Security news
Latest security news
Mon, 14 Sept 2026
- Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR
The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defenses of a larger, AI-driven attack surface. For anyone evaluating MDR right now, the Managed Detection and Response Services Landscape, Q3 2026 report by Forrester is a useful map that lays out where the market is heading. This is a market that has moved beyond "do you cover my telemetry?" to “Can a provider connect and prove that its activity is tied to real reduction in risk?”. Rapid7 was named among the notable providers in this Forrester MDR Landscape. Being included matters to us, but the more interesting story is in what Forrester says about the market itself. Detection and exposure are becoming one service One of the report's clearest signals is directional: Forrester writes that "MDR services will converge with exposure and posture improvement.” That convergence is the whole basis of Rapid7 MDR and our Command Platform strategy. Most MDR services react after an attacker has already broken in. Rapid7
Rapid7 Blog - Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments.
Cybersecurity DiveGitLab - ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of
The Hacker NewsPaperCut - MongoDB security advisory (AV26-918)
Serial number: AV26-918 Date: September 14, 2026 As of September 11, 2026, MongoDB is affected by a vulnerability in the following product: MongoDB Server Prior to 7.0.43 Prior to 8.0.32 Prior to 8.3.11 Prior to 9.1.0-rc0 Prior to 9.0.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Shred collection validator constants during parsing Alerts | MongoDB
Canadian Centre for Cyber Security - Perfect-10 GitLab bug under attack days after patch lands
CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers
The RegisterGitLab - Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.
SecurityWeek - Google’s new search redirects make links harder to check before you click
Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.
Malwarebytes LabsGoogle - Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds
Infosecurity Magazine - Why Patch Automation Needs Brakes, Not Just an Accelerator
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control.
BleepingComputer - New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims.
SecurityWeek
About this news
- 1,264
- Stories
- 36
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets