IT Security News: today roundup CISA and NIST published technical guidance to prevent token theft. Europol and ELA partnered to combat European labour exploitation. Microsoft adopted AI student privacy guardrails with teachers' unions. Experts urge continuous monitoring over periodic security…
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being…
Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation.
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
Two Hugging Face accounts reveal that OpenAI’s agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory…
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch.…
12 Best Kubernetes Security Tools Compared (2026): Features & Pricing
Quick Answer: Kubernetes security quotes hinge on the node-vs-cluster-vs-developer unit choice, and the OSS floor (Kubescape, Falco, Calico, NeuVector,…
Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
12 Best Container Security Tools Compared (2026): Features & Pricing
Quick Answer: Container security has the deepest free floor in the industry Trivy, Falco, and SUSE NeuVector (fully open-sourced) cover scan, runtime, and…
One runaway AI agent racked up a $50,000 cloud bill
Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud…
Acronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges
Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel & WHM…
IT Security News Hourly Summary 2026-09-16 12h : 15 posts
15 posts published in the last hour 09:32Meta Plans Smart Glasses Without Camera, Amid Complaints 09:32Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists 09:3236,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check…
Meta Plans Smart Glasses Without Camera, Amid Complaints
Facebook parent Meta reportedly preparing to launch smart glasses without camera, amid rising complaints around tech’s intrusiveness
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through…
36,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring.
Public PoC Released for Apache Superset SQL Injection Vulnerability
A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset versions before 6.0.0. The…
Apache Superset SQL Injection Flaw Gets Public PoC Exploit
A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset installations running…
Acronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wild
Acronis has released security updates for its Backup plugin for cPanel & WHM and Backup extension for Plesk after detecting limited, targeted exploitation…
Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session…
China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites.…
Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Iranian state-linked hackers are using fake MRI scan results to infect selected people with CHOSEN BRICK, a Windows spyware family built for long-term…
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data.
US Official ‘Suspicious’ Of Anthropic Call For Antitrust Exemption
FTC chair Andrew Ferguson says AI companies looking to bring in regulations that ‘insulate their incumbency from challenge’
AI helps scammers build convincing antivirus renewal pages
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.
