IT Security News: today roundup Manifold Security found AI agent placeholder domains redirecting to scams. Red Hat aligned RHEL 10 automation with DISA security baselines. Lunex malware exploits AMD drivers to steal user browser credentials. The US and China created…
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit…
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively…
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes…
Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world…
IT Security News Daily Summary 2026-09-26
51 posts published today 20:00IT Security News Hourly Summary 2026-09-26 22h : 4 posts 19:31Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams 19:31Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2 19:01Lunex Stealer…
IT Security News Hourly Summary 2026-09-26 22h : 4 posts
4 posts published in the last hour 19:31Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams 19:31Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2 19:01Lunex Stealer Abuses AMD Driver to Disable Security Monitoring…
Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
Manifold Security found placeholder domains cited in 359,000 GitHub files and 349 AI agent skills serving cloaked scam…
Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2
For the U.S. Department of Defense (DoD) and its contractors, security has to hold up against a published baseline—not a general claim that systems are…
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider…
IT Security News Hourly Summary 2026-09-26 21h : 3 posts
3 posts published in the last hour 18:31China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks 18:02Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection 18:01F-Droid 2.0 Released After 10 years With…
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.
Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
A locally hosted, uncensored artificial intelligence model modified a Windows credential-dumping utility until it evaded two Endpoint Detection and…
F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery
F-Droid has released version 2.0 of its official Android app, delivering its largest client update in a decade. The open-source Android app repository…
AI Agents Can Be Secured. We Can Do It.
Learn of the benefits of safely securing AI agents.
IT Security News Hourly Summary 2026-09-26 19h : 3 posts
3 posts published in the last hour 16:31SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted 16:31OpenAI Agents Accessed US Government Websites Without Authorization 16:02Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
SolarWinds has issued security updates for two critical vulnerabilities in its Observability Self-Hosted product that could enable remote code execution…
OpenAI Agents Accessed US Government Websites Without Authorization
OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed…
Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
Cloudflare has patched a vulnerability in its Containers product that could have allowed a paying customer to pull residual data out of disk storage…
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews…
IT Security News Hourly Summary 2026-09-26 17h : 5 posts
5 posts published in the last hour 14:31Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells 14:31Zero Trust for AI Agents Starts With Fixing Zero Visibility 14:02Astrana Health Data Breach Exposes Private and Confidential Information 14:02ShinyHunters Bypass…
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors…
Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how…
Astrana Health Data Breach Exposes Private and Confidential Information
In a cybersecurity incident, Astrana Health disclosed, attackers gained access to company servers and obtained confidential and private information. A…
