Cloudflare's Certificate Transparency Monitoring is now generally available. The biggest change: we no longer email you about certificates Cloudflare issued for your domain, so when an alert lands in your inbox, it's worth a look.

Cloudflare has announced the general availability of its Certificate Transparency Monitoring service, a tool designed to help organizations detect unauthorized certificate issuance for their domains. The service, which had been in a beta phase, now offers a more robust and integrated solution for tracking certificates.
Certificate Transparency (CT) is an open framework that logs all publicly trusted SSL/TLS certificates issued by Certificate Authorities (CAs). This creates a public, auditable record, making it difficult for a CA to issue a certificate for a domain without the domain owner's knowledge. Cloudflare's monitoring service leverages these CT logs to provide alerts when new certificates are observed for registered domains.
The service is particularly useful for identifying potential misconfigurations or malicious activity. For instance, if an attacker successfully compromises a domain or a CA, they might attempt to issue unauthorized certificates to impersonate the legitimate website. By monitoring CT logs, organizations can quickly detect such attempts and take corrective action, such as revoking the fraudulent certificate.
Cloudflare's offering includes features such as real-time alerts and integration with existing Cloudflare accounts. This allows users to manage their monitored domains and receive notifications directly through the Cloudflare dashboard or via other configured alert channels. The service aims to enhance an organization's overall security posture by providing an additional layer of defense against certificate-related threats.
The move to general availability signifies that the service has undergone extensive testing and is now considered stable and ready for widespread use. Cloudflare emphasizes the importance of CT monitoring as a critical component of a comprehensive cybersecurity strategy, especially in an era where digital identity and trust are paramount.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets