200 posts published this week
- 21:55IT Security News Roundup: 2026-09-20
- 21:55IT Security News Daily Summary 2026-09-20
- 18:31Critical Orkes Conductor Flaw Exploited for Unauthenticated Remote Code Execution
- 18:01An AI Helped Researchers Break Into OpenAI
- 17:312026-09-15: SmartApeSG ClickFix to unidentified RAT to MeshAgent
- 17:02U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
- 16:02Unauthenticated RCE Bug Fixed in SolarWinds Access Rights Manager
- 15:02AI-Powered Cyberattacks – How Hackers Use Machine Learning in 2026
- 15:02Gyazo Server Vulnerability Targeted to Steal Millions of User Records
- 14:02AI Hallucinations Nearly Triggered a US-China Military Confrontation
- 13:02SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
- 12:31Below the Waterline Stage 1 – Red Team Planning
- 10:01Business Survival in the Age of AI
- 08:31Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
- 08:31Court Filing Shows Microsoft Exec Called AI Training the “Largest Labor Theft in Human History”
- 06:02When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain
- 06:02Autonomous AI Attacks: The Hugging Face Reality Check
- 01:02Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION
- 21:55IT Security News Daily Summary 2026-09-19
- 18:00IT Security News Hourly Summary 2026-09-19 20h : 7 posts
- 17:31Plugin4Shell: The Zero-Click Flaw That Broke Every Prominent AI Coding Agent at Once
- 17:31Google’s Gemini is the latest AI model to hack other companies
- 17:31Microsoft Fixes Critical Azure AI Flaw Rated CVSS 10.0
- 17:02UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day
- 17:02Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook
- 17:02CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks
- 17:02Hackers Crack Flock Camera, Expose 1.6M Images in 21 Days
- 16:00IT Security News Hourly Summary 2026-09-19 18h : 4 posts
- 15:02Google Gemini also Broke Out of Its Test Environment
- 15:02TigerByte Cyber Emerges From Stealth With $3 Million in Funding
- 15:02WeaselBiscuit Stealer Found in 13 Malicious npm Packages
- 15:00IT Security News Hourly Summary 2026-09-19 17h : 4 posts
- 14:31RatHat Android Malware Uses AI to Control Infected Devices
- 14:31Identity Visibility in 2026: The Foundation of Identity Security
- 14:31Agentic security is the billion-dollar challenge for some clever startup to solve
- 14:01AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
- 13:31Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet
- 12:01TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories
- 12:00IT Security News Hourly Summary 2026-09-19 14h : 3 posts
- 11:31SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
- 11:31Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
- 11:31Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
- 10:02Google Gemini AI Hacked 3 Real Companies during a Cybersecurity Test
- 10:00IT Security News Hourly Summary 2026-09-19 12h : 5 posts
- 09:316 Best VPN Services (2026), Tested and Reviewed
- 09:31Drug trafficking investigation leads to some of the world’s biggest underground bankers
- 09:31North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
- 09:02Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
- 09:02Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
- 08:31AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes
- 08:02CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
- 07:31CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
- 07:31PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner
- 06:02Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link
- 05:02Thousands of horses caught up in Europe-wide trafficking scheme
- 05:02‘Nudify’ apps: What to do if someone makes a fake nude of you
- 04:31BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers
- 02:31Flock Offers Employees Buyouts as Customers Flee
- 01:02CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
- 00:31Anthropic insider claims 10% extinction risk, Five Eyes push basics, Microsoft patches backfire
- 23:01The Department of Know: Passkeys phished, Cisco hits root, nuclear red lines for AI
- 22:02Brevo Supply-Chain Attack Infected Over 100,000 Websites
- 22:00IT Security News Hourly Summary 2026-09-19 00h : 6 posts
- 21:56IT Security News Roundup: 2026-09-18
- 21:55IT Security News Daily Summary 2026-09-18
- 21:31Cyber Briefing: 2026.09.16
- 21:31Friday Squid Blogging: On Squid Egg Sacs
- 21:01CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
- 21:00IT Security News Hourly Summary 2026-09-18 23h : 4 posts
- 20:31Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
- 20:31Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
- 20:02HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
- 20:00IT Security News Hourly Summary 2026-09-18 22h : 4 posts
- 19:31Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes
- 19:02Scammers Are Watching Airline Complaints and Posing as Customer Support
- 19:02Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V
- 19:00IT Security News Hourly Summary 2026-09-18 21h : 13 posts
- 18:31Top 30 Cybersecurity Interview Questions And Answers For 2026
- 18:31Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
- 18:31Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
- 18:31Microsoft warns of cloud storage and financial fraud campaign
- 18:02Robinhood engineers charged in $50K crypto fraud
- 18:02Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
- 18:02Gyazo Data Breach Exposes 23 Million User Records
- 18:02N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
- 18:02FBI, Coast Guard boarded hacked oil tankers heading toward US coast
- 18:02Dataminr, Crisis24 integrate AI threat detection
- 18:02New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
- 18:02SE Labs Launches PIVOT Testing Program
- 18:00IT Security News Hourly Summary 2026-09-18 20h : 17 posts
- 17:31Spain gets its first taste of AI-aided cyber attack
- 17:31Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
- 17:31UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location
- 17:31An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
- 17:31Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
- 17:31Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files
- 17:31Researchers used Claude to hack OpenAI employees’ ChatGPT accounts
- 17:02Cyber-Attacks Cost Organizations $52,000 on Average
- 17:02North Korea’s fake job interviews infected 30,000 devices
- 17:02Threat Intelligence Alone Won’t Close the Exploitation Gap
- 17:02Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
- 17:02An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
- 17:02Fake CAPTCHA Scams
- 17:02International investigation identifies over 70 potential victims exploited in Indian restaurants
- 17:02Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
- 17:01Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
- 17:00IT Security News Hourly Summary 2026-09-18 19h : 17 posts
- 16:31Google Opens Google Home to Claude and Other AI Agents — Here’s What They Can Control
- 16:31Settra ransomware variant deployed in recent attacks
- 16:312026 Péter Szőr Award shortlisted nominees
- 16:31FBI: Fake cop and government impersonation scams cost victims $1.6B
- 16:31Google Pixel owners urged to patch actively exploited modem flaw
- 16:31Zero-Days, AI Agents, and Massive Data Leaks Define the Week
- 16:31Passwd Enterprise Review: Features, Pricing & Security
- 16:31New Android malware uses AI to steal bank logins and PINs
- 16:02Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
- 16:02Android Apps Can Now Check If Your Phone Is Missing Critical Security Patches
- 16:02Ministry of Justice apologizes after court staff accessed Southport victims’ files
- 16:02Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
- 16:02FBI, Coast Guard boarded hacked oil tankers heading towards US coast
- 16:02MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login
- 16:02Atomic macOS (AMOS) Stealer Activity
- 16:02Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws
- 16:00IT Security News Hourly Summary 2026-09-18 18h : 14 posts
- 15:32AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators
- 15:31Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access
- 15:31NightEagle targets Russian companies
- 15:31Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
- 15:31CISA ends weekly vulnerability roundups as part of shift to prioritization approach
- 15:31Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
- 15:31Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
- 15:31Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
- 15:02Did an AI really try to break free from human control?
- 15:02Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
- 15:02FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown
- 15:02Securing the unpatchable in an age of AI-driven vulnerabilities
- 15:02Unbound 1.26.1 Patches Critical RCE, DoS, and DNSSEC Flaws
- 15:00IT Security News Hourly Summary 2026-09-18 17h : 16 posts
- 14:3136,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
- 14:31In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
- 14:31Cyber Briefing: 2026.09.18
- 14:31Meta Plans Smart Glasses Without Camera, Amid Complaints
- 14:03New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
- 14:03AI helps scammers build convincing antivirus renewal pages
- 14:03US Official ‘Suspicious’ Of Anthropic Call For Antitrust Exemption
- 14:03PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
- 14:02Cyberattack Knocks International Meteor Organization Website Offline
- 14:02Researchers used Anthropic’s Claude to hack into OpenAI
- 14:02Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
- 14:02OpenAI Hacked By Anthropic Models – Research
- 14:02Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
- 14:02Brevo Breach Exposes Customer Websites to ClickFix Malware
- 14:02An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
- 14:00IT Security News Hourly Summary 2026-09-18 16h : 19 posts
- 13:31Hacker ‘Breached Italian Gov’t Email’ To Steal Revolut Data
- 13:31Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
- 13:31US, UK, Dutch Expose Iranian Chosen Brick Malware
- 13:31NCSC and Allies Warn of Iranian Spyware Campaign
- 13:31NIS-2: Why practical relevance is crucial in management training
- 13:31Meta Strengthens WhatsApp Account Security
- 13:31When Security Operations Can’t Keep Up: 4 Ways Agentic Network Security Management Improves Security Operations
- 13:31Meta’s Copyright System Is Being Weaponized Against Albanian Protesters
- 13:03CISA Upgrades Vulnerability Reporting Platform
- 13:03AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
- 13:02Italian Start-Up Raises $270m To Fend Off AI Attacks
- 13:02GUARD Act Passes House to Combat Elder Financial Fraud
- 13:02PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
- 13:02AI-Generated Fake Antivirus Renewal Scam Pages
- 13:02Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+
- 13:02Nvidia DSX platform optimizes datacenter power efficiency
- 13:02New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
- 13:02Spain reports first AI agent data breach
- 13:00IT Security News Hourly Summary 2026-09-18 15h : 9 posts
- 12:31GenAI-Powered ‘RatHat’ Android Malware Bypasses App Sandboxes via ADB
- 12:31Protesters Fight Microsoft’s Huge Leeds Data Centre
- 12:31Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
- 12:31JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
- 12:31Two-week Europol task force identifies 18 sexually abused children worldwide
- 12:31CISA Warns Attackers Are Exploiting Acronis Backup Flaw on Linux Servers
- 12:02Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
- 12:0123 Million User Records Compromised in Gyazo Data Breach
- 12:00IT Security News Hourly Summary 2026-09-18 14h : 15 posts
- 11:31Mythos has made 2026 patching hell. It might make 2027 a breeze
- 11:31Are AIs Still Struggling with CAPTCHAs?
- 11:31Health Group Issues Alerts Over 2025 Data Breach
- 11:31Apple Security Advisory – Patches 100+ Vulnerabilities Across iOS, macOS and Other Devices
- 11:02RatHat Turns Android Accessibility Into an Attack Weapon
- 11:02ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)
- 11:02CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
- 11:02WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
- 11:02Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
- 11:02Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities
- 11:02The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
- 11:02CrowdStrike Announces Agentic Identity Provider
- 11:02Revolut hands customer data to criminals, Microsoft patches break Remote Desktop, Conti developer gets four years
- 11:01CrowdStrike Delivers the Next Evolution of the Agentic SOC
- 11:00IT Security News Hourly Summary 2026-09-18 13h : 23 posts
- 10:32Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor
- 10:32NightmareStresser DDoS Service Disrupted in International Operation
- 10:32A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
