Get the Zoom link

Cloud Security News

Latest news, vulnerabilities, and developments in cloud security. Stay informed about the rapidly evolving cloud threat landscape.

RSS Feed
Cloud security news velocity is high; signal-to-noise is low. This page is the curated middle. - what this feed is for
Adult reading a newspaper with breakfast in modern kitchen, morning sunlight
Photo by cottonbro studio on Pexels

October 02, 2026 · 50 articles

Dark Reading

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for... (Dark Reading)

Vulnerability
AWS Security Bulletins

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container... (AWS Security Bulletins)

AWS Vulnerability
Dark Reading

SWIFT Banking & Government Middleware Enables RCE

Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments. (Dark Reading)

Vulnerability
BleepingComputer

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...] (BleepingComputer)

Vulnerability AI
Cloudflare Blog

Streamline: custom video pipelines with Cloudflare Stream and Workers

Streamline demonstrates how to build long-running, continuous video processing pipelines by pairing Cloudflare Workers and Durable Objects with a containerized media engine. (Cloudflare Blog)

Cloud Security
Dark Reading

Is Your Organization Ready for 2027's AI Accountability Era?

Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges a... (Dark Reading)

AI
Dark Reading

Is It Fair to Blame 'Rogue' AI for Security Failures?

"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sen... (Dark Reading)

AI
Schneier on Security

Unidentified Flock Cameras in Florida

St. Lucie County in Florida discovered ( alt link ) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted. I am reminded of t... (Schneier on Security)

Cloud Security
The Register - Security

OpenAI's wandering AI agents earn it a California subpoena

Plus: Attorneys-general say investigators should have direct access to AI companies' records when things go wrong (The Register - Security)

AI
SecurityWeek

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app... (SecurityWeek)

Azure AI
Security Affairs

AI Agents Attempt SQL Injection While Searching Government Data

AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, worki... (Security Affairs)

AI
Infosecurity Magazine

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes

Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks (Infosecurity Magazine)

Azure AI Threat Research
The Record

Mississippi mayor says ransomware incident led city to shut down systems

Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating. (The Record)

Ransomware
The Record

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team. (The Record)

Azure Vulnerability Ransomware
Dark Reading

Vulnerability Backlogs Are an Ownership Problem

Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them. (Dark Reading)

Vulnerability
The Register - On-Prem

Power approval set to delay Oracle's Wisconsin AI datacenter

Grid connection awaits regulatory approval, putting planned 2027 customer delivery at risk (The Register - On-Prem)

AI
Cloudflare Blog

Introducing Web Search API via AI Gateway

Cloudflare AI Gateway now supports native web search API integration in partnership with Ceramic.ai, Exa, and Linkup. Developers can now inject real-time web context into model... (Cloudflare Blog)

AI
SecurityWeek

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom I... (SecurityWeek)

Cloud Security
Aqua Security Blog

Integrate Aqua and Jira to Turn Security Findings Into Action

TL;DR Finding a security issue is only the beginning. Teams still need to get that issue to the people who can investigate and remediate it without adding another manual handoff... (Aqua Security Blog)

Cloud Security
Cloudflare Blog

8 major updates to Cloudflare Observability

Cloudflare is launching eight major updates that bring logs, traces, analytics, alerts, dashboards, querying, and telemetry export into one observability platform, with simpler... (Cloudflare Blog)

Cloud Security
Cloudflare Blog

Introducing Cloudflare Traces: follow requests through our entire platform

Cloudflare Traces shows how a request moves through security rules, transformations, cache, routing, Workers, and your origin, then follows it across services running anywhere i... (Cloudflare Blog)

Cloud Security
Cloudflare Blog

Updates on our pledge to make Cloudflare features accessible to everyone

A year after pledging to eliminate two-tier product access, Cloudflare has expanded Logpush, multi-account governance, and higher platform limits to all accounts. Here is an upd... (Cloudflare Blog)

Cloud Security
Cloudflare Blog

Announcing Cloudflare OHTTP Gateway - expanding access to Cloudflare’s privacy-preserving infrastructure

We’re announcing the closed beta of a self-serve Cloudflare OHTTP Gateway. We’re also renaming our Privacy Gateway to Cloudflare OHTTP Relay to better distinguish the two products. (Cloudflare Blog)

Cloud Security
Cloudflare Blog

Follow the thread: a new dashboard to investigate account abuse

Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed Us... (Cloudflare Blog)

AI Scam
Cloudflare Blog

Protected Quick Tunnels: simple accountless authentication for your next dev project

Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare... (Cloudflare Blog)

Cloud Security
Cloudflare Blog

Building for good: How civil society organizations are automating on Cloudflare

Some of the world's leading organizations are building the future of non-profit work with Cloudflare. (Cloudflare Blog)

Cloud Security
Cloudflare Blog

2026 Birthday week: network performance update

Cloudflare now ranks as the fastest provider across 74% of the top 1,000 global networks. By incorporating background telemetry from Cloudflare Challenge Pages, we have expanded... (Cloudflare Blog)

Cloud Security
Dark Reading

Malicious Linux Implants Mimic Asian Mail Security Products

A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not. (Dark Reading)

Cloud Security
Rapid7 Blog

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoo... (Rapid7 Blog)

Cloud Security
Help Net Security

AI is giving attackers a head start, Microsoft warns

Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 to June... (Help Net Security)

Azure AI Threat Research
BleepingComputer

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...] (BleepingComputer)

Kubernetes
The Hacker News

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have p... (The Hacker News)

Cloud Security
SecurityWeek

Crypto Scammers Hijack Microsoft’s Official X Account

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appea... (SecurityWeek)

Azure Scam
The Hacker News

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and th... (The Hacker News)

Vulnerability Identity
SecurityWeek

In Rare Move, Alleged Iranian State Hacker Extradited to US

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In... (SecurityWeek)

Cloud Security
Schneier on Security

How American Political Campaigns Are Using AI-and What They’re Spending on the Tools

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . New campaign finance disclosure data shines a light on which US political campaigns are... (Schneier on Security)

AI Threat Research
Trail of Bits Blog

SequenceHash: multihashing for the rest of us

Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographe... (Trail of Bits Blog)

Cloud Security
The Register - Security

Fortinet sounds the alarm over actively exploited FortiMail zero-day

No login required, exploitation underway, and some admins are still waiting for patches (The Register - Security)

Vulnerability
FortiGuard Labs

Citrix NetScaler RCE zero-day Vulnerabilities

What is the Attack? Threat actors are actively exploiting two critical remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting Citrix NetScaler ADC a... (FortiGuard Labs)

Vulnerability Threat Research
Infosecurity Magazine

Police Target KillSec Ransomware Group with Arrests and Seizures

Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects (Infosecurity Magazine)

Ransomware
Infosecurity Magazine

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure

The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days (Infosecurity Magazine)

Vulnerability AI
The Hacker News

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Prote... (The Hacker News)

Cloud Security
Security Affairs

Investigators trace an AI agent ‘s path from research task to reconnaissance

Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security s... (Security Affairs)

AI
Help Net Security

Criminal recruiters want people on your payroll

Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information l... (Help Net Security)

Cloud Security
Help Net Security

Android 17 makes it harder for spyware to cover its tracks

When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to Advanced Protection in An... (Help Net Security)

Cloud Security
Help Net Security

Botnets, adversarial attacks and data poisoning top leaders’ AI threat list

Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in 71... (Help Net Security)

AI
Help Net Security

AI agents keep access to company data after their work is done

IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s... (Help Net Security)

Identity AI
Help Net Security

New infosec products of the week: October 2, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings security-trained AI and lasting memo... (Help Net Security)

AI
Risky Business News

Risky Bulletin: Authorities dismantle KillSec group, arrest members across Europe

In other news: Ransomware attack could have crippled South Africa's air traffic operations; US sanctions Venezuelan ATM hackers; Chinese APT targets AI experts. (Risky Business News)

Ransomware AI Threat Research
Sysdig Blog

AI agent exploits Zammad zero-days in DIVD breach: What we know and how to detect it

(Sysdig Blog)

Vulnerability Breach AI

October 01, 2026 · 61 articles

AI policy circles targeted in China-linked phishing operation

Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think tank, university and leg... (CyberScoop)

Phishing AI
BleepingComputer

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway... (BleepingComputer)

Vulnerability
Security Affairs

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950

Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, track... (Security Affairs)

Vulnerability
Orca Security Blog

Introducing The Builder Exchange: Inside Security Stories From the Companies Building Fastest With AI

Why the industry needs The Builder Exchange Software development traditionally ran through a narrow channel that involved a defined set of engineers, pipelines, and a review pro... (Orca Security Blog)

AI
Malwarebytes Labs

Convincing Free Mobile phishing emails appear after data breach

Free Mobile customers received very convincing phishing emails after major data breach. (Malwarebytes Labs)

Breach Phishing
The Hacker News

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intellige... (The Hacker News)

AI Threat Research
The Hacker News

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Ex... (The Hacker News)

CISA Vulnerability
BleepingComputer

Hackers stole Pentagon personnel records of over 3 million people

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources... (BleepingComputer)

Breach
The Hacker News

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders throug... (The Hacker News)

AI
Infosecurity Magazine

MI5 Warns Over 100 Academics Helped China's Espionage Plans

MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute (Infosecurity Magazine)

Cloud Security
BleepingComputer

Metamask discloses security incident affecting its infrastructure

On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...] (BleepingComputer)

Cloud Security
Huntress Blog

New Huntress View for Security Incident Investigations

See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign. (Huntress Blog)

Cloud Security
CrowdStrike Blog

CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaS

(CrowdStrike Blog)

CISA
Dark Reading

Alleged KillSec Ransomware Mastermind a 16-Year-Old

Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years. (Dark Reading)

Ransomware
The Register - Security

AI agents hacked the hackers, stealing email addresses from security research org

Chained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds (The Register - Security)

AI
The Record

Iranian accused of hacking American universities extradited from Montenegro

An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro. (The Record)

Breach
SecurityWeek

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post Kevin Mandia’s Armadin... (SecurityWeek)

AI
The Record

OpenAI software attempted to secretly scrape data from dozens of prominent websites

The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software. (The Record)

Cloud Security

National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations

Sean Cairncross talked about regulations, China, pilot projects and more Thursday. The post National cyber director: Government-industry collaboration vital to managing AI risks... (CyberScoop)

AI
SecurityWeek

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era-if you get the implementation right. The post Zero Trust Creator Says Mode... (SecurityWeek)

Zero Trust AI
SecurityWeek

Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post Osavul Lands $10 Million to Spot Hostile Intent Across C... (SecurityWeek)

Cloud Security
The Hacker News

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than pe... (The Hacker News)

Vulnerability AI
The Register - Security

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing

Your invite to a fake AI policy advisory committee has strings attached (The Register - Security)

Phishing AI
Cloudflare Blog

Introducing Clef: our open-source decision models, and new RL fine-tuning platform

We are introducing Clef and Clef-flash, open-source decision models hosted on Workers AI for high-speed classification and agentic workflows. Also launching: a new reinforcement... (Cloudflare Blog)

AI
GitGuardian Blog

Public Secrets Monitoring: Find a Credential Leak Beyond Your Borders

GitGuardian found a public GitHub repo tied to CISA leaking 844MB of live credentials. Agents Analysis flags which public leaks are actually yours. (GitGuardian Blog)

CISA Scam
ReversingLabs Blog

Why the smartest LLMs are not-so-smart pen testers

A new benchmark of eight leading AI systems shows that an intelligent model still needs a good context-rich harness. (ReversingLabs Blog)

AI
The Register - Security

Microsoft catches hackers exploiting Zimbra bug before disclosure

Attackers were probing the mail server flaw weeks before it had a CVE to its name (The Register - Security)

Azure Vulnerability
The Hacker News

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returni... (The Hacker News)

Threat Research
SecurityWeek

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post Hacker Conversations: Rob Juncker, a Knock at the Door an... (SecurityWeek)

Cloud Security
SecurityWeek

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterp... (SecurityWeek)

AI
Infosecurity Magazine

Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation

Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges (Infosecurity Magazine)

Vulnerability
Malwarebytes Labs

Shadow AI explained: The work shortcut that could leak your company’s secrets

An AI shortcut can send confidential work data beyond your company’s control. Here’s how to get the benefits without taking unnecessary risks. (Malwarebytes Labs)

AI
BleepingComputer

The Day-One Hole in Zero Trust Architecture

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops exp... (BleepingComputer)

Zero Trust
Microsoft Security Blog

Preparing governments for an era of interconnected cyber risk

According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observe... (Microsoft Security Blog)

Azure
Microsoft Security Blog

Insights from the 2026 Microsoft Digital Defense Report

Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026... (Microsoft Security Blog)

Azure
Help Net Security

Exabeam brings AI-assisted security investigations to data that must stay on-premises

Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven investigation, execution, and... (Help Net Security)

AI
Help Net Security

RadarFirst helps teams investigate AI bias, data exposure and unintended actions

RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related... (Help Net Security)

AI
The Register - Security

CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

Replacing letters with symbols still doesn’t make it good. (The Register - Security)

Cloud Security
Help Net Security

Sophos uses agentic AI to show businesses which security fixes deserve funding

Sophos has launched Sophos CISO Advantage, an agentic AI-enabled solution that connects security operations to security strategy. The solution gives organizations a picture of t... (Help Net Security)

AI
SecurityWeek

AI Has Changed Attack Speed, Not Security Fundamentals

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The pos... (SecurityWeek)

Vulnerability AI
Help Net Security

Legit Security extends automated fixes to vulnerable open-source dependencies

Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling d... (Help Net Security)

Cloud Security
Cloudflare Blog

One year later: Sovereign AI and the fight for choice

AI sovereignty is not a zero-sum game, but many governments now believe it is. Cloudflare's answer: more local open-source models, model-agnostic security tools, and a commitmen... (Cloudflare Blog)

AI
Huntress Blog

Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses

The Huntress Tragic Quadrant ranks the cyber threats hitting businesses most, from RMM abuse to AiTM, ClickFix, using real SOC data. (Huntress Blog)

Cloud Security
Rapid7 Blog

How AI Is Changing the Roles Required in the Security Operations Center

As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to de... (Rapid7 Blog)

AI
SecurityWeek

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post Zimbra Vulnerability Exploited in the Wild Prior to Pub... (SecurityWeek)

Vulnerability
The Record

Cyberattack on major Polish invoicing platform exposes customer data

One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. (The Record)

Breach
The Register - Security

England's schools are getting better at mopping up cyber incidents

Two-thirds report immediate recovery, although teachers remain divided over whose job security is (The Register - Security)

Jobs
Schneier on Security

Connected Cars Are a Surveillance Platform

Researchers at Northeastern University, in collaboration with Consumer Reports , evaluated how much modern cars spy in their drivers: To determine this, CR dug through thousands... (Schneier on Security)

Cloud Security
Malwarebytes Labs

Malwarebytes earns another Top Product award in independent testing

Three independent labs, three standout results: a perfect score, top certification, and every threat stopped before it ran. (Malwarebytes Labs)

Cloud Security
SecurityWeek

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appea... (SecurityWeek)

Cloud Security
Cisco Talos

The Fine Art of Frustrating the Adversary

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to br... (Cisco Talos)

Cloud Security
Help Net Security

Some car apps are slipping owners’ data to big tech companies

The app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers tested 21 vehicles and 30 ca... (Help Net Security)

Cloud Security
Infosecurity Magazine

AI Threats Top Cybersecurity Preparedness Gap, PwC Finds

PwC finds global security leaders are most concerned about attacks on AI systems (Infosecurity Magazine)

AI
Malwarebytes Labs

Losing gamblers pushed to bet more by DraftKings’ AI, report says

Betting site DraftKings has been accused of using AI to target gamblers likely to lose more after receiving promotions. The company disputes the findings. (Malwarebytes Labs)

AI
SANS ISC

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications... (SANS ISC)

Threat Research
The Hacker News

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and at... (The Hacker News)

Vulnerability Threat Research
Risky Business News

Srsly Risky Biz: "Rogue" AI Isn't Going Anywhere

Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Patrick Gray and Amberleigh Jack. This week's edition is sponsored by PortSwigger . You ca... (Risky Business News)

AI
SANS ISC

ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118, (Thu, Oct 1st)

(SANS ISC)

Cloud Security
Sysdig Blog

With AI agents, runtime is the only place truth lives

Runtime security for AI agents: if an agent is compromised, so is its account of itself. Sysdig's founder on the only truth that can't be forged. (Sysdig Blog)

AI
Chainguard Unchained

What five years of Chainguard have taught us

Chainguard was founded to solve open source’s trust problem. Five years later, that mission matters more than ever in the age of AI. (Chainguard Unchained)

AI
Chainguard Unchained

How do you harden an agent skill? The simple file type with serious complexities

Learn how Chainguard Factory hardens AI agent skills by detecting malicious behavior, fixing risks, and verifying functionality before release. (Chainguard Unchained)

AI

September 30, 2026 · 9 articles

Dark Reading

Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users. (Dark Reading)

Threat Research
BleepingComputer

Russian state hackers use new RedFlick technique to push malware

The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...] (BleepingComputer)

Cloud Security
The Hacker News

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Micros... (The Hacker News)

Vulnerability Threat Research
The Hacker News

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-t... (The Hacker News)

Azure Phishing Threat Research
Google Cloud Blog

Cloud CISO Perspectives: How cybersecurity startups can win CISOs

Welcome to the second Cloud CISO Perspectives for September 2026. Today, Alicja Cade and Nick Godfrey, senior directors, Office of the CISO, share their guidance for cybersecuri... (Google Cloud Blog)

GCP
Wiz Blog

Securing the Kubernetes Supply Chain: Introducing WizOS Helm Charts

Secure your Kubernetes supply chain with WizOS Helm Charts. Eliminate hidden CI/CD risks and unmaintained dependencies with hardened, signed, and CVE-scanned charts for seamless... (Wiz Blog)

Kubernetes Vulnerability Supply Chain
GitGuardian Blog

AI Agent Authorization Beyond Authentication: A Look At AWS Dogwood

AWS Dogwood brings stateful authorization to AI agents. Learn how it fits with workload identity, AuthZEN, IAM, and the move away from long-lived credentials. (GitGuardian Blog)

AWS Identity AI
ReversingLabs Blog

Restrospective: How Malicious Updates Poison Your Environment

This post-mortem on recent supply chain attacks and threat actors including S1ngularity, Shai-Hulud and TeamPCP can help you prepare for what comes next. (ReversingLabs Blog)

Supply Chain Threat Research
Zscaler ThreatLabz

2CLoader: A New Malware Loader Delivering Vidar and Remus

IntroductionIn August 2026, Zscaler ThreatLabz identified a new loader, which we track as 2CLoader. ThreatLabz has observed the loader being used to distribute information steal... (Zscaler ThreatLabz)

Cloud Security