Cyber Security News
The latest threat intelligence and security headlines from around the world — grouped by week and broken down by region, with a full historical archive.
Global AI Regulation Discussions Intensify
International bodies are accelerating discussions on the regulation of artificial intelligence as concerns grow over its potential use in automated cyberattacks.
Cybersecurity in the Age of AI Agents
Recent analysis highlights the evolution of cyber threats, referencing Anthropic's 2025 disclosure of the first large-scale cyberattack executed without significant human intervention.
Hackread: Latest Cybersecurity News and Trends
A comprehensive update on current global cybersecurity news, including emerging threats, AI developments, and ongoing cybercrime activities.
Google Gemini AI autonomously hacks websites during cybersecurity test
Google revealed that its Gemini AI model successfully and autonomously hacked three websites during a controlled test of its cybersecurity capabilities in May.
Cohesity report reveals 76% of organizations exceed cyberattack recovery goals
A new industry report indicates that while most organizations are meeting recovery goals, only 3% believe their current plans can withstand advanced modern cyberattacks.
TechJack Solutions Cybersecurity News Center
A centralized hub providing updated threat intelligence and active vulnerability tracking for global security professionals.
Cybersecurity News September 18, 2026: CrowdStrike, AI
A roundup of recent global cybersecurity developments, including analysis of CrowdStrike's AI strategy and emerging threats related to AI-assisted terrorism.
ACSC warns Aussie organisations of ongoing targeting of code repositories
The Australian Cyber Security Centre has issued a high-level alert regarding cyber attacks targeting online code repositories, urging organizations to address 'secrets sprawl' and credential security.
Major cyberattack on Australian ports suggests sabotage by a 'foreign state actor'
A serious cyberattack has disrupted operations at several of Australia’s largest ports, with operator DP World forced to shut down network access to contain the breach.
ZeroBEC Campaign Analysis
Security researchers have identified a new BEC campaign that successfully bypassed traditional security measures by avoiding fake Microsoft login pages.
Google Chrome Security Updates
Google has released critical security updates for the Chrome browser to address newly discovered vulnerabilities being exploited in the wild.
FBI and Indonesian Police Dismantle Global Phishing Infrastructure
The FBI, in collaboration with the Indonesian National Police, has dismantled a major phishing operation that used the W3LL toolkit to steal credentials and commit over $20 million in fraud.
Hackers Hijacking Vehicle Shipments
Auto shippers are reporting an increase in incidents where hackers are successfully hijacking vehicle shipments, highlighting vulnerabilities in supply chain security.
AI Cyberattacks Are Getting Faster
Recent industry reports indicate that cyberattacks leveraging artificial intelligence are accelerating in speed, posing new challenges for security teams globally.
Cyble and Cyber Security Council of UAE Sign MOU to Strengthen National Threat Intelligence
Cyble has entered into a Memorandum of Understanding with the UAE's Cyber Security Council to enhance national threat intelligence capabilities and cybersecurity infrastructure.
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has expanded its Known Exploited Vulnerabilities Catalog with four actively exploited security flaws impacting enterprise software. Federal agencies and private organizations are directed to remediate these flaws within specified timelines to mitigate active exploitation risks.
CISA Releases Updated Insider Threat Guide With Physical and Cyber Insights
The U.S. Cybersecurity and Infrastructure Security Agency published a comprehensive update to its Insider Threat Guide. The guidance provides new risk assessment frameworks helping organizations integrate detection capabilities across physical access and digital systems.
ICS Advisory Warns of Critical Flaws in CareCam Pro IP Cameras
CISA released industrial control systems advisory ICSA-26-251-01 detailing critical vulnerabilities in CareCam Pro IP cameras. The flaws could allow remote attackers to intercept feeds or execute unauthorized commands on affected network devices.
ASD Warns Aussie Adobe Commerce and Magento Stores Under Attack
The Australian Signals Directorate's ACSC issued a critical alert warning that Australian ecommerce deployments of Adobe Commerce and Magento Open Source are being actively targeted by threat actors. The attacks exploit CVE-2026-75650 (dubbed StyleSmuggler), an unauthenticated remote code execution flaw with a CVSS score of 10.0.
ASIC Highlights Growing ACSC Cyber Threat Landscape Alerts for Financial Sector
The Australian Securities and Investments Commission issued updated guidance warning financial licensees about escalating threats identified by the Australian Cyber Security Centre. Financial firms are urged to harden perimeter defences and maintain strict incident notification protocols.
CBA Deploys Twin AI Agent Architecture to Defend Banking Systems
The Commonwealth Bank of Australia has engineered two bespoke artificial intelligence agents dedicated to monitoring enterprise networks and triaging anomalous activity. The automated defence system aims to identify intrusions and assist security operations center teams in rapid incident containment.
Supply Chain Malware Campaign 'CanisterWorm' Targets npm Registry
Security researchers have uncovered a new malicious worm dubbed 'CanisterWorm' propagating across developer ecosystems via poisoned npm packages. The malware seeks to hijack deployment credentials and exfiltrate secrets from compromised continuous integration pipelines.
ACSC Warns of Phishing Campaigns Impersonating Australian Signals Directorate Personnel
The ACSC published an urgent advisory warning organizations and citizens about ongoing social engineering operations where malicious actors impersonate ASD cyber security officials. Attackers utilize deceptive emails and calls attempting credential theft and malware delivery under the guise of official cyber incident investigations.
ASD Issues Warning Over Critical TeamCity Vulnerability Exploitation
The Australian Cyber Security Centre (ACSC) issued a warning after observing active exploitation targeting Australian JetBrains TeamCity servers. Malicious cyber actors are actively attempting to leverage the vulnerability to achieve compromise on exposed build and continuous integration systems.
Elementor Pro WordPress Plugin Vulnerability Actively Exploited to Compromise Websites
Threat actors are actively exploiting a critical vulnerability tracked as CVE-2026-32475 in the Elementor Pro WordPress plugin to compromise websites. The flaw allows unauthenticated remote attackers to perform arbitrary file uploads via vulnerable form submission handlers.
HPE Patches Critical Remote Code Execution Flaws in AOS-CX
Hewlett Packard Enterprise released emergency security fixes addressing nearly two dozen vulnerabilities, tracked collectively as CVE-2026-73749 with a CVSS score of 9.8. Unauthenticated attackers could exploit the bugs over the network to execute arbitrary code with elevated privileges.
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
OpenAI announced its new $1 billion Daybreak initiative to supply subsidized frontier AI capabilities, training, and technical assistance to frontline cyber defenders in local government, water, and power sectors. The move comes as critical infrastructure operators face intensifying nation-state and automated cyber threats.
Hackers Compromise Thousands of Dropbox Accounts via Credential Stuffing
Security researchers revealed that attackers compromised over 5,000 corporate Dropbox accounts using widespread credential-stuffing and targeted authentication bypass attempts. The incident emphasizes persistent exposure caused by third-party credential leaks and lack of phishing-resistant MFA.
Partnered Health Confirms Cyber Incident Affecting Patient Information Across National Clinic Network
Australian healthcare provider Partnered Health confirmed a security incident that impacted sensitive patient information across its national clinic network. The organization initiated response procedures and notified authorities to mitigate further risk.
Analysis of Origin Energy Data Breach Highlights Ongoing Risks for Australian Utilities
Fresh analysis detailing the fallout and lessons learned from the Origin Energy breach examines the recurring impact on consumer trust and identity data security across Australia. The review urges Australian businesses to strengthen identity governance and credential monitoring.
US, China gear up for mid-September AI safety talks
Diplomatic and security representatives from the United States and China are preparing for bilateral discussions focused on artificial intelligence safety and cyber risk management. The initiative aims to establish safeguards and mitigate critical vulnerabilities across emerging AI-enabled threat landscapes.
Red Piranha Joins University Western Australia Global Engagement Alliance for Cybersecurity Collaboration
Red Piranha has partnered with the University of Western Australia to foster global cybersecurity collaboration and research initiatives.
Cyber Security News
A collection of the latest updates on global data breaches, ransomware campaigns, and emerging industry security trends.
Cybersecurity Daily Briefing: September 03, 2026
A comprehensive daily summary of critical cybersecurity threats, vulnerabilities, and industry news affecting global enterprises.
Australian Arrests Close a Chapter on One of 2026’s Largest Open Source Supply Chain Attacks
Law enforcement in Australia has made significant arrests related to a major open-source supply chain attack that impacted global software ecosystems earlier this year.
Australian Firms Lose Work Amid Skilled Staff Shortages
Australian employers are reporting lost business and operational challenges due to a persistent shortage of skilled cybersecurity professionals.
JFrog Artifactory CVE-2026-82329 Exploited Days After Patch
Threat actors are actively exploiting a critical vulnerability in JFrog Artifactory, identified as CVE-2026-82329, shortly after the security patch was released.
SonicWall Warns of Two Chained SMA1000 Zero-Days Under Active Exploitation
SonicWall has issued an urgent warning regarding two zero-day vulnerabilities in its SMA1000 series products that are currently being chained and exploited in the wild.
AppsFlyer report flags diverging APAC app growth trends
A new report indicates that while finance and payment app adoption is rising in the APAC region, gaming and retention metrics are showing signs of slowing.