IT Security News: today roundup Attackers actively exploit a critical RCE flaw in Orkes Conductor. Researchers used Claude Opus 5 to infiltrate OpenAI's internal repositories. Malware analysis tracked a ClickFix campaign delivering MeshAgent tools. CISA added actively exploited Linux kernel…
Top 10 Best Identity & Access Management (IAM) Solutions in 2026
Quick Answer: Microsoft Entra ID wins on bundled value inside M365 estates; Okta wins on neutrality and app-catalog breadth; Ping Identity (which now…
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
A breach at image-sharing service Gyazo on September 11 affected over 23 million customers
Top 10 Best Privileged Access Management (PAM) Solutions in 2026
Quick Answer: CyberArk remains the enterprise PAM benchmark; BeyondTrust and Delinea complete the leader trio; ManageEngine PAM360 wins value; HashiCorp…
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection
Hackers are using a layered Windows malware chain to run an XMRig cryptocurrency miner while keeping its key parts out of sight. The operation hides code…
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning…
OpenAI Codex Sandbox Flaws Let Malicious Repositories Execute Commands on Host Systems
OpenAI Codex recently faced two significant security vulnerabilities that allowed malicious repositories to potentially execute commands on a developer’s…
Siemba brings continuous IDOR testing to production APIs
Siemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST,…
Hackers Can Manipulate Web Cache Keys to Access Restricted Data and Poison Websites
A web cache poisoning technique called cache key injection could let attackers access restricted data, disrupt websites, or poison cached pages with…
IT Security News Hourly Summary 2026-09-21 12h : 16 posts
16 posts published in the last hour 09:32Top 10 Best Multi-Factor Authentication (MFA) Solutions in 2026 [Ranked & Scored] 09:32Hackers exploit Gyazo server flaw to steal 23.6 million user records 09:32SIRIUS SPoC network meets as EU enters new era for…
Top 10 Best Multi-Factor Authentication (MFA) Solutions in 2026 [Ranked & Scored]
Push-bombing, real-time phishing kits, and helpdesk social engineering broke “any MFA is fine.” The 2026 question is which MFA survives an attacker who…
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in…
SIRIUS SPoC network meets as EU enters new era for electronic evidence
The 7th SIRIUS Single Point of Contact (SPoC) Network Meeting, organised by Europol’s EU Internet Referral Unit (EU IRU) together with the German Federal…
More CVEs than ever. The same old ones keep getting exploited.
Vulnerability volume is climbing fast. The exploited ones are old and already patchable.
Top 10 Best Single Sign-On (SSO) Solutions in 2026
Quick Answer: Microsoft Entra ID is the bundled default for M365 estates; Okta leads neutral catalog breadth; Ping Identity owns complex enterprise;…
Revolut Customers Targeted with New Wave of Phishing Attacks
Following a major data breach, Revolut customers are being sent convincing phishing messages
North Korean WaterPlum Hackers Infect 30,000 PCs via Fake Job Interviews, Steal $10.7M Crypto
North Korean-linked WaterPlum operators have turned job hunting into a route for theft. By posing as recruiters, they persuaded software developers to run…
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into…
New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN
A newly identified Android banking Trojan called RatHat uses phone features for account theft. The malware can guide itself through an infected device,…
Security’s 30-year habit: layering around the problem
The nurse isn’t careless. Every safe path is slower than Outlook.
Top 10 Best Identity Governance & Administration (IGA) Tools in 2026
Quick Answer: SailPoint remains the IGA benchmark with AI-driven certifications; Saviynt leads cloud-native converged governance; Microsoft Entra ID…
The Target Is No Longer the Model. It’s the Agent.
AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI…
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized…
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has…
