149 posts published today
- 21:31U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
- 21:31Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- 21:00IT Security News Hourly Summary 2026-09-25 23h : 5 posts
- 20:315G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
- 20:31Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- 20:02Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
- 20:02From Debugging to Code Execution: RCE in Microsoft DevLabs’ DebugMCP?
- 20:00IT Security News Hourly Summary 2026-09-25 22h : 14 posts
- 19:31Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!
- 19:31Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines
- 19:31Why would you want to turn off Apple Intelligence and Siri AI on iOS 27?
- 19:31WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments
- 19:31Fake Google Security Team ad says ‘no script reading’ in voice phishing – then prints the script
- 19:31TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
- 19:02Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
- 19:02Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
- 19:02Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems
- 19:02International investigation identifies over 70 potential victims exploited in Indian restaurants
- 19:0214-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers
- 19:02Why security belongs in the network
- 19:01OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services
- 19:00IT Security News Hourly Summary 2026-09-25 21h : 8 posts
- 18:31ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’
- 18:31Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million
- 18:31CAIRN framework, Muse zero-day, BigDiskBuster
- 18:31Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
- 18:02Apple Ships Desktops Pitched As Enterprise AI Alternative
- 18:02ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
- 18:01Discord Wants to Estimate Your Age Without Asking for ID
- 18:00IT Security News Hourly Summary 2026-09-25 20h : 8 posts
- 17:31Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical
- 17:31Google Maps Error Causes Traffic Chaos In Rural Scotland
- 17:31Crooks use fake desktop apps to fool HR staff into giving them remote access
- 17:31Some Supabase customers are publicly exposing reams of people’s data to the web
- 17:31WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution
- 17:31Bitget blames North Korea for $387.5M crypto wallet raid
- 17:01Wordfence Bug Bounty Program Monthly Report – June 2026
- 17:00IT Security News Hourly Summary 2026-09-25 19h : 10 posts
- 16:02PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
- 16:02Macfinger ClickFix campaign, (Tue, Sep 22nd)
- 16:02Storm-3168: Agentic-driven cloud attacks using compromised service principals
- 16:02Amazon Slams the door on Meta’s Muse AI Agent
- 16:02Check Point Warns of Active Exploitation of Two Critical Pre-Authentication Vulnerabilities
- 16:02Sovereignty vs Convenience
- 16:02Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
- 16:02Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
- 16:02ISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)
- 16:00IT Security News Hourly Summary 2026-09-25 18h : 11 posts
- 15:31Wiz uses AI to find vulnerabilities in critical infrastructure
- 15:31In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
- 15:31Kothamine malware uses Tailscale’s tailcat to evade network detection
- 15:31Zero-Days, AI Agents, and Identity Attacks Define Cybersecurity Week
- 15:31Critical Roundcube Flaw Under Active Exploitation in Code Injection Attacks
- 15:31Rogue OpenAI agent targeted Australian government site
- 15:31LinkedIn adds new checks for fake profiles and work histories
- 15:31How an OpenAI ‘agent’ hacked Australia’s Medicare and What that Means for Governments Worldwide
- 15:31Businesses expand AI’s cybersecurity uses as comfort with technology grows
- 15:02Which copy of that file is the real one? Dinner, off the record, in Midtown
- 15:00IT Security News Hourly Summary 2026-09-25 17h : 8 posts
- 14:31North Korea Suspected in $351 Million Bitget Crypto Heist
- 14:31Cyber Briefing: 2026.09.25
- 14:31ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
- 14:31Quantum computing’s “dark horse” just proved it can go universal
- 14:02AI Q&A: what is an Agent?
- 14:02Ransomware gangs exploiting critical TeamCity flaw
- 14:02Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
- 14:00IT Security News Hourly Summary 2026-09-25 16h : 15 posts
- 13:33Party Invite Phishing Scams Target Users
- 13:32CenterPoint Energy breach: 7.49M records claimed stolen
- 13:32Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right
- 13:32Rydox marketplace admin pleads guilty
- 13:32North Korean hackers suspected in $351M crypto theft, the largest so far this year
- 13:31Detection dashboards mask security coverage gaps
- 13:31Locking Down the Enterprise: Data Security Patterns for AI Integrations
- 13:31Microsoft Unified Copilot App Launches with Code, Autopilot
- 13:02Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated
- 13:02Criminals turn placeholder domain into ClickFix trap
- 13:02The SOC Doesn’t Need to Start Over with Every Alert
- 13:02CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
- 13:02CISA Unveils Election Security Plan Ahead of 2026 Midterms
- 13:0214-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
- 13:00IT Security News Hourly Summary 2026-09-25 15h : 7 posts
- 12:31Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
- 12:31Been told to pay at a Bitcoin ATM? Read this first
- 12:31Attackers build “silent” cryptominer on victim’s machine and give themselves away
- 12:31Threat detection dashboards are masking security coverage gaps
- 12:02PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
- 12:02Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems
- 12:00IT Security News Hourly Summary 2026-09-25 14h : 8 posts
- 11:31Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
- 11:31On Anthropic’s AI Misuse Report
- 11:02Two-week Europol task force identifies 18 sexually abused children worldwide
- 11:02Windows, Linux, Android File Notification Systems Leak User Activity
- 11:02Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed
- 11:02SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
- 11:02ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
- 11:00IT Security News Hourly Summary 2026-09-25 13h : 7 posts
- 10:31AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
- 10:31CISA Adds Multiple Check Point Product Flaws to Exploited Vulnerabilities List
- 10:31Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
- 10:31CISA Flags WSO2 Security Flaw Under Active Exploitation
- 10:02CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
- 10:02That shipping rebate offer may come with a monthly charge
- 10:00IT Security News Hourly Summary 2026-09-25 12h : 9 posts
- 09:31‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
- 09:31Bitget Hacked: $352M Theft Largest Crypto Heist 2026
- 09:31CrowdStrike Delivers the Next Evolution of the Agentic SOC
- 09:31RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
- 09:31MacSync info-stealing malware hides malicious commands in an iCloud calendar
- 09:31U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
- 09:02Researchers Identify AliExpress Phishing Domains Before Registration
- 09:02CrowdStrike Announces Agentic Identity Provider
- 09:00IT Security News Hourly Summary 2026-09-25 11h : 10 posts
- 08:32Docker introduces OCI-based Kits to package agents and their guardrails
- 08:32Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network
- 08:31Abnormal AI brings governance, cloud security, and threat investigation into one suite
- 08:31Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline
- 08:31Dataiku Agent Management reveals unmonitored AI agents
- 08:31New MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft
- 08:31Fake payroll desktop apps hand attackers a route to company paychecks
- 08:02Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
- 08:02SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads
- 08:01IT Security News Hourly Summary 2026-09-25 10h : 6 posts
- 07:31OpenAI hacks Australia health, Astrana Health breached, TeamCity flaw exploited
- 07:31Sudo Vulnerability Lets Attackers Bypass Time-Based Authorization Controls
- 07:31Starting university? Watch out for these common student scams
- 07:02Roundcube Webmail Vulnerability in Attackers’ Crosshairs
- 07:012026-09-24: Files for an ISC Diary (Macfinger ClickFix activity)
- 07:00IT Security News Hourly Summary 2026-09-25 09h : 11 posts
- 06:31Anthropic Releases Lower-Cost Opus 5.5 Ahead Of IPO
- 06:31Duelbits Hot Wallet Hack Drains $7 Million, Forces Platform Offline
- 06:31A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
- 06:31WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
- 06:31Bitget Confirms $351.6 Million Hot Wallet Hack, Suspends Withdrawals
- 06:31Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data
- 06:31Attackers Drain Payy Network After Exploiting Ethereum Bridge Contract
- 06:02Stop watching what AI agents say and start watching what they do
- 06:02OnePlus Android Devices Face Root Access Risk From Unpatched Flaws
- 06:01Cloudflare Containers Flaw Could Expose Data From Other Customers’ Workloads
- 06:00IT Security News Hourly Summary 2026-09-25 08h : 4 posts
- 05:31Half of threat hunters say bad data is their biggest problem
- 05:02Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
- 05:02Your incident count is missing a few incidents
- 05:02Cloudflare Containers Vulnerability Could Leak Data Between Customer Workloads
- 04:31New infosec products of the month: September 2026
- 04:02ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)
- 01:02Open AI Agents Attack Australian Healthcare
- 01:02Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
- 00:02Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
