200 posts published today
- 21:31Cyber Briefing: 2026.09.16
- 21:31Friday Squid Blogging: On Squid Egg Sacs
- 21:01CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
- 21:00IT Security News Hourly Summary 2026-09-18 23h : 4 posts
- 20:31Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
- 20:31Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
- 20:02HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
- 20:00IT Security News Hourly Summary 2026-09-18 22h : 4 posts
- 19:31Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes
- 19:02Scammers Are Watching Airline Complaints and Posing as Customer Support
- 19:02Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V
- 19:00IT Security News Hourly Summary 2026-09-18 21h : 13 posts
- 18:31Top 30 Cybersecurity Interview Questions And Answers For 2026
- 18:31Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
- 18:31Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
- 18:31Microsoft warns of cloud storage and financial fraud campaign
- 18:02Robinhood engineers charged in $50K crypto fraud
- 18:02Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
- 18:02Gyazo Data Breach Exposes 23 Million User Records
- 18:02N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
- 18:02FBI, Coast Guard boarded hacked oil tankers heading toward US coast
- 18:02Dataminr, Crisis24 integrate AI threat detection
- 18:02New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
- 18:02SE Labs Launches PIVOT Testing Program
- 18:00IT Security News Hourly Summary 2026-09-18 20h : 17 posts
- 17:31Spain gets its first taste of AI-aided cyber attack
- 17:31Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
- 17:31UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location
- 17:31An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
- 17:31Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
- 17:31Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files
- 17:31Researchers used Claude to hack OpenAI employees’ ChatGPT accounts
- 17:02Cyber-Attacks Cost Organizations $52,000 on Average
- 17:02North Korea’s fake job interviews infected 30,000 devices
- 17:02Threat Intelligence Alone Won’t Close the Exploitation Gap
- 17:02Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
- 17:02An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
- 17:02Fake CAPTCHA Scams
- 17:02International investigation identifies over 70 potential victims exploited in Indian restaurants
- 17:02Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
- 17:01Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
- 17:00IT Security News Hourly Summary 2026-09-18 19h : 17 posts
- 16:31Google Opens Google Home to Claude and Other AI Agents — Here’s What They Can Control
- 16:31Settra ransomware variant deployed in recent attacks
- 16:312026 Péter Szőr Award shortlisted nominees
- 16:31FBI: Fake cop and government impersonation scams cost victims $1.6B
- 16:31Google Pixel owners urged to patch actively exploited modem flaw
- 16:31Zero-Days, AI Agents, and Massive Data Leaks Define the Week
- 16:31Passwd Enterprise Review: Features, Pricing & Security
- 16:31New Android malware uses AI to steal bank logins and PINs
- 16:02Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
- 16:02Android Apps Can Now Check If Your Phone Is Missing Critical Security Patches
- 16:02Ministry of Justice apologizes after court staff accessed Southport victims’ files
- 16:02Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
- 16:02FBI, Coast Guard boarded hacked oil tankers heading towards US coast
- 16:02MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login
- 16:02Atomic macOS (AMOS) Stealer Activity
- 16:02Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws
- 16:00IT Security News Hourly Summary 2026-09-18 18h : 14 posts
- 15:32AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators
- 15:31Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access
- 15:31NightEagle targets Russian companies
- 15:31Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
- 15:31CISA ends weekly vulnerability roundups as part of shift to prioritization approach
- 15:31Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
- 15:31Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
- 15:31Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
- 15:02Did an AI really try to break free from human control?
- 15:02Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
- 15:02FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown
- 15:02Securing the unpatchable in an age of AI-driven vulnerabilities
- 15:02Unbound 1.26.1 Patches Critical RCE, DoS, and DNSSEC Flaws
- 15:00IT Security News Hourly Summary 2026-09-18 17h : 16 posts
- 14:3136,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
- 14:31In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
- 14:31Cyber Briefing: 2026.09.18
- 14:31Meta Plans Smart Glasses Without Camera, Amid Complaints
- 14:03New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
- 14:03AI helps scammers build convincing antivirus renewal pages
- 14:03US Official ‘Suspicious’ Of Anthropic Call For Antitrust Exemption
- 14:03PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
- 14:02Cyberattack Knocks International Meteor Organization Website Offline
- 14:02Researchers used Anthropic’s Claude to hack into OpenAI
- 14:02Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
- 14:02OpenAI Hacked By Anthropic Models – Research
- 14:02Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
- 14:02Brevo Breach Exposes Customer Websites to ClickFix Malware
- 14:02An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
- 14:00IT Security News Hourly Summary 2026-09-18 16h : 19 posts
- 13:31Hacker ‘Breached Italian Gov’t Email’ To Steal Revolut Data
- 13:31Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
- 13:31US, UK, Dutch Expose Iranian Chosen Brick Malware
- 13:31NCSC and Allies Warn of Iranian Spyware Campaign
- 13:31NIS-2: Why practical relevance is crucial in management training
- 13:31Meta Strengthens WhatsApp Account Security
- 13:31When Security Operations Can’t Keep Up: 4 Ways Agentic Network Security Management Improves Security Operations
- 13:31Meta’s Copyright System Is Being Weaponized Against Albanian Protesters
- 13:03CISA Upgrades Vulnerability Reporting Platform
- 13:03AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
- 13:02Italian Start-Up Raises $270m To Fend Off AI Attacks
- 13:02GUARD Act Passes House to Combat Elder Financial Fraud
- 13:02PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
- 13:02AI-Generated Fake Antivirus Renewal Scam Pages
- 13:02Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+
- 13:02Nvidia DSX platform optimizes datacenter power efficiency
- 13:02New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
- 13:02Spain reports first AI agent data breach
- 13:00IT Security News Hourly Summary 2026-09-18 15h : 9 posts
- 12:31GenAI-Powered ‘RatHat’ Android Malware Bypasses App Sandboxes via ADB
- 12:31Protesters Fight Microsoft’s Huge Leeds Data Centre
- 12:31Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
- 12:31JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
- 12:31Two-week Europol task force identifies 18 sexually abused children worldwide
- 12:31CISA Warns Attackers Are Exploiting Acronis Backup Flaw on Linux Servers
- 12:02Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
- 12:0123 Million User Records Compromised in Gyazo Data Breach
- 12:00IT Security News Hourly Summary 2026-09-18 14h : 15 posts
- 11:31Mythos has made 2026 patching hell. It might make 2027 a breeze
- 11:31Are AIs Still Struggling with CAPTCHAs?
- 11:31Health Group Issues Alerts Over 2025 Data Breach
- 11:31Apple Security Advisory – Patches 100+ Vulnerabilities Across iOS, macOS and Other Devices
- 11:02RatHat Turns Android Accessibility Into an Attack Weapon
- 11:02ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)
- 11:02CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
- 11:02WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
- 11:02Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
- 11:02Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities
- 11:02The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
- 11:02CrowdStrike Announces Agentic Identity Provider
- 11:02Revolut hands customer data to criminals, Microsoft patches break Remote Desktop, Conti developer gets four years
- 11:01CrowdStrike Delivers the Next Evolution of the Agentic SOC
- 11:00IT Security News Hourly Summary 2026-09-18 13h : 23 posts
- 10:32Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor
- 10:32NightmareStresser DDoS Service Disrupted in International Operation
- 10:32A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
- 10:32Bots with good manners are better at fooling people on social media
- 10:32CISA Upgrades Vulnerability Reporting Platform with More Automation
- 10:32Europol and European Labour Authority strengthen cooperation against labour exploitation
- 10:32Top 10 Best Cloud Compliance Tools in 2026
- 10:31Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell
- 10:31Top 10 Best Cloud Encryption Solutions in 2026
- 10:31Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
- 10:31Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2
- 10:31ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
- 10:31WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities
- 10:02Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites
- 10:02Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
- 10:02One Click in a Malicious VS Code Project Can Give Attackers Persistent Access to Your PC
- 10:02Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
- 10:02Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
- 10:02CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
- 10:02AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection
- 10:02Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps
- 10:02Top 10 Best Container Registry Security Tools in 2026
- 10:00IT Security News Hourly Summary 2026-09-18 12h : 12 posts
- 09:31Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
- 09:31Europol celebrates the International Day of Police Cooperation
- 09:31Four AI Agent Security Risks Organisations Can’t Afford to Ignore
- 09:31Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
- 09:31Filigran, CyberASAP and Pulse Conferences Unite to Champion Cybersecurity’s Unsung Heroes
- 09:31Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication
- 09:02Android apps can now check security patches down to individual device components
- 09:02Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
- 09:02Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
- 09:02Critical Orkes Conductor Vulnerability Exploited in Attacks
- 09:02Arcjet brings security controls and audit trails to AI agents
- 09:00IT Security News Hourly Summary 2026-09-18 11h : 9 posts
- 08:3112 Best CDR Solutions Compared (2026): Features & Pricing
- 08:31Fake parcel delivery messages steal your card and bank details
- 08:3112 Best SSPM Tools Compared (2026): Features & Pricing
- 08:31Manufacturing Accounts for 22% of all Ransomware Victims
- 08:3112 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing
- 08:02Buying or selling a second-hand phone? How to protect your personal data
- 08:02Slow is a design principle, not a delay
- 08:02WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
- 08:00IT Security News Hourly Summary 2026-09-18 10h : 8 posts
- 07:31Beware the SparroWock: The backdoor that bites, the commands that catch
- 07:31Nuclear-style AI safeguards, AI legislation shelved, CISA’s decoy guidance
- 07:31MIND Secures $72 Million for AI-Powered DLP
- 07:31AI Cloud Firm Nebius Hikes GPU, CPU Prices
- 07:31Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
- 07:02German Court Finds Meta Liable For Fraudulent Ads
- 07:02Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
- 07:00IT Security News Hourly Summary 2026-09-18 09h : 7 posts
- 06:31HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
- 06:31Abandoned IoT apps keep sending sensitive data to broken servers
- 06:31RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
- 06:31Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites
- 06:31Lucid Works With Bolt On European Robotaxi Network
- 06:02Hardcoded MCP credentials found in public GitHub files
- 06:00IT Security News Hourly Summary 2026-09-18 08h : 11 posts
- 05:31Andorran Police joins Europol’s secure communication network
- 05:31FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks
- 05:3198% of fraudulent hires have company credentials by the time they’re caught
- 05:31MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
- 05:31Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories
- 05:31AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
- 05:02Unifying Client-Side Protection in Akamai Application Protection Platform
- 05:02OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
- 05:02Most WordPress pros still lack a breach recovery plan
