Automatic cybersecurity RSS aggregation

Cybersecurity Feeds

CK Cyber collects the latest RSS items from selected advisory, threat intelligence, vulnerability research, and security news sources, then renders them here without third-party browser scripts.

Advisories Threat Intel Vulnerabilities AppSec
Last refreshed Sep 17, 2026 12:01 PM ET
Next refresh Sep 18, 2026 7:00 AM ET
Sources online 13 / 14
Headlines loaded 52

Latest cybersecurity headlines.

Newest items from the monitored security sources, sorted by published date.

  1. SANS Internet Storm Center LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

    At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especiall...

    Enterprise IT
  2. BleepingComputer What Recent AI-Powered Attacks Mean for Your Identity Security

    AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identit...

    Cloud/SaaS Enterprise IT AI/ML
  3. BleepingComputer Windows 11 24H2 Home and Pro reach end of support in October

    Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]

    Enterprise IT Microsoft Windows
  4. The Hacker News Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

    Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an adviso...

    Enterprise IT
  5. The Hacker News Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

    A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be e...

    Enterprise IT
  6. BleepingComputer US takes down NightmareStresser DDoS-for-hire platform

    The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of...

    Government Cloud/SaaS
  7. The Hacker News CISO's Expert Guide to Agentic Pentesting for Websites

    Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (...

    Cloud/SaaS Google Cloud
  8. The Hacker News China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

    The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky...

    Enterprise IT
  9. Cisco Talos Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

    Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from Janu...

    Enterprise IT AI/ML Cisco
  10. BleepingComputer Chinese hackers use SparroWocky malware in govt espionage attacks

    The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin Americ...

    Government
  11. SANS Internet Storm Center ISC Stormcast For Thursday, September 17th, 2026 (Thu, Sep 17th) Enterprise IT
  12. Dark Reading AI Security Spending Jumps as Fear Outpaces Proof of Value

    CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?

    AI/ML
  13. SANS Internet Storm Center Scans Targeting Hospitality Applications, (Wed, Sep 16th)

    Earlier today, I noted an odd request showing up in our "First Seen" report:

    Enterprise IT
  14. KrebsOnSecurity Data Broker Radaris Loses Domains in Privacy Fight

    The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-se...

    Mobile/Consumer
  15. Dark Reading Fighting Your Dragons Through Tough Tech Times

    Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during h...

    Enterprise IT
  16. Dark Reading BragJack Attack Can Turn a Browser's Agentic AI Against It

    A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and ex...

    Enterprise IT AI/ML
  17. Cisco Security Advisories Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

    On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables.  T...

    Enterprise IT Cisco
  18. Cisco Security Advisories Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

    Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cis...

    Enterprise IT Government Cisco Secure Firewall Cisco
  19. Cisco Security Advisories Cisco Secure Firewall Management Center Software Static Credential Vulnerability

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log...

    Enterprise IT Cisco Secure Firewall Cisco
  20. Cisco Security Advisories Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulne...

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T...

    Enterprise IT Government Cisco Secure Firewall Cisco

Source directory.

Use this as the source map. Each source can be opened when you want to inspect its latest pulled items.

Advisories Government

CISA Cybersecurity Advisories

High-priority cybersecurity advisories, alerts, and defensive guidance from CISA.

Show latest from this source
  1. Siemens Reyrolle 7SR5

    Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to up...

    Government
Threat News Cybersecurity

The Hacker News

Cybersecurity news, threat activity, vulnerability reporting, and security research updates.

Show latest from this source
Threat News Incidents

BleepingComputer

Security news, malware campaigns, breach reporting, and vulnerability coverage.

Show latest from this source
Investigations Cybercrime

KrebsOnSecurity

Cybercrime investigations, breach analysis, fraud reporting, and security industry coverage.

Show latest from this source
  1. Microsoft Plugs Nearly 1,000 Security Holes

    Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest sing...

    Enterprise IT Microsoft Windows
  2. FBI Probes Service Selling 153M+ Drivers Licenses

    A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the...

    Government Cloud/SaaS
Threat Intel Handler Diary

SANS Internet Storm Center

Daily security observations, attack activity, and practitioner-focused incident notes from SANS ISC.

Show latest from this source
Security Research Google

Google Online Security Blog

Security engineering, vulnerability research, abuse prevention, and online safety updates from Google.

Show latest from this source
  1. Bringing Rust to the Pixel Baseband

    Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on...

    Enterprise IT
Advisories Cisco

Cisco Security Advisories

Official Cisco product security advisories and vulnerability notices.

Show latest from this source
Threat Intel Research

Cisco Talos

Threat intelligence, malware analysis, vulnerability research, and defensive reporting from Cisco Talos.

Show latest from this source
Threat Intel Research

Palo Alto Unit 42

Threat research, malware analysis, incident response insights, and adversary tracking from Unit 42.

Show latest from this source
  1. Atomic macOS (AMOS) Stealer Activity

    Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The pos...

    Enterprise IT Palo Alto Networks Apple macOS
Security Engineering Cloudflare

Cloudflare Security

Security engineering, network defense, cryptography, abuse prevention, and Internet security research.

Show latest from this source
Vulnerabilities Research

Tenable Research

Vulnerability research, exposure analysis, and security advisory coverage from Tenable.

Show latest from this source
  1. ScadaLTS Multiple Vulnerabilities

    ScadaLTS Multiple Vulnerabilities ScadaLTS is an open-source, web-based SCADA/HMI application. Version 2.8.1-release-candidate build 0 is affected by...

    Critical Infrastructure Education/Research
  2. GCP Apigee PE to Service Agent with API Proxy

    GCP Apigee PE to Service Agent with API Proxy  Tenable Research has identified and responsibly disclosed a privilege escalation vulnerability in Goog...

    AI/ML Education/Research Google Cloud
  3. WordPress - Kubio AI Website Builder DoS

    WordPress - Kubio AI Website Builder DoS The REST endpoint `GET /wp-json/kubio/v1/enable-theme` passes the client-supplied `name` parameter directly...

    Enterprise IT AI/ML Education/Research WordPress
  4. WordPress Loops & Logic - Reflected XSS

    WordPress Loops & Logic - Reflected XSS A Reflected Cross-Site Scripting vulnerability exists in the Wordpress plugin 'Loops & Logic' The ‘name’ para...

    Education/Research WordPress
Security News Enterprise

Dark Reading

Enterprise cybersecurity reporting, operations, risk, application security, and threat coverage.

Show latest from this source
  1. Fighting Your Dragons Through Tough Tech Times

    Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during h...

    Enterprise IT
Application Security Community

OWASP

Application security project updates, community news, and secure software guidance from OWASP.

Feed temporarily unavailable Open the RSS link directly or check back after the cache refreshes.
Security Government

FBI RSS

Public safety, cyber, and federal security updates from the official FBI feeds directory.

Show latest from this source

Import the whole list.

Use the OPML file to add the full CK Cyber reading list to a compatible RSS reader at once.

OPML