Automatic cybersecurity RSS aggregation

Cybersecurity Feeds

CK Cyber collects the latest RSS items from selected advisory, threat intelligence, vulnerability research, and security news sources, then renders them here without third-party browser scripts.

Advisories Threat Intel Vulnerabilities AppSec
Last refreshed Aug 3, 2026 10:34 AM ET
Next refresh Aug 4, 2026 7:00 AM ET
Sources online 14 / 14
Headlines loaded 56

Latest cybersecurity headlines.

Newest items from the monitored security sources, sorted by published date.

  1. The Hacker News ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

    This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public system...

    Financial Services AI/ML Critical Infrastructure
  2. Dark Reading Is There Really a Fix for CISO Fatigue?

    Accountability without any real authority is driving CISO burnout, and organizations need to take notice.

    Enterprise IT
  3. The Hacker News FOMO in the SOC: Where AI Platforms like Claude Actually Fit

    AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already he...

    AI/ML OpenAI Anthropic Claude
  4. The Hacker News Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

    An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkS...

    Mobile/Consumer Apple iOS
  5. Palo Alto Unit 42 Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

    Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single fac...

    Enterprise IT Palo Alto Networks
  6. The Hacker News PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

    The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the...

    Government
  7. SANS Internet Storm Center ISC Stormcast For Monday, August 3rd, 2026 (Mon, Aug 3rd) Enterprise IT
  8. BleepingComputer OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

    OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant adv...

    AI/ML OpenAI
  9. BleepingComputer COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

    A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose...

    Financial Services
  10. BleepingComputer Google Chrome may soon block New Tab hijacker extensions by default

    Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the defaul...

    Enterprise IT Google Chrome
  11. SANS Internet Storm Center Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd) Enterprise IT Apple macOS
  12. BleepingComputer Rails patches critical Active Storage flaw with RCE potential

    A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and...

    Enterprise IT
  13. SANS Internet Storm Center Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

    Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impe...

    AI/ML
  14. Cisco Security Advisories Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to byp...

    Enterprise IT Cisco Secure Firewall Cisco
  15. Cisco Security Advisories Cisco Secure Firewall Management Center Software Static Credential Vulnerability

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log...

    Enterprise IT Cisco Secure Firewall Cisco
  16. Dark Reading CISA Issues Fresh SBOM Guidance. Did They Get It Right?

    A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.

    Government
  17. Dark Reading The Morning After We Pull a Root of Trust, Nobody Owns It

    The most valuable move any security team can make is building a certificate and key inventory.

    Enterprise IT
  18. Dark Reading Interpol Leverages Global System to Curtail Fraud Payments

    When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.

    Government Financial Services
  19. Palo Alto Unit 42 The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

    Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The...

    Enterprise IT Software Supply Chain AI/ML Palo Alto Networks Apple macOS
  20. SANS Internet Storm Center zipdump.py: Metadata Encoding, (Fri, Jul 31st)

    I was asked for help with a problem similar to the following.

    Enterprise IT

Source directory.

Use this as the source map. Each source can be opened when you want to inspect its latest pulled items.

Advisories Government

CISA Cybersecurity Advisories

High-priority cybersecurity advisories, alerts, and defensive guidance from CISA.

Show latest from this source
  1. Schneider Electric IGSS

    Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The IGSS prod...

    Critical Infrastructure Government
  2. Open Source Software: Security Principles and Practices

    Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Soft...

    Critical Infrastructure Software Supply Chain Government
Threat News Cybersecurity

The Hacker News

Cybersecurity news, threat activity, vulnerability reporting, and security research updates.

Show latest from this source
Threat News Incidents

BleepingComputer

Security news, malware campaigns, breach reporting, and vulnerability coverage.

Show latest from this source
Investigations Cybercrime

KrebsOnSecurity

Cybercrime investigations, breach analysis, fraud reporting, and security industry coverage.

Show latest from this source
  1. Read This Before You Buy That TV Streaming Stick

    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-...

    Enterprise IT
  2. LG to Ban Residential Proxies from Smart TV Apps

    The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an al...

    Enterprise IT
  3. Microsoft Patches a Record 570 Security Flaws

    Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost tripl...

    Enterprise IT Microsoft Windows
  4. Lessons Learned from CISA’s Recent GitHub Leak

    The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal...

    Government Software Supply Chain GitHub
Threat Intel Handler Diary

SANS Internet Storm Center

Daily security observations, attack activity, and practitioner-focused incident notes from SANS ISC.

Show latest from this source
Security Research Google

Google Online Security Blog

Security engineering, vulnerability research, abuse prevention, and online safety updates from Google.

Show latest from this source
  1. Bringing Rust to the Pixel Baseband

    Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on...

    Enterprise IT
Advisories Cisco

Cisco Security Advisories

Official Cisco product security advisories and vulnerability notices.

Show latest from this source
Threat Intel Research

Cisco Talos

Threat intelligence, malware analysis, vulnerability research, and defensive reporting from Cisco Talos.

Show latest from this source
  1. Black Hat special: Rewind and revisit

    Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.

    Enterprise IT Cisco
  2. Don’t swing at everything

    Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

    Enterprise IT Cisco
Threat Intel Research

Palo Alto Unit 42

Threat research, malware analysis, incident response insights, and adversary tracking from Unit 42.

Show latest from this source
  1. Russian Global Webmail Espionage

    Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian...

    Enterprise IT Palo Alto Networks
Security Engineering Cloudflare

Cloudflare Security

Security engineering, network defense, cryptography, abuse prevention, and Internet security research.

Show latest from this source
Vulnerabilities Research

Tenable Research

Vulnerability research, exposure analysis, and security advisory coverage from Tenable.

Show latest from this source
  1. Link Library - Reflected Cross-Site Scripting

    Link Library - Reflected Cross-Site Scripting The WordPress Plugin Link Library version below 7.9.4 is affected by an unauthenticated Reflected XSS.T...

    Software Supply Chain Education/Research WordPress
Security News Enterprise

Dark Reading

Enterprise cybersecurity reporting, operations, risk, application security, and threat coverage.

Show latest from this source
Application Security Community

OWASP

Application security project updates, community news, and secure software guidance from OWASP.

Show latest from this source
Security Government

FBI RSS

Public safety, cyber, and federal security updates from the official FBI feeds directory.

Show latest from this source
  1. Special Event Security

    Across the country—and sometimes in other countries—the FBI plays a critical role in keeping everyone safe at the public gatherings the U.S. Departme...

    Government

Import the whole list.

Use the OPML file to add the full CK Cyber reading list to a compatible RSS reader at once.

OPML