McKesson, a major U.S.
Secure AI Systems: Defending Enterprise Applications Against Agent-Era Threats
The rise of autonomous AI agents within business software demands a fresh approach to security. Unlike earlier chatbot tools, modern agents act with real…
Debian votes to allow AI-assisted coding
The Debian Linux distribution community has formally adopted a policy allowing the use of generative AI tools in software development, following a vote…
McKesson Confirms Data Breach as Attacker Deadline Looms
The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.
Anthropic Warns Claude Users of Infostealer Infections
Anthropic has begun forcibly logging users out of Claude AI accounts and removing stored payment data after detecting widespread infostealer malware…
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This…
Hugging Face Incident: AI Agent Access Lessons
A recent security incident at Hugging Face, a major AI platform and model repository, has prompted security leaders to reconsider how they manage access…
Security Hardening Assessment: Prepare for AI Transformation Without Increasing Risk
As organizations accelerate AI adoption, AI introduces new security considerations, but it can also amplify existing weaknesses such as excessive…
Judge Rules Pentagon’s Anthropic Measures Illegal
A federal judge has determined that the Pentagon acted illegally when it designated artificial intelligence company Anthropic as a supply chain security…
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website…
IT Security News Hourly Summary 2026-08-31 15h : 12 posts
12 posts published in the last hour 12:32China-linked Fire Ant Hides Inside Trusted Infrastructure 12:31AWS Console Private Access can block sign-ins to personal accounts 12:31Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities 12:31What the Hugging Face Incident Teaches Security…
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks.…
AWS Console Private Access can block sign-ins to personal accounts
The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28…
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut…
What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
Security teams must treat autonomous agents as highly privileged identities.
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the…
OpenClaw 2.0 Released With Enhanced AI Agent Security and Credential Protection
OpenClaw has launched version 2.0, offering a major overhaul of its AI-agent platform. This update emphasizes streamlined deployment, a rebuilt browser…
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant…
Anthropic Warns Claude Users of Infostealer Malware Infections
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new…
ShinyHunters claims it stole 284 million patient records from McKesson
Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S.…
Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. “The…
IT Security News Hourly Summary 2026-08-31 14h : 8 posts
8 posts published in the last hour 11:31Hackers Use Ethereum Blockchain to Steal Credit Card Data From Online Shoppers 11:31Microsoft Confirms False “Defender Antivirus Turned Off” Alerts Spreading Across Windows Devices 11:31Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs 11:31New…
Hackers Use Ethereum Blockchain to Steal Credit Card Data From Online Shoppers
Online shoppers can have their card details stolen without ever leaving a legitimate store. A tracked Magecart campaign plants malicious checkout code on…