Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code…
ConnectSecure helps MSPs automate Microsoft 365 security remediation
ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The…
Letting Agents Hit By AI-Generated Complaints
Most tenants’ complaints now lengthy, legally complex, at times citing legislation inaccurately, say letting agents
LiteLLM Supply Chain Breach: How a 40-Minute Hack Exposed 2,500+ Companies
The 2026 LiteLLM Supply Chain Breach Explained: How a 40-Minute Hack Exposed 2,500+ Companies. A research report by…
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on…
CBTS brings continuous penetration testing to enterprise security
CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations…
AI Token Prices Fall To Annual Low
Average token prices for AI inference fall to low for the year to date, amid release of low-cost Chinese models, increased US efficiency focus
Microsoft Fixes 400 Flaws on August Patch Tuesday
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys,…
OpenAI’s Chief Ethicist Leaves After Less Than A Year
Start-up’s head of ethics reportedly departs company, as it faces scrutiny over safety in development of its models
Crytica’s RDAi detects OT device tampering from within
Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the…
Manus Set To Resume Independent Operations After Meta Split
Chinese-founded agentic AI start-up tells customers to back up data as it prepares to finalise reversal of Meta buyout
Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious…
AI Agent Hacks Gym To Book Spots For User
AI system unexpectedly hacks gym’s reservation system to book user into busy Pilates class, in latest reminder of agentic unpredictability
IT Security News Hourly Summary 2026-08-12 11h : 15 posts
15 posts were published in the last hour 8:31 : Ivanti EPM Update Patches Remotely Exploitable Flaws 8:31 : Inside Astaroth’s New Spambot Component 8:31 : Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely 8:31 : Falcon Cloud Security…
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
Inside Astaroth’s New Spambot Component
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Inside Astaroth’s New Spambot Component
Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation…
Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the…
The Best Network Traffic Analysis (NTA) Tools, Compared and Priced (2026)
Network traffic analysis spans two buying worlds — ops tools with published price lists and security platforms with quote-only enterprise pricing — and…
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept…
Split-second deepfake glitch blows digital certificate fraudster’s cover
Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to…
Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that…