Security news

Latest security news

24 of 1,256 storiesContiClear all

Yesterday · Tue, 15 Sept 2026

  1. What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies

    Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned.

    CyberScoop
  2. “We Think the Security Control Is Working” Is No Longer Good Enough

    Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.

    SecurityWeek
  3. Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

    Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these

    The Hacker News

Mon, 14 Sept 2026

  1. WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

    WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin

    The Hacker NewsWordPress
  2. Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

    We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.

    Unit 42

Fri, 11 Sept 2026

  1. The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

    Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence. With fraud damages anticipated to approach hundreds of billions of USD , security teams must navigate numerous non-compliant channels while ingesting and processing diverse data formats—such as documents, imagery, video, and unformatted text—linked to organizational assets. The recent introduction of a new Fraud framework by the MITRE organization underscores the critical need to combat fraud and highlights the significant danger these threat actors pose to all organizations. The MITRE organization has been taking a positive step towards standardizing the fight against fraud, while helping organizations target the relevant directions to look

    Rapid7 Blog
  2. Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

    Swapping legal work for malware development ended in extradition and a guilty plea

    The Register
  3. Ukrainian hacker gets four years in US prison over Conti ransomware attacks

    A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.

    The Record
  4. Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

    Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

    SecurityWeek
  5. Conti ransomware gang member sentenced to 4 years in prison

    A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.

    BleepingComputer

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets