Cybersecurity News
Understand the Threats. Protect What Matters.
- Flock Once Touted Its Cameras as ‘Made in the USA.’ Now It’s Not So Clearby Paresh Dave on September 17, 2026 at 9:00 am
Flock reveals little about where its license plate readers are assembled, but the answer could have geopolitical and cybersecurity implications.
- Data Broker Radaris Loses Domains in Privacy Fightby BrianKrebs on September 16, 2026 at 6:14 pm
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.
- New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activityby CISA on September 16, 2026 at 12:00 pm
- Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Worksby Dhruv Mehrotra, Joseph Cox on September 16, 2026 at 10:30 am
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.
- CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems from Token Theft, Forgery, and Misuseby CISA on September 15, 2026 at 12:00 pm
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to [email protected]
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zoneby [email protected] (The Hacker News) on September 17, 2026 at 12:30 pm
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with
- Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinarby [email protected] (The Hacker News) on September 17, 2026 at 11:50 am
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
- CISO’s Expert Guide to Agentic Pentesting for Websitesby [email protected] (The Hacker News) on September 17, 2026 at 10:50 am
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin Americaby [email protected] (The Hacker News) on September 17, 2026 at 10:05 am
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. “SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
- OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploadsby [email protected] (The Hacker News) on September 17, 2026 at 9:53 am
OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. “As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the








