecurity Magazine published details for CVE-2026-86950.

1 source recordContext source

What happened

Infosecurity Magazine published details for CVE-2026-86950.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-86950 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-86950.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Securityaffairs published details for CVE-2026-86950.

1 source recordContext source

What happened

Securityaffairs published details for CVE-2026-86950.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-86950 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-86950.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Securityaffairs published details for CVE-2026-88772.

1 source recordContext source

What happened

Securityaffairs published details for CVE-2026-88772.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-88772 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-88772.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

Cloud CISO Perspectives: How cybersecurity startups can win CISOs

Google Cloud published a source item for review.

1 source recordAuthoritative source

What happened

Google Cloud published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised

Helpnetsecurity published details for CVE-2026-82329.

1 source recordContext source

What happened

Helpnetsecurity published details for CVE-2026-82329.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-82329 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-82329.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

South Africa Seeks Help After Cyberattack Targets Air Traffic Control

Darkreading published a source item for review.

1 source recordContext source

What happened

Darkreading published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

AI Boosts SOC Analyst Capacity but Limits Skill Development

Infosecurity Magazine published a source item for review.

1 source recordContext source

What happened

Infosecurity Magazine published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

your thoughts on ai

Anthropic published a source item for review.

1 source recordAuthoritative source

What happened

Anthropic published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.