178 posts published today
- 21:31Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
- 21:01Green Growth Without Washington: Why US Businesses Are Still Investing in Climate Technology
- 21:01Citrix Patches Critical Zero Days Under Active Exploitation
- 21:00IT Security News Hourly Summary 2026-09-30 23h : 9 posts
- 20:31A week in security (September 21 – September 27)
- 20:31http-terminator – AI-Assisted HTTP Request-Smuggling Discovery
- 20:31WatchGuard fixes critical Fireware OS flaw allowing remote code execution
- 20:02MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
- 20:02Hackers stole millions of US military personnel records during months-long data breach
- 20:02Huawei Smartphone Chip Narrows Performance Gap
- 20:01Certainties in life: Death, taxes, and critical Citrix vulns under attack
- 20:01New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage
- 20:00IT Security News Hourly Summary 2026-09-30 22h : 11 posts
- 19:02Medela – 423,947 breached accounts
- 19:02PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries
- 19:02When Productivity Extensions Become Attack Platforms
- 19:02AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub
- 19:02The Silent Container Death: A TCP Dial That Never Times Out
- 19:02Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
- 19:02Local Residents Protest Massive North Devon Data Centre
- 19:02Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
- 19:01OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought
- 19:01Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
- 19:00IT Security News Hourly Summary 2026-09-30 21h : 10 posts
- 18:31Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
- 18:31Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux
- 18:31Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells
- 18:31Ping Command Options & Syntax: Network Admin Guide
- 18:31Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
- 18:3116-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
- 18:31Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS
- 18:01Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
- 18:01Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
- 18:01IT Security News Hourly Summary 2026-09-30 20h : 4 posts
- 17:01Pentagon Confirms Breached 3 Million DMDC Personnel Database
- 17:01Mass exploitation of Citrix NetScaler: What we currently know
- 17:01iPhone Security Warning: Apple Says iOS 26 Flaw May Have Been Exploited
- 17:00IT Security News Hourly Summary 2026-09-30 19h : 7 posts
- 16:31Two new NetScaler zero-days exploited, ShinyHunters steals FBI medical files, OpenAI Australia hack disputed
- 16:31Meta disputes claim that Muse read a user’s private messages without permission
- 16:31ISC Stormcast For Monday, September 28th, 2026 https://isc.sans.edu/podcastdetail/10112, (Mon, Sep 28th)
- 16:02101 Malicious npm Packages Secretly Enroll Developers into WhatsApp Spam Channels
- 16:02Hackers steal protective order and foster care records from Arizona courts
- 16:01Global Group Ransomware Abuses WinMerge to Deploy Encryptor
- 16:00IT Security News Hourly Summary 2026-09-30 18h : 11 posts
- 15:3184% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain
- 15:31Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
- 15:31National cyber director defends private-sector hacking program, urges focus on security basics
- 15:31Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
- 15:31MCP Python SDK Flaw Exposes OAuth Credentials
- 15:31Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- 15:02Opsec Fail Leaks a Rare Look Inside a Media-Buy-Powered Scam Operation
- 15:02Legit Security launches agentic remediation for open-source dependency vulnerabilities
- 15:02Six arrests for smuggling migrants via Schengen airports
- 15:01Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
- 15:00IT Security News Hourly Summary 2026-09-30 17h : 12 posts
- 14:31Cyber Briefing: 2026.09.30
- 14:31Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments
- 14:31Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
- 14:31The devil is still in the email – but wears a new mask
- 14:31Jailbreaking AI: What It Is and Why It Matters for Security
- 14:31Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks
- 14:31Timeshare exit scams: From fake buyers to recovery fraud
- 14:02AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
- 14:02Oracle launches Fusion Claw AI agentic runtime
- 14:02Quantum teleportation breakthrough: Scientists crack a 25-year entanglement challenge
- 14:01RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
- 14:00IT Security News Hourly Summary 2026-09-30 16h : 14 posts
- 13:31Signal adds encrypted backups, cross-platform restore
- 13:31AI Coding Agents Leak 13K Internal Images on GitHub
- 13:31EU CRA requirements for containers and Kubernetes
- 13:31WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
- 13:31US CSuite Phishing Campaign Steals M365 Sessions
- 13:02PaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
- 13:02Know Your Enemy: Browser-Based Attack Techniques in 2026
- 13:02CyberASAP Celebrates 10th Anniversary with Special Event Exploring Future of UK Cyber Security Innovation
- 13:02Trump, Six AI Giants Sign ‘Super Intelligence’ Safety Accord
- 13:02Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
- 13:01Don’t Make It Easy For Them: Cybersecurity Awareness Month 2026
- 13:01Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
- 13:01Docker CopyEscape CVE-2026-17106 Lets Malicious Containers Overwrite Host Files
- 13:00IT Security News Hourly Summary 2026-09-30 15h : 13 posts
- 12:31Attackers Target Developer Credentials to Expand Supply Chain Intrusions Beyond Source Code
- 12:31AI Boosts SOC Analyst Capacity but Limits Skill Development
- 12:31Claude Compliance API Lets Security Teams Monitor Chats, Files and Agent Activity
- 12:31Chrome, Firefox Updates Patch Over 100 Vulnerabilities
- 12:31Critical MikroTik RouterOS Vulnerability Exposes Devices to Remote Code Execution
- 12:02AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
- 12:02AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
- 12:02Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Bug
- 12:02CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
- 12:02Your car’s app could be telling Big Tech who you are and where you go
- 12:02US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
- 12:0212 Best IGA Tools in 2026: The Ranked Buyer’s Guide
- 12:00IT Security News Hourly Summary 2026-09-30 14h : 14 posts
- 11:32Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
- 11:31Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware
- 11:31AI Is Making Software Cheaper to Attack. Defenders Need to Change the Price
- 11:31EU law enforcement chiefs gather to discuss new challenges in EU security
- 11:31Continuous Penetration Testing: Why Annual Pen Tests Are a Compliance Checkbox, Not a Security Strategy
- 11:31Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
- 11:31How much does the average UK SME spend on cybersecurity each year?
- 11:31I Want Better Reporting on AI Genie Behavior
- 11:31How Is AI Improving These 3 Tech Sectors?
- 11:02Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software
- 11:02OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
- 11:02Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
- 11:01How Israeli Checkpoints Choke Palestinian Life in the Occupied West Bank
- 11:00IT Security News Hourly Summary 2026-09-30 13h : 16 posts
- 10:32RSA Launches Agent ID Platform to Secure AI Agents and MCP Servers
- 10:31RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
- 10:31Hackers Abuse MSP360 and ScreenConnect RMM Tools for Persistent Access and Credential Theft
- 10:31Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code
- 10:31More than half of UK businesses lack confidence in basic cyber skills
- 10:31New OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators
- 10:31ShinyHunters Defiant After FBI Calls on Members to Come Forward
- 10:31AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access
- 10:02Attackers Use PaperCut RCE Chain to Steal Tokens and Access Domain Controller
- 10:02China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
- 10:02Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore
- 10:02Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
- 10:02RSA Agent ID Secures AI Agents and MCP Servers With Identity-Based Access Controls
- 10:02OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
- 10:01Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells
- 10:00IT Security News Hourly Summary 2026-09-30 12h : 5 posts
- 09:31Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
- 09:028 Top Red Teaming Service Providers for Enterprise Adversary Emulation
- 09:02Apple Patches CoreGraphics Zero Day Exploited in Attacks
- 09:01Cybersecurity Month: 4 essential security habits
- 09:00IT Security News Hourly Summary 2026-09-30 11h : 9 posts
- 08:31OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access and Admin Paths
- 08:31WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
- 08:31UK rail cops’ £320K face-scanning spree nets zero matches
- 08:31U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
- 08:02International investigation identifies over 70 potential victims exploited in Indian restaurants
- 08:02Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access
- 08:02Former US Air Force members behind million-dollar BEC scheme head to prison
- 08:01Spain, Denmark and the Netherlands win Europol 2026 Excellence Awards in Innovation
- 08:00IT Security News Hourly Summary 2026-09-30 10h : 13 posts
- 07:31Star Blizzard, Cloudflare CA, GPT-6.1 scuttled
- 07:31Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts With No MFA
- 07:31Tech Company Halo Moves Into Futuristic Ipswich Headquarters
- 07:31MCP Python SDK OAuth Flaw Lets Malicious Servers Hijack AI Agent Accounts
- 07:31Spectre bug is back, this time to haunt JIT engines
- 07:31OpenAI Rolled out Codex Security Cloud, an Always-on Application Security Service
- 07:02SpaceX’s Starship Orbits Earth For First Time
- 07:02High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
- 07:02Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
- 07:02Genea brings AI agents to access control with role-based permissions
- 07:02Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
- 07:01Security tools can now scan Claude Enterprise chats and uploads for sensitive data
- 07:00IT Security News Hourly Summary 2026-09-30 09h : 6 posts
- 06:31Apple Hit By $5.7bn Verdict Over Vibration Patents
- 06:31Unsloth Fixes Arbitrary Code Execution Flaw Triggered by Malicious Hugging Face Models
- 06:02Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks
- 06:02OWASP Noir: Open-source static analysis tool
- 06:01SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
- 06:00IT Security News Hourly Summary 2026-09-30 08h : 6 posts
- 05:31OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext
- 05:31FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader
- 05:31EU Cyber Resilience Act requirements for containers and Kubernetes
- 05:31OpenAI Launches Codex Security Cloud for Always-On Application Security Scanning
- 05:01In this new SME cybersecurity service, the AI assists and the consultants decide
- 05:00IT Security News Hourly Summary 2026-09-30 07h : 5 posts
- 04:31OpenSSL Fixes High-Severity Flaw That Can Leak Server Memory in Plaintext
- 04:31Most open critical and high flaws are over 90 days old
- 04:31Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization
- 04:02WSL containers are generally available on Windows
- 04:01Most organizations need six months or longer to roll out new security controls
- 03:31Securing AI agents requires securing the systems around them
- 03:31Post-quantum website certificates from Cloudflare are scheduled for early 2027
- 02:01Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
- 02:01ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th)
- 01:01ShinyHunters Leader Busted
- 23:01Phishing Abuses RMM Tools for Persistent Access
- 23:00IT Security News Hourly Summary 2026-09-30 01h : 3 posts
- 22:31Dutch ShinyHunters Suspect Investigated for Trying to Arrange 2 Murders
- 22:01Add one more AI worry to the nightmare scenario: self-replicating prompt injections
