IT Security News: today roundup CrowdStrike highlights training strategies to build resilient cybersecurity workforces. AWS launched open-weight AI models on Bedrock in Europe. A popular Twitch extension exposed account tokens for 30,000 users. Automated attackers scanned nearly two million Android…
Buying or selling a second-hand phone? How to protect your personal data
Buying or selling a used phone can be safe – but only if you wipe the old device properly and reset any phone you receive…
Slow is a design principle, not a delay
Two things happened last week, one day apart, and almost nobody connected them. On 11 September, the EU Cyber Resilience Act’s vulnerability reporting…
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST…
IT Security News Hourly Summary 2026-09-18 10h : 8 posts
8 posts published in the last hour 07:31Beware the SparroWock: The backdoor that bites, the commands that catch 07:31Nuclear-style AI safeguards, AI legislation shelved, CISA’s decoy guidance 07:31MIND Secures $72 Million for AI-Powered DLP 07:31AI Cloud Firm Nebius Hikes GPU,…
Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
Nuclear-style AI safeguards, AI legislation shelved, CISA’s decoy guidance
Nuclear-style safeguards proposed for AI risks Key lawmaker suggests action on AI safety legislation will wait until 2027 CISA releases cyber decoy…
MIND Secures $72 Million for AI-Powered DLP
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
AI Cloud Firm Nebius Hikes GPU, CPU Prices
Nebius raises prices for second time in three months, amid sustained demand for training, deployment of AI models
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
German Court Finds Meta Liable For Fraudulent Ads
Frankfurt regional court tells Meta to compensate financial website over fraudulent adverts misusing its imagery
Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated…
IT Security News Hourly Summary 2026-09-18 09h : 7 posts
7 posts published in the last hour 06:31HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th) 06:31Abandoned IoT apps keep sending sensitive data to broken servers 06:31RatHat Android Malware Abuses ADB to Retain Shell Access After…
HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: “QUERY”. The HTTP protocol faced already by changes (HTTP/2, HTTP/2) but it’s…
Abandoned IoT apps keep sending sensitive data to broken servers
Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped…
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an…
Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites
A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware.…
Lucid Works With Bolt On European Robotaxi Network
California-based Lucid to sell electric vehicles to Estonia’s Bolt for planned robotaxi network in European cities
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub,…
IT Security News Hourly Summary 2026-09-18 08h : 11 posts
11 posts published in the last hour 05:31Andorran Police joins Europol’s secure communication network 05:31FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks 05:3198% of fraudulent hires have company credentials by the time they’re caught 05:31MovieReaper Malware…
Andorran Police joins Europol’s secure communication network
Through this connection, the Andorran Police will be able to securely share law enforcement information with Europol and a wide network of European and…
FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to…
98% of fraudulent hires have company credentials by the time they’re caught
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud…
MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
A newly identified Windows malware framework dubbed MovieReaper is being distributed through pirated movie torrents after threat actors compromised a…
Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories
Researchers used Anthropic’s Claude Opus 5 to help weaponize an image-decoder vulnerability, compromise OpenAI’s community forum, take over employees’…
