IT Security News: today roundup Five major security awareness platforms were evaluated for personalization capabilities. Citrix confirmed active zero-day exploitation of two critical NetScaler flaws. Emergency Citrix updates patch two actively exploited NetScaler RCE zero-days. Kiteworks warned clients to shut…
IT Security News Hourly Summary 2026-09-28 18h : 21 posts
21 posts published in the last hour 15:32Call for Presentations Open for 2026 CISO Forum Virtual Summit 15:32New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS 15:32Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation…
Call for Presentations Open for 2026 CISO Forum Virtual Summit
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address…
New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS
A cross-platform side-channel attack that abuses file-notification services to monitor user activity on Linux, Windows and macOS. The technique turns…
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific…
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild.
Anthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny
Anthropic declined an Australian Senate AI hearing as officials investigate an OpenAI agent breach and consider mandatory AI incident reporting.
File Notification APIs in Windows, Linux, and Android Are Leaking What You Do on Your Computer
A research team from Graz University of Technology in Austria has shown that a routine feature built into virtually every major operating system can be…
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI.
Fake Email Thread Tricks AI Summarizer Without Hidden Text
Forcepoint X-Labs has published new research showing that indirect prompt injection against AI email summarizers can work without…
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach
Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets
Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open
A criminal crew linked to Blackhatsect0r and DXQRTXX built an automated system designed to find weaknesses across the internet. Its exposed server…
Singapore Expands AI Cybersecurity After UNC3886 Attacks
Singapore is changing its cybersecurity strategy after a state-sponsored cyber espionage group targeted the country’s four major telecommunications…
OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code on Developer Machines
A critical attack path in OpenCode, an open-source AI coding agent, could let a malicious website execute commands on a developer’s computer. Tracked as…
Supabase Misconfigurations Leave Customer Data Publicly Exposed
A cybersecurity firm UpGuard has found that thousands of databases hosted on Supabase can expose private information to the public internet. According to…
NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
The UK National Cyber Security Center (NCSC) has urged organizations to take immediate action against eight vulnerabilities affecting customer-managed…
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed.
New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence
A new guide featuring the experiences of 16 women working in cyber threat intelligence (CTI) is challenging the idea that professionals need a…
Ex-soldier’s telecom hacking spree earns him 70 months
Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
Cyber Briefing: 2026.09.28
Storm-3168 used compromised Azure credentials to delete more than 100 cloud resources, while Psychedelic Stealer targeted Ukrainian businesses and a DC…
TrustSink Attack Uses Rogue MFA Provider to Steal Microsoft Entra Passwords During Legitimate Logins
TrustSink is a newly disclosed identity attack that turns a trusted MFA step into a password-stealing trap. Rather than sending victims to a clearly fake…
IT Security News Hourly Summary 2026-09-28 17h : 17 posts
17 posts published in the last hour 14:32NVIDIA Launches Open Agent Safety Platform With 100 Industry Partners to Secure Autonomous AI Agents 14:32ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells 14:32James Moore, CultureAI Q&A: AI…
NVIDIA Launches Open Agent Safety Platform With 100 Industry Partners to Secure Autonomous AI Agents
NVIDIA has launched the Open Agent Safety Platform, an open framework designed to secure autonomous AI agents as they gain access to models, tools, code…
ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The…
