169 posts were published in the last hour
- 20:34 : OpenClaw security best practices for CISOs
- 20:34 : GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
- 20:4 : Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military
- 19:39 : Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
- 19:38 : How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
- 19:7 : Refresh Token Rotation in Node.js: Stopping Token Theft Without Logging Users Out
- 19:6 : How to choose the best SOC platform in 2026 (and our top 4)
- 19:5 : Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
- 19:5 : IT Security News Hourly Summary 2026-07-22 21h : 12 posts
- 19:4 : Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
- 18:36 : Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability
- 18:36 : A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool
- 18:36 : ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
- 18:35 : Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
- 18:35 : RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
- 18:34 : 2026 DevOps Security Insights: What Matters Most for CISOs
- 18:34 : Ghost in the Calendar: The Microsoft 365 Calendar Implant
- 18:34 : Operational Cyberpsychology: Applying Behavioral Science to Harden Enterprise Cyber Defense
- 18:34 : Red Card for Piracy: Feds Seize Over 1,000 Illegal World Cup Streams
- 18:5 : Rondo Meets Geoserver, (Wed, Jul 22nd)
- 18:5 : How Agentic Ransomware is Changing Enterprise Cybersecurity
- 18:5 : Ostium Confirms $23.75 Million Vault Exploit After Off-Chain Price Feed Compromise
- 18:4 : Meta’s Muse AI: How Instagram Users Can Opt Out After Privacy Backlash
- 17:36 : OpenAI Models Escaped Test Environment and Breached Hugging Face
- 17:35 : Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results
- 17:35 : New Data Shows Suno Breach Affected 55M Accounts
- 17:34 : Music Industry Introduces Voluntary AI Labels to Improve Transparency in Recordings
- 17:34 : Real world incident response: Microsoft and AXA XL strengthen cyber resilience
- 17:5 : Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?
- 17:4 : Linux kernel team publishes 432 CVEs in two days
- 17:4 : Galaxy Digital launches $5M initiative to boost Bitcoin against future quantum computing threats
- 16:34 : How to Make AI Tools Work Reliably for Growing Teams
- 16:34 : Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective
- 16:34 : FakeGit Malware Campaign Abuses GitHub Repositories and AI Tools
- 16:34 : AI Chatbot Usage Declines as Privacy and Trust Concerns Influence User Adoption
- 16:5 : IT Security News Hourly Summary 2026-07-22 18h : 16 posts
- 16:2 : Threat group claims credit for ransomware attack on Coca-Cola’s dairy unit
- 15:35 : Secure Healthcare Networks with Zero Trust Device Segmentation
- 15:35 : Trump’s AI Safety Chief Is Out — After Just 90 Days on the Job
- 15:35 : France Bans Social Media for Under-15s, Requires Age Checks
- 15:35 : If you pay a hacker’s ransom, chances are that they’ll come back for more
- 15:35 : A Single Extra “t” in a NuGet Package Allow Attackers to Manipulate Results
- 15:35 : Russian Intelligence Hijacks IP Cameras to Monitor Weapons Deliveries to Ukraine
- 15:34 : Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files
- 15:34 : SolarWinds Patches 15 Critical Serv-U Flaws That Could Hand Attackers Root Access
- 15:34 : Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains
- 15:34 : Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
- 15:34 : OpenAI models escaped containment and hacked a major AI application library
- 15:5 : Firewall Types Explained: Packet Filtering, Stateful, NGFW, and WAF (2026)
- 15:5 : Azure DevOps Prompt Injection Targets AI Coding Agents
- 15:5 : Meeting the European Central Bank’s AI Cybersecurity Mandate
- 15:5 : Palo Alto Networks to Acquire Observability Platform Provider Embrace
- 15:4 : OpenAI: Our models breached Hugging Face during a cyber capability test
- 15:4 : TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
- 14:35 : Security Advisory – Action Required – July 2026 Security Update
- 14:34 : Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
- 14:34 : OpenAI Presence connects AI agents to enterprise data with built-in guardrails
- 14:34 : On the “HollowByte” denial-of-service report
- 14:5 : When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
- 14:5 : Swimlane AI SOC automates security operations for MSSPs
- 14:5 : ThreatDown expands security visibility to AI tools and machine identities
- 14:4 : Astelia extends reachability analysis with agentic AI for vulnerability management
- 14:4 : The Fastest Path to AI Adoption Runs Through Security
- 14:4 : Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
- 13:34 : Inside a TrickBot Variant Using DNS Tunneling for C2
- 13:6 : AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release
- 13:6 : Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
- 13:5 : FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims
- 13:5 : Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service
- 13:5 : CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
- 13:5 : IT Security News Hourly Summary 2026-07-22 15h : 14 posts
- 13:5 : Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks
- 13:4 : New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies
- 13:4 : Chick-fil-A loyalty accounts hijacked using stolen passwords
- 13:4 : Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
- 13:4 : StrongestLayer Raises $4.1 Million in Seed Funding Extension
- 13:3 : Car Alarm Devices Vulnerable to Hacking
- 13:3 : Paidwork breach exposes 23M users
- 13:3 : Glow raises $180M Series A at $1.2B valuation
- 13:3 : Council worker gets suspended sentence for data snooping
- 13:2 : Google Launches Gemini 3.5 Flash Cyber AI Model
- 13:2 : 4 ways to secure local developer IDEs and tools without sacrificing velocity
- 12:34 : Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses
- 12:5 : CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
- 12:5 : Paidwork breach exposes data of 23 million users: Check if you’re affected
- 12:4 : Greedy ransomware crews return for seconds after victims cough up first extortion payments
- 12:4 : Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
- 12:4 : Open AI Claims Its AI Models Went Rogue and Hacked Another Company
- 11:35 : New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
- 11:35 : U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
- 11:34 : First-Person Identity Theft Story
- 11:34 : Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
- 11:34 : Glow exits stealth with $180 million to secure the AI-enabled endpoint
- 11:34 : Why Modern SOCs Need Multi-Layered Detections
- 11:6 : Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
- 11:6 : States Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking Them
- 11:5 : Lookout identifies exploitable vulnerabilities in mobile apps
- 11:5 : US seizes over 1,000 domains used for illegal World Cup 2026 streams
- 11:5 : Ubuntu snap-confine Vulnerability Enables Local Root Access
- 10:35 : Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
- 10:35 : FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims
- 10:34 : Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns
- 10:34 : Arista adds AI-driven zero trust to VeloCloud SD-WAN
- 10:34 : Box expands enterprise AI governance with new agent security featuresox
- 10:34 : Google Makes CodeMender Available as Managed AI Security Agent
- 10:6 : North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
- 10:6 : Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
- 10:5 : Black Hat 2026: Key news, takeaways and security trends
- 10:5 : Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era
- 10:5 : Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns
- 10:5 : Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
- 10:5 : Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
- 10:5 : Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
- 10:5 : IT Security News Hourly Summary 2026-07-22 12h : 6 posts
- 10:5 : Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
- 10:4 : Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
- 10:4 : Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
- 10:4 : Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
- 10:4 : AI models cheat on cybersecurity evaluations, then fail to admit it
- 9:31 : OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
- 9:5 : Microsoft To Fund Mistral Data Centre Expansion In Europe
- 9:4 : Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform
- 9:4 : SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root
- 9:4 : Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
- 8:36 : OpenAI Says Models Escaped Sandbox, Hacked Outside Firm
- 8:36 : Council worker spared prison after four-day data-snooping spree
- 8:35 : Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
- 8:34 : Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
- 8:5 : How hackers used Steam Workshop to spread malware
- 8:4 : China Considers Restrictions On AI Models
- 8:4 : OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
- 8:4 : Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
- 7:35 : Moonshot Plans Funding Round At $50bn Valuation, Ahead Of IPO
- 7:35 : GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions
- 7:34 : OpenAI Confirms Its Models Breached Hugging Face Production Systems During Cyber Benchmark Testing
- 7:34 : Bit2Watt instability, AI models cheat, Chinese LLM ban
- 7:5 : IT Security News Hourly Summary 2026-07-22 09h : 10 posts
- 7:5 : Z.ai Builds Massive AI Data Centre With Domestic Chips
- 7:4 : Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers
- 7:4 : Google Unveils Gemini 3.5 Flash Cyber: A Game-Changer for AI-Powered Security
- 6:32 : UK Government Scraps Tech Department, But Highlights AI
- 6:32 : Small teams are the heaviest users of AI coding agents
- 6:32 : OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
- 6:32 : Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
- 6:32 : Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
- 6:5 : Scotland To Deploy Drones To Aid Gull Management
- 6:5 : AccuKnox Wins Best AI Startup Award for Enterprise Agentic AI Security at BSides Bangalore
- 6:5 : Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities
- 6:4 : Snowpick: Open-source ServiceNow exposure scanner
- 5:34 : Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks
- 5:4 : OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers
- 5:4 : AI can’t fix cybersecurity’s hiring problem
- 5:4 : Security teams keep finding critical flaws after scheduled testing ends
- 4:34 : OpenAI’s GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers
- 4:34 : Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks
- 4:34 : Cloud operations become the next big role for agentic AI
- 2:5 : ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)
- 1:34 : OpenAI admits it was the source of the agent swarm that attacked Hugging Face
- 1:34 : LG to Ban Residential Proxies from Smart TV Apps
- 1:34 : WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug
- 1:5 : IT Security News Hourly Summary 2026-07-22 03h : 1 posts
- 1:4 : Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn
- 23:33 : OpenAI Models Escaped Containment and Hacked Hugging Face
- 23:4 : OpenAI Models Escaped Containment and Hacked HuggingFace
- 22:34 : Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
- 22:6 : 14 Types of Cybercrime + How to Prevent Them
- 22:6 : How to Make Strong Passwords: Best Internet Safety Practices
- 22:5 : IT Security News Hourly Summary 2026-07-22 00h : 3 posts
- 21:55 : IT Security News Daily Summary 2026-07-21