IT Security News: today roundup CISA added actively exploited SharePoint and MikroTik flaws to KEV. A Tennessee science center hosted family squid dissection events. Researchers created 5G-Shark to intercept cellular signals without jamming. Chinese hackers exploited Chrome and Windows zero-days…
Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
A locally hosted, uncensored artificial intelligence model modified a Windows credential-dumping utility until it evaded two Endpoint Detection and…
F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery
F-Droid has released version 2.0 of its official Android app, delivering its largest client update in a decade. The open-source Android app repository…
AI Agents Can Be Secured. We Can Do It.
Learn of the benefits of safely securing AI agents.
IT Security News Hourly Summary 2026-09-26 19h : 3 posts
3 posts published in the last hour 16:31SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted 16:31OpenAI Agents Accessed US Government Websites Without Authorization 16:02Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
SolarWinds has issued security updates for two critical vulnerabilities in its Observability Self-Hosted product that could enable remote code execution…
OpenAI Agents Accessed US Government Websites Without Authorization
OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed…
Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
Cloudflare has patched a vulnerability in its Containers product that could have allowed a paying customer to pull residual data out of disk storage…
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews…
IT Security News Hourly Summary 2026-09-26 17h : 5 posts
5 posts published in the last hour 14:31Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells 14:31Zero Trust for AI Agents Starts With Fixing Zero Visibility 14:02Astrana Health Data Breach Exposes Private and Confidential Information 14:02ShinyHunters Bypass…
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors…
Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how…
Astrana Health Data Breach Exposes Private and Confidential Information
In a cybersecurity incident, Astrana Health disclosed, attackers gained access to company servers and obtained confidential and private information. A…
ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread the SIDEEYE backdoor.
CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting WSO2 and Adobe Commerce to its Known…
IT Security News Hourly Summary 2026-09-26 15h : 11 posts
11 posts published in the last hour 12:31Drug trafficking investigation leads to some of the world’s biggest underground bankers 12:31Old-School Credit Card Scams Are Far From Dead 12:31Thousands of horses caught up in Europe-wide trafficking scheme 12:03OpenAI Says Its Models…
Drug trafficking investigation leads to some of the world’s biggest underground bankers
The investigation, led by the Spanish National Police (Policía Nacional) and supported by Europol, has resulted in the arrest of 21 suspects for offences…
Old-School Credit Card Scams Are Far From Dead
In an era of increasingly sophisticated AI-fueled scams, a retro threat may be lurking in your mailbox.
Thousands of horses caught up in Europe-wide trafficking scheme
Europol has supported a major operation against a criminal network suspected of trafficking horses across Europe using falsified documents and manipulated…
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”
OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted
OpenAI’s autonomous AI agents attempted to hack four government, university, and public-data systems while carrying out routine information-gathering…
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received…
Is that vibe coded app safe? 5 checks before you download
As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated…
