Red Hat has disclosed CVE-2026-66794, a high-severity Server-Side Request Forgery vulnerability affecting the cluster-proxy-addon component in…
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.
OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities
OpenAI has temporarily slowed the development of its latest frontier AI models after initial testing suggested that its upcoming Astra system may meet the…
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated…
Europol and Frontex strengthen cooperation with new Working Arrangement
The new arrangement replaces the agreement signed in 2015 and reflects the significantly expanded mandates that both agencies have received in recent…
Hackers Hide Malware Code Inside English Words to Infect Windows Users
A new Windows malware campaign is hiding malicious code inside ordinary English words, making the payload look less suspicious during analysis. The…
MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.
OpenAI Pauses AI Training Amid Concerns of New Model Potentially Discovering 0-Day Flaws
OpenAI has temporarily slowed frontier AI training after internal testing suggested that its upcoming Astra model may reach a critical cybersecurity…
Migrant smuggling network using rental cars dismantled across the Balkans
Led by the Greek authorities and supported by Europol, the investigation targeted a criminal network composed mainly of Syrian and Egyptian nationals…
Hackers Are Turning Claude, ChatGPT and Copilot Into Bait for Real Malware
Cybercriminals are increasingly using trusted artificial intelligence names as a shortcut to infect users with malware. Fake download pages, browser…
Using Microsoft Graph and Powershell to Mine for Information – Stale Accounts and Licenses, (Thu, Aug 20th)
Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s…
The Oracle of Delphi Will Steal Your Credentials
Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced…
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.
Season 4 of The Europol Podcast available now
The Europol Podcast is the official podcast of the EU’s agency for law enforcement cooperation. This season, we spoke to our Europol experts on the…
9 million images of people’s faces exposed by reverse lookup service
A researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated…
Europol-led action against nihilistic violent extremist network “The Com”
An estimated 4 340 URLs related to nihilistic violent extremism were referred during the initiative organised by Europol’s EU Internet Referral Unit – EU…
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Cisco has issued security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to access…
French-Spanish operation targets hazardous waste trafficking network: four arrested
The investigation focused on an alleged cross-border network that illegally transported tonnes of demolition waste from France to Spain, posing serious…
IT Security News Hourly Summary 2026-08-20 14h : 14 posts
14 posts published in the last hour 11:31Five arrests for smuggling migrants across the Bulgarian-Serbian green border 11:31AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking 11:31AWS limits AI agents’ data access, even when manipulated 11:31NASA AIT-GUI Flaws…
Five arrests for smuggling migrants across the Bulgarian-Serbian green border
The action day led to:5 arrests (1 High Value Target, 2 police officers and 2 associates)5 locations searched;Seizures include: 3 vehicles used for…
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
Atalanta’s Argo product is now being used to prove the resilience of Viasat’s satellite communications network.
AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and…
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL’s open-source AMMOS Instrument…