Posts of last few hours
Please support the site operations by clicking ads.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Stamford, CT, September 16th, 2026, CyberNewswire Now in early access, AxoDetect runs Sigma rules in stream alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake Detection engineers do not need more detections. They need their existing detections to fire earlier, on cleaner data, without paying SIEM ingest rates […]
The post Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB attributed the activity to an operator sub-cluster tracked as Outsider, which appears to operate as a customer within the wider phishing-as-a-service ecosystem rather […]
The post Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CenterPoint Energy has confirmed that an unauthorized third party accessed personal information belonging to some of its customers by compromising one of the utility provider’s external systems. The Houston-based energy company disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission dated September 14, 2026. CenterPoint learned of the potential […]
The post CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
A critical local privilege escalation vulnerability in Parallels Desktop could allow an unprivileged macOS user or a malicious process to gain root-level access to the host system. The issue, tracked as CVE-2026-90894, was disclosed by Yuval Moravchick from JFrog’s Vulnerability Research team and has been named “ParaShells.” This flaw was demonstrated against Parallels Desktop version […]
The post Parallels Desktop Flaw Lets Unprivileged Mac Users Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State of the Union address to the European Parliament in Strasbourg, she also committed the EU to joint work with Canada, the U.K. and other partners on evaluating and verifying advanced models, early warning and AI … More →
The post Self-improving AI should slow down, von der Leyen tells EU lawmakers appeared first on Help Net Security.
Latest Blog Posts
- 4 weeks 2 days ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago