A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a…
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant…
IT Security News Hourly Summary 2026-09-05 11h : 4 posts
4 posts published in the last hour 08:0212-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers 08:02Global public-private operation disrupts Sality botnet active for two decades 08:02Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities…
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and…
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data…
CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each
Used-car platform CARS24 has alleged that confidential information belonging to approximately 3,100 customers was stolen and supplied to a rival business…
Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours
A threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root…
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory…
Defenders call out OpenAI defense pledge, Astra release timing
OpenAI has pledged $1 billion to support frontline defenders just days after calling for a collective surge in cyberdefense. Yet that pledge arrived on…
Surviving and thriving in the AI Vulnpocalypse
Katie Moussouris on AI’s Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David…
numbat – AI agent observability, (Fri, Sep 4th)
​​​​​​​
Why Vulnerability Management Must Move Beyond CVSS
Learn why vulnerability management must move beyond CVSS to prioritize real risk using exploitability, asset context, attack paths, and AI-driven analysis.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S.…
Defenders call out timing of OpenAI defense pledge, Astra release
OpenAI has pledged $1 billion to support frontline defenders just days after calling for a collective surge in cyberdefense. Yet that pledge arrived on…
Cyber Resilience Starts With a Unified Recovery Strategy
Learn why cyber resilience requires a unified recovery strategy that restores data, configurations, identities, cloud systems, and critical dependencies.
IT Security News Hourly Summary 2026-09-05 00h : 11 posts
11 posts published in the last hour 21:55IT Security News Daily Summary 2026-09-04 21:31Fable 5.1 released, USPS “untested” IT, Exchange hijack vulnerability 21:31Friday Squid Blogging: Squid on a Stick at the New York State Fair 21:31Attackers Exploit Critical Switchvox Flaw…
IT Security News Daily Summary 2026-09-04
168 posts published today 21:31Fable 5.1 released, USPS “untested” IT, Exchange hijack vulnerability 21:31Friday Squid Blogging: Squid on a Stick at the New York State Fair 21:31Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials 21:31The Department of…
Fable 5.1 released, USPS “untested” IT, Exchange hijack vulnerability
Anthropic announces safety changes and new models USPS installs “untested” IT systems for mail-in ballots Thousands of Exchange servers vulnerable to…
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote…
The Department of Know: Astra launches, CISA cuts programs, McKesson breached
Read the full stories at CISOSeries.com This week’s Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick , director,…
Attack Surface Reduction Is the Only Scalable Defense Strategy Left
Learn how attack surface reduction helps organizations eliminate unnecessary exposure, reduce security noise, and strengthen defenses through automation.