A year ago we wrote that we’d put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay…
CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps
CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a lot of funding. This is…
When the Algorithm Fires You: Uber Faces €825M Fine
Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The…
IT Security News Hourly Summary 2026-08-25 20h : 8 posts
8 posts published in the last hour 17:02AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge 17:02Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as…
AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a $140 million funding round led by Apax Digital Funds, with…
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch…
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text,…
Hackers Shift From Disrupting to Destroying Critical Infrastructure
Cyberattacks on operational technology (OT) systems have shifted from data theft and ransom demands toward outright physical destruction, according to…
SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route for malware delivery. The campaign relies on…
ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps
ToxicPanda 2.0 now targets 349 financial apps across 16 countries while abusing VPN, Accessibility and Android debugging features for deeper control.
WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into the messaging app, marking one of the largest passwordless…
IT Security News Hourly Summary 2026-08-25 19h : 13 posts
13 posts published in the last hour 16:31You could’ve applied all 1,449 Oracle patches and still been hit by this attack 16:31Salesforce’s Headless 360 Pushes Enterprise Software Beyond the Browser 16:31Linux Foundation to Govern TRACE, an Open Standard for AI…
You could’ve applied all 1,449 Oracle patches and still been hit by this attack
Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert
Salesforce’s Headless 360 Pushes Enterprise Software Beyond the Browser
Salesforce is preparing for a future in which employees may no longer need to open Salesforce to use it. At TDX 2026, CEO Marc Benioff described the shift…
Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation.
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
Inside Astaroth’s New Spambot Component
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Inside Astaroth’s New Spambot Component
Suspected Iran-Linked Cyberattack Shuts UK Power Generator for Four Days
A suspected Iran-linked cyberattack reportedly forced a small UK power generator offline for four days, raising concerns about infrastructure resilience.
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation.
Flock Cameras Spark Debate Over Surveillance and Civil Liberties
With Flock Safety operating one of the largest networks of automatic license plate readers (ALPRs), automatic license plate readers (ALPRs) are becoming…
That fake Grand Theft Auto VI demo is actually just malware
Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.
Road to OSCE3: Episodio 1 – OSEP
¡Hola a todos! Con este post da comienzo una serie de 3 posts donde hablaré de las certificaciones que forman OSCE3 y de cómo yo me las he preparado. ¿Qué…
CISA orders agencies to fix exploited Zimbra vulnerability
The collaboration software’s developer took almost a full month to patch the flaw after disclosing it.
Knowing what not to attack
Most talk about offensive security agents is about power. Can it find the bug? Can it chain the exploit? Can it own the box? That’s the easy part. Wiring…