IT Security News: today roundup Microsoft outlined AI-focused security platform updates for Ignite 2026. US businesses maintain climate technology investments despite shifting federal support. Citrix issued patches for two actively exploited zero-day RCE flaws. Malwarebytes published its weekly security news…
‘North Korean’ Attackers Steal $387.5m From Bitget
Exchange Bitget resumes transactions after suspected North Korean attackers carry out biggest single crypto heist so far this year
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in…
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond andrew.gertz@t… Wed, 09/30/2026 – 20:13 Data Security Todd Moore | Global VP of Data…
Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware
Gemini 4 starts with cybersecurity MI5 flags Chinese research funding Custom GPTs steer users into ClickFix attacks Get the show notes here:…
Sydney Data Centre Plan Withdrawn After Protests
Developer Goodman Group pulls plan for 90 MW data centre that it intended to build in Sydney suburb near homes, schools
IT Security News Hourly Summary 2026-10-01 09h : 8 posts
8 posts published in the last hour 06:32ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st) 06:31Hackers Hide Microsoft Defender Exclusions From Admins to Evade Antivirus Scans 06:31Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft 06:31Many expect AI in the…
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing…
Hackers Hide Microsoft Defender Exclusions From Admins to Evade Antivirus Scans
Threat actors are increasingly abusing Microsoft Defender Antivirus exclusions to keep malicious files outside the reach of endpoint scans, and a…
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security…
Many expect AI in the SOC to make entry jobs harder to get
A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase…
Fire That Killed Four Linked To Lithium-Ion Battery
Electrical event caused lithium-ion battery to go into thermal runaway, sparking intense fire that killed mother, three children
Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used…
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively…
IT Security News Hourly Summary 2026-10-01 08h : 8 posts
8 posts published in the last hour 05:32New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers 05:32CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access 05:31Employment scam victims tripled at financial…
New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers
A new Windows malware loader, tracked as 2CLoader, that combines extensive anti-analysis logic, indirect system calls, API tampering, and flexible…
CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access
A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code…
Employment scam victims tripled at financial firms in 21 countries
Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries.…
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to…
AI Agents Expose 13,000+ Developer Screenshots Across 900+ GitHub Repositories
AI coding agents have inadvertently exposed over 13,000 internal developer screenshots in public GitHub repositories. These exposures potentially revealed…
The vulnerabilities AI finds are the ones attackers want
Attackers exploited a flaw found by an AI research agent within four days of its public disclosure, and they are exploiting more vulnerabilities overall,…
FBI’s Operation Blackout Takes Down Overseas Scammers Targeting Americans
The FBI has intensified its global effort to crack down on large-scale scam operations targeting Americans. Director Kash Patel announced that Operation…
IT Security News Hourly Summary 2026-10-01 07h : 4 posts
4 posts published in the last hour 04:31FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers 04:31Google says Gemini 4 Argon can find and patch critical software flaws 04:01Google’s SynthID Bio can watermark AI-designed protein binders without breaking…
FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment.
Google says Gemini 4 Argon can find and patch critical software flaws
Google announced Gemini 4 Argon, its new frontier AI model, and is rolling it out to a set of trusted cyber defenders through its Fairwind Program. Google…
