200 posts published this week
- 21:56IT Security News Roundup: 2026-09-27
- 21:55IT Security News Daily Summary 2026-09-27
- 19:31Best Security Awareness Platforms for Personalized Employee Training
- 18:31Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
- 18:00IT Security News Hourly Summary 2026-09-27 20h : 4 posts
- 17:02Citrix Confirms NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attack
- 17:02Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
- 17:01New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory
- 17:00IT Security News Hourly Summary 2026-09-27 19h : 3 posts
- 16:31SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1
- 16:01Six arrests for smuggling migrants via Schengen airports
- 16:00IT Security News Hourly Summary 2026-09-27 18h : 4 posts
- 15:31Wireshark 4.6.9 Released, (Sun, Sep 27th)
- 15:31x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining
- 15:31SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
- 15:31Bitget Hack Climbs to $387.5 Million as Exchange Launches Recovery Bounty and Points to North Korea
- 14:31Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION
- 13:31Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction
- 10:31Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
- 09:31Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
- 08:31Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- 08:31Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
- 07:02Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
- 21:56IT Security News Roundup: 2026-09-26
- 21:55IT Security News Daily Summary 2026-09-26
- 20:00IT Security News Hourly Summary 2026-09-26 22h : 4 posts
- 19:31Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
- 19:31Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2
- 19:01Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
- 19:00IT Security News Hourly Summary 2026-09-26 21h : 3 posts
- 18:31China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
- 18:02Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
- 18:01F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery
- 17:01AI Agents Can Be Secured. We Can Do It.
- 17:00IT Security News Hourly Summary 2026-09-26 19h : 3 posts
- 16:31SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
- 16:31OpenAI Agents Accessed US Government Websites Without Authorization
- 16:02Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
- 15:31Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
- 15:00IT Security News Hourly Summary 2026-09-26 17h : 5 posts
- 14:31Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- 14:31Zero Trust for AI Agents Starts With Fixing Zero Visibility
- 14:02Astrana Health Data Breach Exposes Private and Confidential Information
- 14:02ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
- 14:02CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog
- 13:00IT Security News Hourly Summary 2026-09-26 15h : 11 posts
- 12:31Drug trafficking investigation leads to some of the world’s biggest underground bankers
- 12:31Old-School Credit Card Scams Are Far From Dead
- 12:31Thousands of horses caught up in Europe-wide trafficking scheme
- 12:03OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
- 12:02OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted
- 12:02Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
- 12:02Is that vibe coded app safe? 5 checks before you download
- 12:02New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
- 12:02Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
- 12:0216-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records
- 12:02SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
- 09:02CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
- 09:00IT Security News Hourly Summary 2026-09-26 11h : 5 posts
- 08:31Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit
- 08:31U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
- 08:31Windows 11 Update Causes Black Screen and Desktop Loading Issues After Sign-In
- 08:01Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat
- 08:00IT Security News Hourly Summary 2026-09-26 10h : 3 posts
- 07:31Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
- 07:31Storm-3168 Hackers Abuse Compromised Service Principals to Destroy Azure Cloud Resources
- 07:01OpenAI Says Misaligned AI Agents Hacked Hugging Face and Bypassed Security Controls
- 01:31Is Privacy Dead?
- 00:00IT Security News Hourly Summary 2026-09-26 02h : 3 posts
- 23:313 Consulting Myths Debunked by Unit 42 Experts
- 23:01The Department of Know: NCSC’s AI “inconvenient truth,” automated payment skimming, CISA’s CVE plan
- 23:00IT Security News Hourly Summary 2026-09-26 01h : 5 posts
- 22:31Seattle Council Votes to Restrict Personalized Grocery Prices
- 22:31InfraTrust Report Flags Exploited Network Management Flaws
- 22:31Roundcube Webmail Under Attack: 523,000 Instances Exposed Online
- 22:02U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- 22:00IT Security News Hourly Summary 2026-09-26 00h : 5 posts
- 21:56IT Security News Roundup: 2026-09-25
- 21:55IT Security News Daily Summary 2026-09-25
- 21:31U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
- 21:31Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- 21:00IT Security News Hourly Summary 2026-09-25 23h : 5 posts
- 20:315G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
- 20:31Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- 20:02Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
- 20:02From Debugging to Code Execution: RCE in Microsoft DevLabs’ DebugMCP?
- 20:00IT Security News Hourly Summary 2026-09-25 22h : 14 posts
- 19:31Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!
- 19:31Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines
- 19:31Why would you want to turn off Apple Intelligence and Siri AI on iOS 27?
- 19:31WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments
- 19:31Fake Google Security Team ad says ‘no script reading’ in voice phishing – then prints the script
- 19:31TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
- 19:02Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
- 19:02Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
- 19:02Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems
- 19:02International investigation identifies over 70 potential victims exploited in Indian restaurants
- 19:0214-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers
- 19:02Why security belongs in the network
- 19:01OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services
- 19:00IT Security News Hourly Summary 2026-09-25 21h : 8 posts
- 18:31ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’
- 18:31Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million
- 18:31CAIRN framework, Muse zero-day, BigDiskBuster
- 18:31Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
- 18:02Apple Ships Desktops Pitched As Enterprise AI Alternative
- 18:02ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
- 18:01Discord Wants to Estimate Your Age Without Asking for ID
- 18:00IT Security News Hourly Summary 2026-09-25 20h : 8 posts
- 17:31Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical
- 17:31Google Maps Error Causes Traffic Chaos In Rural Scotland
- 17:31Crooks use fake desktop apps to fool HR staff into giving them remote access
- 17:31Some Supabase customers are publicly exposing reams of people’s data to the web
- 17:31WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution
- 17:31Bitget blames North Korea for $387.5M crypto wallet raid
- 17:01Wordfence Bug Bounty Program Monthly Report – June 2026
- 17:00IT Security News Hourly Summary 2026-09-25 19h : 10 posts
- 16:02PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
- 16:02Macfinger ClickFix campaign, (Tue, Sep 22nd)
- 16:02Storm-3168: Agentic-driven cloud attacks using compromised service principals
- 16:02Amazon Slams the door on Meta’s Muse AI Agent
- 16:02Check Point Warns of Active Exploitation of Two Critical Pre-Authentication Vulnerabilities
- 16:02Sovereignty vs Convenience
- 16:02Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
- 16:02Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
- 16:02ISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)
- 16:00IT Security News Hourly Summary 2026-09-25 18h : 11 posts
- 15:31Wiz uses AI to find vulnerabilities in critical infrastructure
- 15:31In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
- 15:31Kothamine malware uses Tailscale’s tailcat to evade network detection
- 15:31Zero-Days, AI Agents, and Identity Attacks Define Cybersecurity Week
- 15:31Critical Roundcube Flaw Under Active Exploitation in Code Injection Attacks
- 15:31Rogue OpenAI agent targeted Australian government site
- 15:31LinkedIn adds new checks for fake profiles and work histories
- 15:31How an OpenAI ‘agent’ hacked Australia’s Medicare and What that Means for Governments Worldwide
- 15:31Businesses expand AI’s cybersecurity uses as comfort with technology grows
- 15:02Which copy of that file is the real one? Dinner, off the record, in Midtown
- 15:00IT Security News Hourly Summary 2026-09-25 17h : 8 posts
- 14:31North Korea Suspected in $351 Million Bitget Crypto Heist
- 14:31Cyber Briefing: 2026.09.25
- 14:31ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
- 14:31Quantum computing’s “dark horse” just proved it can go universal
- 14:02AI Q&A: what is an Agent?
- 14:02Ransomware gangs exploiting critical TeamCity flaw
- 14:02Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
- 14:00IT Security News Hourly Summary 2026-09-25 16h : 15 posts
- 13:33Party Invite Phishing Scams Target Users
- 13:32CenterPoint Energy breach: 7.49M records claimed stolen
- 13:32Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right
- 13:32Rydox marketplace admin pleads guilty
- 13:32North Korean hackers suspected in $351M crypto theft, the largest so far this year
- 13:31Detection dashboards mask security coverage gaps
- 13:31Locking Down the Enterprise: Data Security Patterns for AI Integrations
- 13:31Microsoft Unified Copilot App Launches with Code, Autopilot
- 13:02Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated
- 13:02Criminals turn placeholder domain into ClickFix trap
- 13:02The SOC Doesn’t Need to Start Over with Every Alert
- 13:02CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
- 13:02CISA Unveils Election Security Plan Ahead of 2026 Midterms
- 13:0214-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
- 13:00IT Security News Hourly Summary 2026-09-25 15h : 7 posts
- 12:31Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
- 12:31Been told to pay at a Bitcoin ATM? Read this first
- 12:31Attackers build “silent” cryptominer on victim’s machine and give themselves away
- 12:31Threat detection dashboards are masking security coverage gaps
- 12:02PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
- 12:02Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems
- 12:00IT Security News Hourly Summary 2026-09-25 14h : 8 posts
- 11:31Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
- 11:31On Anthropic’s AI Misuse Report
- 11:02Two-week Europol task force identifies 18 sexually abused children worldwide
- 11:02Windows, Linux, Android File Notification Systems Leak User Activity
- 11:02Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed
- 11:02SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
- 11:02ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
- 11:00IT Security News Hourly Summary 2026-09-25 13h : 7 posts
- 10:31AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
- 10:31CISA Adds Multiple Check Point Product Flaws to Exploited Vulnerabilities List
- 10:31Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
- 10:31CISA Flags WSO2 Security Flaw Under Active Exploitation
- 10:02CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
- 10:02That shipping rebate offer may come with a monthly charge
- 10:00IT Security News Hourly Summary 2026-09-25 12h : 9 posts
- 09:31‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
- 09:31Bitget Hacked: $352M Theft Largest Crypto Heist 2026
- 09:31CrowdStrike Delivers the Next Evolution of the Agentic SOC
- 09:31RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
- 09:31MacSync info-stealing malware hides malicious commands in an iCloud calendar
- 09:31U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
- 09:02Researchers Identify AliExpress Phishing Domains Before Registration
- 09:02CrowdStrike Announces Agentic Identity Provider
- 09:00IT Security News Hourly Summary 2026-09-25 11h : 10 posts
- 08:32Docker introduces OCI-based Kits to package agents and their guardrails
- 08:32Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network
- 08:31Abnormal AI brings governance, cloud security, and threat investigation into one suite
- 08:31Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline
- 08:31Dataiku Agent Management reveals unmonitored AI agents
- 08:31New MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft
- 08:31Fake payroll desktop apps hand attackers a route to company paychecks
- 08:02Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
