The U.S. Cybersecurity and Infrastructure Security Agency's running feed of cybersecurity advisories and alerts: newly disclosed vulnerabilities, active exploits, and mitigation guidance for organizations and individuals.
CISA alert (September 27, 2026) warning that critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited, with guidance on patching and detection.
A security writeup from Peter James: after asking Meta's Muse agent to archive the files it could see and send them to Google Drive, the download contained the root filesystem of the session's Linux environment — Muse's internal documentation, memory files, agent logs and SSH key files. The findings were reported through Meta's bug bounty program; the archive, keys and session logs were not published.
An independent, one-person observatory by Mara Masaeva that looks for coordinated AI-agent swarms using public internet data. It publishes its full research log, including replications of the public-scanner trace of the 2026 agent activity documented by Transluce, and the detectors and searches that failed.
Anthropic's Threat Intelligence team shares case studies of operations it disrupted in which threat actors tried to use Claude for malicious activity — cyber operations, surveillance, influence operations, scams and more — and how malicious use has evolved since earlier reports.
A four-course specialization on ingesting, transforming, storing and serving data to stakeholders, taught on Coursera. Free to audit; a paid subscription adds graded assignments and a certificate.