<<Page Under Construction 😉 >>
What does RSS even mean? RSS stands for “Really Simple Syndication”, which is a standardized system for the distribution of content from an online publisher to Internet users.
What this really means is that below, you’ll find some news feeds that I’ve chosen to follow on this page. I’m not responsible for the content, but I have tried to focus the sources to be interesting to Cybersecurity and Information Security professionals. Or, anyone who is interested in those topics. Or, anyone at all who would like to read them.
If you’re the author of a feed, or have a suggestion on one I should add to this page, please drop me a note!
General Cyber News Feeds
Forbes – Cybersecurity News
ZDNet – Security News
KrebsOnSecurity – In-depth Security News and Investigation
CSO Online, from IDG – Hottest Topics on Cyber and Security
The Hacker News – Cybersecurity News and Analysis
The Guardian – Data and Security
Threatpost – First Stop for Security News
Dark Reading – Connecting the Information and Security Community
SANS Institute – Security Awareness Tip of the Day
Help Net Security – Daily infosec news with a focus on enterprise security
IT Security Central – User Activity Monitoring | DLP | Employee Productivity
TechRepublic – Straight up Security
WeLiveSecurity – News, views, and insight from the ESET security community
Schneier on Security – A blog covering security and security technology
Lohrmann on Cybersecurity – Government Technology RSS Feed
Forbes – Cybersecurity News
- Feed has no items.
ZDNet – Security News
- Feed has no items.
Krebs On Security – In-depth Security News and Investigation
- Who’s Tracking You? Use This New Service to Find Outon 2026-08-14
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful […]
- Microsoft Plugs Nearly 400 Security Holeson 2026-08-11
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
- Canadian Man Pleads Guilty in Snowflake Extortionson 2026-08-06
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text […]
- Read This Before You Buy That TV Streaming Stickon 2026-07-30
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones […]
- LG to Ban Residential Proxies from Smart TV Appson 2026-07-22
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown […]
- Microsoft Patches a Record 570 Security Flawson 2026-07-14
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by […]
CSO Online, from IDG – Hottest Topics on Cyber and Security
- Feed has no items.
The Hacker News – Cybersecurity News and Analysis
- Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debton 2026-08-24 by info@thehackernews.com (The Hacker News)
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more […]
- Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoningon 2026-08-24 by info@thehackernews.com (The Hacker News)
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed […]
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and Moreon 2026-08-24 by info@thehackernews.com (The Hacker News)
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. […]
- WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwordson 2026-08-24 by info@thehackernews.com (The Hacker News)
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain […]
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Accounton 2026-08-24 by info@thehackernews.com (The Hacker News)
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, […]
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdooron 2026-08-24 by info@thehackernews.com (The Hacker News)
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity […]
The Guardian – Data and Security
- Feed has no items.
Threatpost – First Stop for Security News
- Student Loan Breach Exposes 2.5M Recordson 2022-08-31 by Nate Nelson
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggeron 2022-08-30 by Nate Nelson
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmson 2022-08-29 by Nate Nelson
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseon 2022-08-26 by Nate Nelson
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerason 2022-08-25 by Nate Nelson
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
- Twitter Whistleblower Complaint: The TL;DR Versionon 2022-08-24 by Threatpost
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Dark Reading – Connecting the Information and Security Community
- Feed has no items.
SANS Institute – Security Awareness Tip of the Day
- Feed has no items.
Help Net Security – Daily infosec news with a focus on enterprise security
- AI supply chain risk is showing up in developer workflows firston 2026-08-25 by Mirko Zorz
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos. He explains why segmentation buys more risk […]
- TruffleHog AWS Analyze reduces remediation time on leaked AWS credentialson 2026-08-25 by Sinisa Markovic
Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise already finds and verifies leaked credentials across 800+ secret […]
- HOL Guard: Open-source antivirus for AI agentson 2026-08-25 by Anamarija Pogorelec
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Your files are never uploaded, and the whole thing works with […]
- The cybercrime supply chain has five stages, each with a priceon 2026-08-25 by Help Net Security
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run infostealer malware, brokers who verify and resell access, ransomware-as-a-service operators who […]
- New TCG guidance gives buyers a way to test PQC-ready TPM claimson 2026-08-25 by Help Net Security
The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers can now ask a vendor for evidence against a […]
- Cybersecurity jobs available right now: August 25, 2026on 2026-08-25 by Sinisa Markovic
Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and court orders, and provide authorized subscriber, […]
IT Security Central – User Activity Monitoring | DLP | Employee Productivity
- Feed has no items.
TechRepublic – Straight up Security
- Microsoft Exchange Server SE CU1 Delayed Amid AI-Assisted Security Reviewson 2026-08-24 by TechRepublic Staff
Microsoft has yet to set a firm Exchange Server SE CU1 release date as engineers work through AI-assisted security findings and ongoing patch releases. The post Microsoft Exchange Server SE CU1 Delayed Amid AI-Assisted Security Reviews appeared first on TechRepublic.
- ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remainon 2026-08-24 by TechRepublic Staff
ChatGPT for Teens adds stronger protections for users ages 13 to 17, but parents still face limits around monitoring, age prediction, and AI safety. The post ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain appeared first on TechRepublic.
- Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Waiton 2026-08-21 by Aminu Abdullahi
Google’s new Android verification flow adds a 24-hour wait for apps from unverified developers as broader identity checks approach. The post Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait appeared first on TechRepublic.
- ICE Warns Employees Against Meta Smart Glasseson 2026-08-20 by Joseph Ofonagoro
ICE warned employees against using Meta smart glasses on duty as DHS seeks $7.5 million to develop biometric-enabled prototypes for field agents. The post ICE Warns Employees Against Meta Smart Glasses appeared first on TechRepublic.
- Windows 11 24H2 Home and Pro Support Ends Oct. 13: What Users Should Doon 2026-08-20 by Aminu Abdullahi
Windows 11 24H2 Home and Pro support ends Oct. 13, 2026. Here’s what users and IT teams should know about upgrading to Windows 11 25H2. The post Windows 11 24H2 Home and Pro Support Ends Oct. 13: What Users Should Do appeared first on TechRepublic.
- Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Offon 2026-08-20 by Joseph Ofonagoro
Amazon’s less-detailed order emails protect purchase data but may make phishing harder to spot. Learn how to verify order messages safely online. The post Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off appeared first on TechRepublic.
WeLiveSecurity – News, views, and insight from the ESET security community
- How QR-code phishing can slip past corporate security measureson 2026-08-17
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
- Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?on 2026-08-13
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
- Black Hat USA 2026: What the Hugging Face hack tells us about human responsibilityon 2026-08-13
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
- Black Hat USA 2026: AI is racing ahead of cybersecurity controlson 2026-08-12
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
- Are AI tutors safe for your kids?on 2026-08-10
AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.
- This month in security with Tony Anscombe – July 2026 editionon 2026-07-31
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
Schneier on Security – A blog covering security and security technology
- Feed has no items.
Lohrmann on Cybersecurity – Government Technology RSS Feed
- Slopsquatting in the Supply Chain: Weaponized AI Hallucinationson 2026-08-23
In this interview with Snyk CTO Manoj Nair, we examine how attackers weaponize recurring LLM package hallucinations before developers even hit "run."
- Hacking Back Is Back: White House to Enable Cyber Privateerson 2026-08-17
In an Aug. 12 National Security Presidential Memorandum, President Donald Trump set out guidance for more private-sector action in global cyber battles. Here’s the rest of the story.
- Innovation or Negligence? What Recent AI Hacks Mean for the Future of Cybersecurityon 2026-08-09
Wonderful capability or ethical failure? Decoding the stories coming out of Black Hat USA and the unsanctioned AI cyber attacks of 2026.
- How New Laws Will Help Guard Seniors Against Scamson 2026-08-02
In a rare show of bipartisan agreement, both the U.S. House and the Senate have voted to approve bills aimed at battling fraud — especially scams aimed at older adults.
- Virtual Integrity Revisited: 7 Habits for the AI Ageon 2026-07-26
In Part 3 of this exploration of AI ethics, we bring this topic closer to home: How can we use the power of AI to strengthen human trust and character?
- From Principles to Practice: Actionable Blueprints for Ethical AIon 2026-07-19
Part 2 of this series on ethical AI looks at operationalizing trust with clear prompting framework and robust data governance for your public- or private-sector organization.
#StayVigilant
#StaySafe
#LookOutForEachOther

















