IT Security News: today roundup CISA listed actively exploited Check Point, Arista, and F5 vulnerabilities. Attackers target Rust developers with malicious job interview invitations. Extortion group ShinyHunters hacked rival gang Clop's dark web site. US and China discussed mutual notifications…
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts,…
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik…
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
‘SalesBleed’ security flaws ‘lead to very unexpected consequences’
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher,…
Rogue AI agents put trusted access under scrutiny
Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently…
Researchers used Claude to hack OpenAI
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked…
IT Security News Hourly Summary 2026-09-24 21h : 10 posts
10 posts published in the last hour 18:31A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight 18:31North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests 18:31Texas utility CenterPoint confirms breach after attacker…
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something…
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure.
Texas utility CenterPoint confirms breach after attacker leaks customer data
Texas utility CenterPoint Energy has confirmed a data breach after a threat actor published customer information online and claimed to have stolen around…
ChatGPT and Cybersecurity: Risks, Uses, and Misuses
By HOC Team | Updated: October 2026 | Read time: ~20 min When ChatGPT launched in November 2022,…
Trust and the enticing consultancy offer
In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris…
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Gemini crosses the line in cybersecurity test
Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets…
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical Orkes Conductor flaw is under active attack, with 6,696 exploit attempts blocked in a week. Defenders should upgrade to version 3.30.2 or later.
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to…
IT Security News Hourly Summary 2026-09-24 20h : 15 posts
15 posts published in the last hour 17:32The Closed Quorum: Inside the first reported autonomous AI C2 implant 17:32UkeySoft Spotify Music Converter Review: Download Spotify to MP3 with Free Account(2026) 17:31LimeLeads – 17,838,396 breached accounts 17:31Developers Complain After Z.ai’s ZCode…
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in…
UkeySoft Spotify Music Converter Review: Download Spotify to MP3 with Free Account(2026)
If you are looking for a professional Spotify to MP3 downloader to save Spotify songs… UkeySoft Spotify Music Converter Review: Download Spotify to MP3…
LimeLeads – 17,838,396 breached accounts
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The…
Developers Complain After Z.ai’s ZCode Sends Data To Cloud
Developers say ZCode sent details on their coding projects to external cloud server without their knowledge or consent
Microsoft Password Reset Portal Can Leak Account Verification Details
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user…
Introducing CAIRN: Frontier tracking for AI-integrated malware
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
