IT Security News: today roundup Ransomware hit Japanese railway operator Keio Corporation, disrupting business systems. OpenAI launched new AI agents named Dots at its developer event. The FBI warned cybercrime group ShinyHunters it can locate them. Veracode reported a 20%…
Apple Hit By $5.7bn Verdict Over Vibration Patents
US jury finds Apple devices infringe two patents on haptic feedback belonging to Taction Technologies
Unsloth Fixes Arbitrary Code Execution Flaw Triggered by Malicious Hugging Face Models
Unsloth has addressed a critical arbitrary code execution vulnerability in its Studio web interface. This flaw allowed a malicious Hugging Face model…
Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks
A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware. The threat uses…
OWASP Noir: Open-source static analysis tool
OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods,…
SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access…
IT Security News Hourly Summary 2026-09-30 08h : 6 posts
6 posts published in the last hour 05:31OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext 05:31FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader 05:31EU Cyber Resilience Act requirements for containers and Kubernetes 05:31OpenAI Launches Codex Security…
OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext
OpenSSL has announced a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation that could allow a remote peer to read…
FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader
The FBI and Dutch National Police have announced the arrest of a 24-year-old man from Amsterdam who is suspected of playing a major role in the…
EU Cyber Resilience Act requirements for containers and Kubernetes
Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity…
OpenAI Launches Codex Security Cloud for Always-On Application Security Scanning
OpenAI has expanded its Codex platform with Codex Security Cloud, a cloud-hosted application security feature that continuously analyzes GitHub…
In this new SME cybersecurity service, the AI assists and the consultants decide
BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized…
IT Security News Hourly Summary 2026-09-30 07h : 5 posts
5 posts published in the last hour 04:31OpenSSL Fixes High-Severity Flaw That Can Leak Server Memory in Plaintext 04:31Most open critical and high flaws are over 90 days old 04:31Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON…
OpenSSL Fixes High-Severity Flaw That Can Leak Server Memory in Plaintext
OpenSSL has released security updates for a high-severity vulnerability that could expose heap memory as plaintext during Datagram Transport Layer…
Most open critical and high flaws are over 90 days old
Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their…
Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization
Octopus Deploy has disclosed a high-severity vulnerability in Octopus Server that could allow authenticated users to execute arbitrary code on affected…
WSL containers are generally available on Windows
Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls…
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top…
Securing AI agents requires securing the systems around them
Enterprise AI is changing from software that primarily generates information to software that can take action. AI agents can call APIs, invoke tools,…
Post-quantum website certificates from Cloudflare are scheduled for early 2027
Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and…
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
The accord opened the door to future regulation but focused on four voluntary steps for the companies to take.
ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116,…
ShinyHunters Leader Busted
FBI Warns Staff Assume ShinyHunters Stole Everyone’s Data; Clop Dismisses Rival Hack; Kiteworks Restores Service Cybersecurity Today host David Shipley…
Phishing Abuses RMM Tools for Persistent Access
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity
IT Security News Hourly Summary 2026-09-30 01h : 3 posts
3 posts published in the last hour 22:31Dutch ShinyHunters Suspect Investigated for Trying to Arrange 2 Murders 22:01Add one more AI worry to the nightmare scenario: self-replicating prompt injections 22:00IT Security News Hourly Summary 2026-09-30 00h : 4 posts
