<<Page Under Construction 😉 >>
What does RSS even mean? RSS stands for “Really Simple Syndication”, which is a standardized system for the distribution of content from an online publisher to Internet users.
What this really means is that below, you’ll find some news feeds that I’ve chosen to follow on this page. I’m not responsible for the content, but I have tried to focus the sources to be interesting to Cybersecurity and Information Security professionals. Or, anyone who is interested in those topics. Or, anyone at all who would like to read them.
If you’re the author of a feed, or have a suggestion on one I should add to this page, please drop me a note!
General Cyber News Feeds
Forbes – Cybersecurity News
ZDNet – Security News
KrebsOnSecurity – In-depth Security News and Investigation
CSO Online, from IDG – Hottest Topics on Cyber and Security
The Hacker News – Cybersecurity News and Analysis
The Guardian – Data and Security
Threatpost – First Stop for Security News
Dark Reading – Connecting the Information and Security Community
SANS Institute – Security Awareness Tip of the Day
Help Net Security – Daily infosec news with a focus on enterprise security
IT Security Central – User Activity Monitoring | DLP | Employee Productivity
TechRepublic – Straight up Security
WeLiveSecurity – News, views, and insight from the ESET security community
Schneier on Security – A blog covering security and security technology
Lohrmann on Cybersecurity – Government Technology RSS Feed
Forbes – Cybersecurity News
- Feed has no items.
ZDNet – Security News
- Feed has no items.
Krebs On Security – In-depth Security News and Investigation
- Read This Before You Buy That TV Streaming Stickon 2026-07-30
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones […]
- LG to Ban Residential Proxies from Smart TV Appson 2026-07-22
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown […]
- Microsoft Patches a Record 570 Security Flawson 2026-07-14
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by […]
- Lessons Learned from CISA’s Recent GitHub Leakon 2026-07-13
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's […]
- Felons, Fraudsters Flog Offensive Cybersecurity Startupon 2026-07-08
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
- FBI Seizes NetNut Proxy Platform, Popa Botneton 2026-07-02
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from […]
CSO Online, from IDG – Hottest Topics on Cyber and Security
- Feed has no items.
The Hacker News – Cybersecurity News and Analysis
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokenson 2026-08-04 by info@thehackernews.com (The Hacker News)
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user […]
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hookson 2026-08-04 by info@thehackernews.com (The Hacker News)
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 […]
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Accesson 2026-08-04 by info@thehackernews.com (The Hacker News)
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise […]
- When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wantedon 2026-08-04 by info@thehackernews.com (The Hacker News)
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced […]
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agenton 2026-08-04 by info@thehackernews.com (The Hacker News)
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as […]
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rooton 2026-08-04 by info@thehackernews.com (The Hacker News)
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The […]
The Guardian – Data and Security
- Feed has no items.
Threatpost – First Stop for Security News
- Student Loan Breach Exposes 2.5M Recordson 2022-08-31 by Nate Nelson
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggeron 2022-08-30 by Nate Nelson
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmson 2022-08-29 by Nate Nelson
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseon 2022-08-26 by Nate Nelson
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerason 2022-08-25 by Nate Nelson
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
- Twitter Whistleblower Complaint: The TL;DR Versionon 2022-08-24 by Threatpost
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Dark Reading – Connecting the Information and Security Community
- Feed has no items.
SANS Institute – Security Awareness Tip of the Day
- Feed has no items.
Help Net Security – Daily infosec news with a focus on enterprise security
- AI developers targeted via trojanized GitHub repositorieson 2026-08-04 by Sinisa Markovic
Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in April 2026, that was spread through the ClickFix social engineering […]
- Sevii APS Module preempts attacks with autonomous cyber defenson 2026-08-04 by Industry News
Sevii has announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module complements ADRs autonomous defense against threats, extending the platform to continuously transform customer’s external global and internal […]
- ServiceNow organizes autonomous security around six solution areason 2026-08-04 by Industry News
ServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, and agentic incident response, and cyber risk and […]
- Snyk unveils continuous AI pentesting and agent red teamingon 2026-08-04 by Industry News
Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could actually exploit. AI is accelerating software release cycles while rapidly […]
- RapidFort Runtime brings continuous CVE monitoring and tamper detectionon 2026-08-04 by Industry News
RapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The offerings provide end-to-end continuous threat elimination, from curated, independently malware-scanned open-source software before deployment to continuous CVE monitoring and tamper detection […]
- Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malwareon 2026-08-04 by Sinisa Markovic
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threat Intelligence. Overview of the CaptiveCrunch attack flow (Source: Microsoft) Microsoft named the […]
IT Security Central – User Activity Monitoring | DLP | Employee Productivity
- Feed has no items.
TechRepublic – Straight up Security
- Open Secure AI Alliance Expands at Black Hat: What You Should Knowon 2026-08-04 by Zeus Kerravala
The Open Secure AI Alliance introduced SAFE guidelines and open agent-security tools at Black Hat, giving enterprises a framework for safer AI deployment. The post Open Secure AI Alliance Expands at Black Hat: What You Should Know appeared first on TechRepublic.
- Gmail’s New Feature Warns You Before Revealing You Were BCC’don 2026-08-04 by Kezia Jungco
Gmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address. The post Gmail’s New Feature Warns You Before Revealing You Were BCC’d appeared first on TechRepublic.
- Samsung Will Ban Smart TV Apps Containing Residential Proxy Softwareon 2026-08-04 by Joseph Ofonagoro
Samsung plans to ban Smart TV apps containing residential proxy software after researchers found apps could route traffic through users’ home connections. The post Samsung Will Ban Smart TV Apps Containing Residential Proxy Software appeared first on TechRepublic.
- Chrome to Block Policy-Abusing Extensions on Personal Deviceson 2026-08-04 by Joseph Ofonagoro
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices. The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic.
- Why Apple’s Recent Crypto Lawsuit Should Worry Australian IT Leaderson 2026-08-04 by Joseph Ofonagoro
A $1.8 million App Store scam lawsuit tests how much software vetting Australian firms can safely outsource. The post Why Apple’s Recent Crypto Lawsuit Should Worry Australian IT Leaders appeared first on TechRepublic.
- Microsoft Project Perception Enters Public Preview: What Security Teams Should Knowon 2026-08-04 by TechRepublic Staff
Microsoft’s Project Perception brings coordinated AI agents into security operations, raising new questions about permissions, oversight, accuracy, and deployment risk. The post Microsoft Project Perception Enters Public Preview: What Security Teams Should Know appeared first on TechRepublic.
WeLiveSecurity – News, views, and insight from the ESET security community
- This month in security with Tony Anscombe – July 2026 editionon 2026-07-31
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
- Beyond the screenshot: Why you should verify what you seeon 2026-07-30
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
- Forgotten UEFI shims undermining Secure Booton 2026-07-14
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
- ESET Threat Report H1 2026on 2026-07-08
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
- Cyber readiness for SMBs: Getting the basics righton 2026-07-03
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
- This month in security with Tony Anscombe – June 2026 editionon 2026-06-30
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
Schneier on Security – A blog covering security and security technology
- Iran Cyberattacks Against Minnesota Water Systemson 2026-08-04
Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” […]
- Some Claude Chats Are Searchable on Googleon 2026-08-04
And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ […]
- More on the OpenAI Agent’s Attack on Hugging Faceon 2026-08-03
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their […]
- The OpenAI Hack Shows the Genie Is Out of the Bottleon 2026-08-03
This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running […]
- Friday Squid Blogging: Squid Helps Discover New Marine Specieson 2026-07-31
The Squid is a new scientific machine: One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging […]
- Anthropic’s Opus 5 Is Better at Resisting Prompt Injectionon 2026-07-31
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all […]
Lohrmann on Cybersecurity – Government Technology RSS Feed
- How New Laws Will Help Guard Seniors Against Scamson 2026-08-02
In a rare show of bipartisan agreement, both the U.S. House and the Senate have voted to approve bills aimed at battling fraud — especially scams aimed at older adults.
- Virtual Integrity Revisited: 7 Habits for the AI Ageon 2026-07-26
In Part 3 of this exploration of AI ethics, we bring this topic closer to home: How can we use the power of AI to strengthen human trust and character?
- From Principles to Practice: Actionable Blueprints for Ethical AIon 2026-07-19
Part 2 of this series on ethical AI looks at operationalizing trust with clear prompting framework and robust data governance for your public- or private-sector organization.
- On AI Ethics: Why Prompt Engineering Needs a Moral Compasson 2026-07-12
In this first of a three-part series, we look at why “working as designed” is no longer good enough for enterprise AI or cybersecurity pros.
- Navigating NIST’s New Cybersecurity AI Frontieron 2026-07-05
AI and quantum guidance are driving the future of the National Institute of Standards and Technology Cybersecurity Framework. Here’s how.
- AI at Work: Employees Aren’t Waiting for Permissionon 2026-06-28
New research is showing that staff are bringing their own AI to work at a growing pace, and security predictions from years ago are coming to fruition now. What’s the trend and what can you do?
#StayVigilant
#StaySafe
#LookOutForEachOther

















