MalwareMalicious ChatGPT Custom GPTs lead to ClickFix attackLaura FrenchSeptember 30, 2026Instructions to visit a malicious website were delivered through the real ChatGPT site.
SC AwardsSC Awards Celebrate 30 Years of Recognizing the People and Technology Advancing Cybersecurity Kelley DamoreSeptember 29, 2026
Training57% of security execs report challenges with onboarding entry-level staffSteve ZurierSeptember 29, 2026SkillBit survey says security teams struggle to find and train new staff as AI compresses the time they have to patch new bugs.
Threat IntelligenceShinyHunters targets Oracle PeopleSoft in new campaign amid FBI attack claimsLaura FrenchSeptember 29, 2026Google says ShinyHunters found a way to bypass WAF rules to reach vulnerable endpoints.
Patch/Configuration ManagementCISA warns organizations to patch 2 critical Citrix NetScaler RCEsSteve ZurierSeptember 28, 2026Federal agencies are told to make the patches by this Wednesday
AI/MLWas the Australia health portal incident a misconfiguration error?Steve ZurierSeptember 25, 2026Questions emerge over whether a reported AI hack was actually a basic government portal misconfiguration.
Security OperationsKiteworks warns customers to shut down servers due to possible imminent attackLaura FrenchSeptember 25, 2026Kiteworks’ CISO cited “credible threat intelligence from law enforcement” for the urgent alert.
Vulnerability ManagementCISA publishes framework for improving CVE program as vulnerability counts riseLaura FrenchSeptember 25, 2026The framework outlines four key areas of focus for the CVE program’s “Quality Era.”
RansomwareCritical 9.8 JetBrains TeamCity RCE exploited by ransomware, says CISASteve ZurierSeptember 24, 2026Ransomware groups exploit a critical TeamCity flaw, putting software supply chains at risk.
Critical Infrastructure SecurityMemTensor npm, PyPI packages compromised with cross-platform credential stealerLaura FrenchSeptember 24, 2026A Go binary called sckit was added to four malicious releases, targeting developer secrets.