IT Security News: today roundup Ransomware hit Japanese railway operator Keio Corporation, disrupting business systems. OpenAI launched new AI agents named Dots at its developer event. The FBI warned cybercrime group ShinyHunters it can locate them. Veracode reported a 20%…
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern…
Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux
Google released a Chrome Stable update fixing 32 security vulnerabilities across Windows, macOS, and Linux, including one critical and multiple…
Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells
Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy…
Ping Command Options & Syntax: Network Admin Guide
By HOC Team | Updated: September 2026 Read time: ~15 min The ping command is the undisputed…
Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations. The campaign…
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
It’s 2 am. Do you know what your teen is doing?
Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS
Cloudflare is building a certificate authority to make post-quantum website authentication practical without burdening TLS connections with oversized…
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to…
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of…
IT Security News Hourly Summary 2026-09-30 20h : 4 posts
4 posts published in the last hour 17:01Pentagon Confirms Breached 3 Million DMDC Personnel Database 17:01Mass exploitation of Citrix NetScaler: What we currently know 17:01iPhone Security Warning: Apple Says iOS 26 Flaw May Have Been Exploited 17:00IT Security News Hourly…
Pentagon Confirms Breached 3 Million DMDC Personnel Database
HOC Shorts The Pentagon confirmed a major data breach involving the Defense Manpower Data Center (DMDC), exposing sensitive…
Mass exploitation of Citrix NetScaler: What we currently know
Suspected state-linked actors targeted critical vulnerabilities in the widely used platform, causing widespread disruption across Europe and North America.
iPhone Security Warning: Apple Says iOS 26 Flaw May Have Been Exploited
Apple patched an iPhone flaw that may have been exploited in targeted attacks. Here’s what iOS 26 users need to know and how to update.
IT Security News Hourly Summary 2026-09-30 19h : 7 posts
7 posts published in the last hour 16:31Two new NetScaler zero-days exploited, ShinyHunters steals FBI medical files, OpenAI Australia hack disputed 16:31Meta disputes claim that Muse read a user’s private messages without permission 16:31ISC Stormcast For Monday, September 28th, 2026…
Two new NetScaler zero-days exploited, ShinyHunters steals FBI medical files, OpenAI Australia hack disputed
Citrix NetScaler Zero-Days Exploited, Kiteworks Shutdown Warning, ShinyHunters WAF Bypass, FBI Medical Files Leak, OpenAI Medicare “Hack” Reframed Citrix…
Meta disputes claim that Muse read a user’s private messages without permission
Meta says its Muse AI agent cannot access a user’s Messages without explicit permission, disputing a journalist’s account that the agent read his private…
ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112,…
101 Malicious npm Packages Secretly Enroll Developers into WhatsApp Spam Channels
Researchers at OX Security have flagged 101 npm packages that silently subscribe developers to WhatsApp spam channels the moment they are installed. The…
Hackers steal protective order and foster care records from Arizona courts
Attackers copied sensitive court records, including more than 150,000 foster care reports, raising privacy and safety concerns for those Arizonans…
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large…
IT Security News Hourly Summary 2026-09-30 18h : 11 posts
11 posts published in the last hour 15:3184% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain 15:31Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures 15:31National cyber director defends private-sector hacking program, urges focus on…
84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain
A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in…
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that…
National cyber director defends private-sector hacking program, urges focus on security basics
Letting businesses help the government deter cybercrime will benefit all Americans, Sean Cairncross said.
