Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says…
Armored Likho expands its cyber-espionage toolkit
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram…
AI-Assisted Bug Discovery Still Depends on Human Validation
With artificial intelligence, security researchers can identify software vulnerabilities much faster by scanning code, generating payloads, mapping attack…
Post-Hugging Face Reflections: The Agentic Attacker Is Already Here
Bill Robbins, CEO of Menlo Security An AI agent broke out of the sandbox built to contain it and put itself on the open internet. Then it attacked another…
IT Security News Hourly Summary 2026-08-15 19h : 6 posts
6 posts published in the last hour 16:31Apple Warns of Supply Crunch as Demand Surges 16:31Iran-Linked Hackers Suspected in Cyberattacks Targeting Minnesota Water Systems 16:31Russian Hackers Use Exchange Zero-Day in Email Attacks 16:31Trump Memo Signals New U.S. Push to Disrupt…
Apple Warns of Supply Crunch as Demand Surges
Apple’s issue is a supply crunch: strong demand for iPhones and Macs is outpacing the company’s ability to secure key components, especially advanced…
Iran-Linked Hackers Suspected in Cyberattacks Targeting Minnesota Water Systems
Several water systems in Minnesota were under attack from cyber intruders over the weekend. Investigators believe the attacks were launched from an…
Russian Hackers Use Exchange Zero-Day in Email Attacks
Russia-aligned cyberespionage group Laundry Bear, also tracked as Void Blizzard and TA488, is exploiting a Microsoft Exchange Outlook Web Access (OWA)…
Trump Memo Signals New U.S. Push to Disrupt Foreign Cybercrime Groups
The memo from the White House signed by President Donald Trump will increase the role of cybersecurity companies in fighting foreign criminal…
How to tell if your AI platforms’ accounts have been hacked
A guide on how to check if hackers have broken into your accounts on the most popular AI platforms.
GeoServer Zero Day Being Probed While No Patch Available
A newly found GeoServer zero-day is already receiving active exploitation efforts, while there is no patch ready yet. Firms using the open-source…
IT Security News Hourly Summary 2026-08-15 17h : 5 posts
5 posts published in the last hour 14:31How To Prevent The Scaling Of Identity Fraud In Online Gaming 14:31Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC 14:31CISA Warns of Critical Flaw in Johnson Controls Metasys Systems…
How To Prevent The Scaling Of Identity Fraud In Online Gaming
The online gaming industry has exploded, attracting not only millions of legitimate players but also sophisticated fraudsters who are looking to exploit…
Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC
Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security…
CISA Warns of Critical Flaw in Johnson Controls Metasys Systems
Critical Flaw Disclosed in Building Automation System A serious vulnerability in Johnson Controls’ Metasys building automation technology was reported in…
Shell Investigating Data Breach Following Cl0p Ransomware Group Claim
Multinational energy giant Shell has launched an active investigation after the notorious Cl0p ransomware syndicate claimed responsibility for…
How AI Helps Defenders Keep Up and Where It Still Falls Short
Security teams today are more capable than ever, yet they are still falling behind. Organizations have invested heavily in tools designed to stop…
UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON
UK eyes AI gene-synthesis guardrails DeadLock puts ransomware on the blockchain An evil twin flies home from DEF CON Episode show notes:…
IT Security News Hourly Summary 2026-08-15 14h : 4 posts
4 posts published in the last hour 11:31Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication 11:02ChainDrop worm crawls into npm supply chain, evades standard defenses 11:01Critical macOS Screen Sharing Bug (CVE-2026-65400) Exploitation to Install…
Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication
Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in…
ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
Critical macOS Screen Sharing Bug (CVE-2026-65400) Exploitation to Install Monero Miners
Cybersecurity agencies, including the Netherlands National Cyber Security Centre (NCSC-NL), have issued urgent warnings regarding active macOS screen…
IT Security News Hourly Summary 2026-08-15 13h : 3 posts
3 posts published in the last hour 10:31Attackers Exploit SharePoint Authentication Bypass After Public PoC Release 10:01Passwords stored in public Google Doc then showed up in search results 10:00IT Security News Hourly Summary 2026-08-15 12h : 3 posts
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The…