Attackers exploited CVE-2026-73570 to compromise 274 Zimbra servers, while 8,200 systems remain unpatched. Learn what administrators should check.
ICYMI: July 2026 @AWS Security
If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service…
IT Security News Hourly Summary 2026-08-26 22h : 7 posts
7 posts published in the last hour 19:31OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers 19:3121 Critical Ubiquiti UniFi Flaws Enable Authentication Bypass, Command Injection and Privilege Escalation 19:31More than 100 water systems were hit in July…
OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn’t see this…
21 Critical Ubiquiti UniFi Flaws Enable Authentication Bypass, Command Injection and Privilege Escalation
Ubiquiti has patched 21 critical-severity vulnerabilities spanning nearly its entire UniFi product line, warning that attackers with only network access…
More than 100 water systems were hit in July cyberattacks
‘These are test runs for a larger-scale attack’
Critical Next.js Vulnerabilities Enables Remote Code Execution Attacks
Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF…
Shrinking Patch Windows, Quantum Risk And Rogue AI Agents: The Three Threats Collapsing Modern Security Assumptions
Security teams are entering a period where many of the assumptions that shaped modern cybersecurity programs no longer hold the way they once did. Until…
WhatsApp Introduces Multi-Passkey and Complex 2FA Upgrades
Cross-Platform Passkey Integration Meta revealed a major security upgrade for WhatsApp on August 25, 2026, which increases passkey support and enables…
IT Security News Hourly Summary 2026-08-26 21h : 10 posts
10 posts published in the last hour 18:31Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations 18:31CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates 18:31ASOS Account Takeover Attack Exposes…
Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations
The company won’t say if medical devices are affected or if any customer data was exfiltrated.
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
ASOS Account Takeover Attack Exposes Data of 138,828 Customers
ASOS says attackers used credentials stolen elsewhere to access customer accounts, exposing personal data belonging to an estimated 138,828 people.
Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business…
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat…
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and…
FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and…
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian…
IT Security News Hourly Summary 2026-08-26 20h : 3 posts
3 posts published in the last hour 17:31US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate 17:01US Police Officers Face Arrests and Firing for Misusing Flock Camera Data 17:00IT Security News Hourly Summary 2026-08-26…
US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
The FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments.
US Police Officers Face Arrests and Firing for Misusing Flock Camera Data
Police officers across the United States are facing arrests, firings and investigations for allegedly misusing Flock Safety’s automated license plate…
IT Security News Hourly Summary 2026-08-26 19h : 9 posts
9 posts published in the last hour 16:31WhatsApp Just Added 3 New Ways to Protect Your Account 16:31TikTok Agrees to $400M Settlement Over Children’s Privacy 16:31The Password Notebook Is Back — but Is It Actually Safer? 16:02Who Has Admin Rights…
WhatsApp Just Added 3 New Ways to Protect Your Account
WhatsApp is adding stronger two-step verification, multiple passkeys and more context for unknown callers as it expands protections against scams.