IT Security News: today roundup CrowdStrike highlights training strategies to build resilient cybersecurity workforces. AWS launched open-weight AI models on Bedrock in Europe. A popular Twitch extension exposed account tokens for 30,000 users. Automated attackers scanned nearly two million Android…
Cyber-Attacks Cost Organizations $52,000 on Average
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
North Korea’s fake job interviews infected 30,000 devices
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
Threat Intelligence Alone Won’t Close the Exploitation Gap
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real…
Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
North Korean operators built a foothold on a DevOps engineer’s Mac in a campaign whose job interview lures deliver malware via Terraform lock files.
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it…
Fake CAPTCHA Scams
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
International investigation identifies over 70 potential victims exploited in Indian restaurants
The coordinated action conducted on 18 September 2026 led to two arrests. Allegedly, the traffickers forced their victims to work up to 16 hours per day,…
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the…
Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6…
IT Security News Hourly Summary 2026-09-18 19h : 17 posts
17 posts published in the last hour 16:31Google Opens Google Home to Claude and Other AI Agents — Here’s What They Can Control 16:31Settra ransomware variant deployed in recent attacks 16:312026 Péter Szőr Award shortlisted nominees 16:31FBI: Fake cop and…
Google Opens Google Home to Claude and Other AI Agents — Here’s What They Can Control
Google Home now lets Claude and other compatible AI agents inspect devices, review activity, and perform approved actions through Home MCP.
Settra ransomware variant deployed in recent attacks
Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools.
2026 Péter Szőr Award shortlisted nominees
VB Congratulates the researchers shortlisted for the 2026 Péter Szőr Award. Read more
FBI: Fake cop and government impersonation scams cost victims $1.6B
AI, fake uniforms, and mock government offices help crooks sell the con
Google Pixel owners urged to patch actively exploited modem flaw
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
Weekly summary of Cybersecurity Insider newsletters
Passwd Enterprise Review: Features, Pricing & Security
Review Passwd Enterprise pricing, security, Google Workspace integration, and private Google Cloud deployment to see if it fits your organization.
New Android malware uses AI to steal bank logins and PINs
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks…
Android Apps Can Now Check If Your Phone Is Missing Critical Security Patches
Android has released new Security State libraries that allow apps and enterprise tools to check whether a device is missing important security patches.…
Ministry of Justice apologizes after court staff accessed Southport victims’ files
Sensitive personal data was involved, but there is no evidence it was shared with third parties
Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than…
FBI, Coast Guard boarded hacked oil tankers heading towards US coast
The feds are said to be investigating the compromise of the tankers’ networks, which in one case interfered with one of the tanker’s navigation and…
MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login
MikroTik router owners face a security problem after researchers reproduced a takeover chain that can hand an outsider full administrator control without…
