IT Security News: today roundup N-able patched a critical N-central zero-day vulnerability after attackers created unrecognized user accounts on compromised systems. A market review evaluated FWaaS providers, highlighting Cloudflare for affordability, Cato Networks for simplicity, and Prisma Access. Palo Alto…
Critical ArangoDB Flaws Allow Authentication Bypass and Remote Code Execution as Root
Two critical flaws in ArangoDB can let an outsider bypass login controls, read or alter database data, and then gain root-level code execution on the…
Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks
Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code…
CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild
The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able’s N-central remote monitoring and management platform to…
New FBI cyber strategy promises increase in adversary disruptions
The document also focuses on helping victims, reflecting the bureau’s attempt to encourage more companies to share information with it.
Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Android banking fraud is entering a deceptive phase. Attackers are using malware that copies targeted banking apps into a concealed Android work profile,…
CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms
Microsoft Teams for Android Vulnerability Exposes Sensitive Information
Microsoft has released a security update for CVE-2026-65812, a vulnerability in Microsoft Teams for Android that could allow an authorized attacker to…
IT Security News Hourly Summary 2026-09-09 18h : 19 posts
19 posts published in the last hour 15:32Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide 15:32NIS2 Compliance in the AI Age: Why Traditional Cybersecurity Isn’t Enough 15:32‘Gambling with our lives’: Anthropic researcher quits,…
Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide
A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit…
NIS2 Compliance in the AI Age: Why Traditional Cybersecurity Isn’t Enough
Discover why achieving NIS2 compliance is more challenging in the AI age, the four key challenges organizations face, and why segmentation is essential.
‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
Anthropic researcher Jacob Coxon resigned over AI extinction fears, calling for pacing agreements between labs.
DoppelCart Fake-Shop Network Found Operating Across 119,000 Domains
A newly published investigation has uncovered what may be the largest documented fake-shop network to date, spanning roughly 119,000 domains and dubbed…
MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7 million users to…
More than 100,000 fake stores are out to steal your card details
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs
Software developers are being targeted with fake job offers that turn routine coding tests into a path for remote access malware. The campaign uses…
LG Targets Residential Proxies in New Smart TV Security Move
Several webOS apps using residential proxy technology are being suspended by LG Electronics for routing third-party traffic through smart TVs. The company…
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns…
One WeChat Call Was Enough to Hijack Accounts Across iPhone and Android
A new wave of WeChat vulnerability can turn an incoming voice call into a zero-click account takeover, enabling a compromised account to target another…
Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls
Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company…
Why hostile state cyber activity is now a day-to-day business risk
Christopher Clark, Cyber Security Incident Response Team Director, Thrive Geopolitical escalation can become a cyber security problem for businesses far…
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to…
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
UK Law To Ban Nudity On Children’s Devices
Government promises legislation forcing Apple, Google to ban taking and sending of nude images on devices used by children