IT Security News: today roundup CrowdStrike added AI remediation and app visibility to Falcon Cloud Security. IBM and Red Hat patched over 400 Java library vulnerabilities. Wordfence highlighted the urgency of replacing vulnerable public key encryption. Microsoft will block MSIX…
AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI
AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI in Cybersecurity Host David Shipley interviews Dave Lewis of 1Password about…
CVE-2026-21589: Critical Pre-Authentication File Read Affects Atlassian Data Center Products
Atlassian has released an out-of-band security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting a broad range of its…
IT Security News Hourly Summary 2026-10-09 03h : 3 posts
3 posts published in the last hour 00:01FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins 00:01Citizen Lab Slams Trump Administration, ‘Techno-Fascist’ Executives 00:00IT Security News Hourly Summary 2026-10-09 02h : 6 posts
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out…
Citizen Lab Slams Trump Administration, ‘Techno-Fascist’ Executives
The Citizen Lab’s Ron Deibert warns the US government is pushing for pervasive surveillance and says certain technology executives are all too happy to…
IT Security News Hourly Summary 2026-10-09 02h : 6 posts
6 posts published in the last hour 23:31Building your AI vulnerability harness, Part 1 23:31Critical Atlassian File Access Flaw Draws Attacks Across Eight Products 23:31FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor 23:01Texas AG Says Oracle Health’s 2025…
Building your AI vulnerability harness, Part 1
Vulnerability scanners produce findings faster than manual triage can process them. Your developers ship more code with more dependencies, and the volume…
Critical Atlassian File Access Flaw Draws Attacks Across Eight Products
CVE-2026-21589 is being exploited after a public PoC, putting self-hosted Jira, Confluence, Bitbucket and other Atlassian products at risk.
FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor
The FBI and DOJ seized domains and disrupted scanning and spear-phishing tools used by Flax Typhoon, a China-linked…
Texas AG Says Oracle Health’s 2025 Breach Affected 20M Individuals
A Texas AG filing says Oracle Health’s 2025 breach affected nearly 20 million people, while major questions about access and attribution remain.
Google Chrome Update Fixes 247 Security Flaws, Including 4 Critical Bugs
Google Chrome 155 fixes 247 security vulnerabilities, including four Critical use-after-free flaws. See what security teams should do now.
IT Security News Hourly Summary 2026-10-09 01h : 12 posts
12 posts published in the last hour 22:31Configuring your AI vulnerability harness, Part 2: The steering file 22:31New Report Finds 43% of Security Pros Still Use Passwords 22:31Post-quantum authentication: Why organizations should start testing certificate ecosystems now 22:31Anthropic Gives Vetted…
Configuring your AI vulnerability harness, Part 2: The steering file
This post shows you how to configure an AI model to perform structured, evidence-based vulnerability triage with the consistency of a seasoned security…
New Report Finds 43% of Security Pros Still Use Passwords
The 2026 Global State of Authentication report finds 43% of security pros still use passwords at work despite passkey awareness and rising AI phishing…
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS Pilot Program helps advance future readiness.
Anthropic Gives Vetted Defenders Fewer Claude Guardrails
Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.
Google’s October Android Update Patches 7 Critical Security Vulnerabilities
Google’s October Android security update patches seven critical vulnerabilities, including flaws that do not require user interaction.
EU law enforcement chiefs gather to discuss new challenges in EU security
The Convention was opened by Jürgen Ebner, Europol’s Acting Executive Director, and Justin Kelly, Commissioner of the Irish An Garda Síochána.Jürgen…
Leader of 764 pleads guilty, faces up to 30 years in prison
Prasan Nepal ran the nihilistic violent extremist network for almost four years and played a crucial role facilitating the grooming, manipulation and…
US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide
Infecting devices from 2021 until the FBI stepped in
Hackers hijack Google domains after breaching ccTLD registries
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana,…
Anthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source software
The critical infrastructure defense program will seek to pair Claude models, Anthropic engineers and threat research with the expertise of cybersecurity…
FBI disrupts Chinese hacking tools used to breach critical infrastructure
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used…
IT Security News Hourly Summary 2026-10-09 00h : 16 posts
16 posts published in the last hour 21:56IT Security News Roundup: 2026-10-08 21:55IT Security News Daily Summary 2026-10-08 21:31New in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced Remediation 21:31IBM and Red Hat Fix 400+ Security Vulnerabilities in Widely Used…
