91Articles
8Categories
2026-03-09Date
🚨
Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalogsubmitted by kid to cybersecurity 1 points | 0 comments https://thehackernews.com/2026/03/hikvision-and-rockwell-automation-cvss.html
KEV
🚨
CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2021-22054 Omnissa Workspace ONE Server-Side Request Forgery CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data Vul…
KEV
🐛
Critical ExifTool Vulnerability Allows Malicious Images to Execute Code on macOS
🐛
Nginx UI Vulnerabilities Let Attackers Download Full System Backups
🐛
1-Click ZITADEL Vulnerability Could Allow Full System Takeover
🐛
Apache ZooKeeper Flaw Exposes Sensitive Data to Attackers
🐛
Vaultwarden Vulnerabilities Enable Privilege Escalation and Data Exposure
🐛
CVE program funding secured, easing fears of repeat crisis
🐛
ZDI-26-172: Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability
🐛
ZDI-26-171: Unraid Update Request Path Traversal Remote Code Execution Vulnerability
🐛
VU#976247: Retraction of "Antivirus and Endpoint Detection and Response Archive Scanning Engines may not properly scan malformed ZIP archives"
⚠️
Coruna iOS Exploit Kit Goes Mass-Market: Cybersecurity Today for March 9, 2026 with David Shipley
⚠️
CISA Alerts Users to Actively Exploited Vulnerabilities Impacting macOS and iOS
KEV
⚠️
WiFi Signals Can Track Human Activity Through Walls by Mapping Body Keypoints
⚠️
TrendAI™ at [un]prompted 2026: From KYC Exploits to Agentic Defense
⚠️
PQC roadmap remains hazy as vendors race for early advantage
⚠️
Hikvision Multiple Product Vulnerability Could Let Attackers Escalate Privileges
KEV
⚠️
ExifTool Vulnerability Lets Malicious Images Trigger macOS Code Execution
⚠️
4 ways to prepare your SOC for agentic AI
⚠️
Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure
⚠️
Rogues gallery: 15 worst ransomware groups active today
⚠️
Breaking in with CrashFix, supply chain security, and CMMC phase 1 - ESW #449
⚠️
New Attack Against Wi-Fi
⚠️
Cyber Espionage Group CL-UNK-1068 Linked to China Targets Asian Infrastructure
⚠️
OpenAI says Codex Security found 11,000 high-impact bugs in a month
⚠️
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks
⚠️
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware
⚠️
Open-source tool Sage puts a security layer between AI agents and the OS
⚠️
Open-source tool Sage puts a security layer between AI agents and the OS
⚠️
ShinyHunters claims ongoing Salesforce Aura data theft attacks
⚠️
Ericsson US discloses data breach after service provider hack
⚠️
Google: Cloud attacks exploit flaws more than weak credentials
⚠️
My Really Fun RSA 2026 Presentations!
⚠️
Fixing request smuggling vulnerabilities in Pingora OSS deployments
⚠️
Active defense: introducing a stateful vulnerability scanner for APIs
📢
Tarnung als Taktik: Warum Ransomware-Angriffe raffinierter werden
📢
Your KnowBe4 Fresh Compliance Plus Content Updates | February 2026
📢
CMMC Is Now In Contracts
📢
IBM security advisory (AV26-200)
📢
Red Hat security advisory (AV26-202)
📢
Ubuntu security advisory (AV26-201)
📢
[Control systems] CISA ICS security advisories (AV26–204)
📢
Dell security advisory (AV26-203)
📢
[Control Systems] Moxa security advisory (AV26-205)
📢
Mozilla security advisory (AV26-207)
📢
Microsoft Edge security advisory (AV26-206)
📢
From Alerts to Action: Making Public–Private Threat Intel Actually Useful - Ian Washburn - CSP #222
📢
9 Must-Know Best Practices for Email Security
📢
Ivanti security advisory (AV26-113) – Update 1
🔥
Countries with Most Personal Records Leaked in Data Breaches (2004-2025)
🔥
Countries with Most Personal Records Leaked in Data Breaches (2004-2025)
🔥
Countries with Most Personal Records Leaked in Data Breaches (2004-2025)
🔥
Microsoft: Fake AI Extensions Breached Chat Histories in 20,000+ Enterprise Tenants
🔥
Why Password Audits Miss the Accounts Attackers Actually Want
🔥
Russian-backed hackers have gained access to Signal and WhatsApp accounts used ‌by officials, military personnel and journalists, as claimed by two intelligence agencies in the Netherlands.
🔥
UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device
🔥
Salt Typhoon is hacking the world’s phone and internet giants. Here’s everywhere that’s been hit.
🕵️
ISC Stormcast For Monday, March 9th, 2026 https://isc.sans.edu/podcastdetail/9840, (Mon, Mar 9th)
🕵️
Transparent Tribe’s ‘Vibeware’ Move Points to AI-Made Malware at Scale
🕵️
Cybercrime Group in Vietnam Enables Massive Fraudulent Signups
🕵️
ClipXDaemon Malware Targets Crypto Users in Linux X11 Sessions
🕵️
NIS-2: Tausende reißen BSI-Frist und riskieren Strafen
🕵️
MaaS VIP Keylogger Campaign Uses Steganography to Steal Credentials at Scale
🕵️
Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign
🕵️
Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threats
🕵️
Internet Infrastructure TLD .arpa Abused in Phishing Attacks
🕵️
Iran-linked APT targets US critical sectors with new backdoors - Help Net Security
🕵️
BoryptGrab Malware Abuses GitHub to Steal Browser and Crypto Wallet Data
🕵️
Mentorship Monday - Discussions for career and learning!
🕵️
ClickFix Attack Uses Windows Terminal to Evade Detection
🕵️
900+ Certificates Used by Fortune 500, Governments Exposed by Key Leaks
🕵️
Fake CleanMyMac Site Spreads SHub Stealer, Targets Crypto Wallets
🕵️
FBI Investigating ‘Suspicious’ Cyber Activity on System Holding Sensitive Surveillance Information - SecurityWeek
🕵️
Secure agentic AI for your Frontier Transformation
🕵️
Security Risk Advisors Releases “The Purple Perspective 2026” Report
🕵️
Cybersecurity M&A Roundup: 42 Deals Announced in February 2026
🕵️
AI-to-AI Communication and Secret AI Code Must Be Stopped At All Costs
🕵️
Stop Credential Stealers With This
🕵️
Announcing Prisma AIRS Availability in Singapore Region
🕵️
From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
🌐
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
🌐
Can the Security Platform Finally Deliver for the Mid-Market?
🌐
Microsoft Teams phishing targets employees with backdoors
📡
Ring’s Jamie Siminoff has been trying to calm privacy fears since the Super Bowl, but his answers may not help
📡
Microsoft still working to fix Windows Explorer white flashes
📡
Encrypted Client Hello: Ready for Prime Time?, (Mon, Mar 9th)
📡
FBI warns of phishing attacks impersonating US city, county officials
📡
Russian government hackers targeting Signal and WhatsApp users, Dutch spies warn
📡
Microsoft Teams will tag third-party bots trying to join meetings
📡
OpenAI acquires Promptfoo to secure its AI agents
📡
Dutch govt warns of Signal, WhatsApp account hijacking attacks