Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents,…
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs…
Switzerland Moves Away From Microsoft 365 to Open-Source Alternatives
Switzerland’s federal administration is preparing to test a sovereign, open-source digital workplace that could reduce its long-term dependence on…
Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance
Microsoft will retire support for Manifest V2 browser extensions in Microsoft Edge by early 2027, requiring users, enterprises, and developers to move to…
HPE Patches Multiple ArubaOS-CX Vulnerabilities
Hewlett Packard Enterprise has released a security advisory for Aruba Networking ArubaOS-CX, warning customers about multiple vulnerabilities affecting…
Natural Resources Wales Exposes Sensitive Employee Data in Spreadsheet Breach
Natural Resources Wales has disclosed a personal data breach involving a spreadsheet containing sensitive diversity information belonging to former and…
Nightwing CEO has a Labor Day message for staff – and apparently The Register
Nothing says ‘For internal use only’ quite like emailing it to the press
Cloudflare and CrowdStrike Bring AI Agents Into the Cyber Defense Fight
Cloudflare is using OpenAI GPT-5.6 Cyber to automate vulnerability discovery and remediation as AI agents reshape enterprise security operations.
IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers
Identity verification company IDScan is being sued in multiple cases after hackers allegedly gained unauthorized access to the service and started selling…
CrowdStrike Investigates FalconFlank Zero-Day as PoC Reaches SYSTEM
CrowdStrike is investigating FalconFlank, a privilege-escalation PoC that can reach SYSTEM access. Here’s what defenders should disable and monitor.
IT Security News Hourly Summary 2026-09-07 17h : 6 posts
6 posts published in the last hour 14:31LG TV flaws could let attackers listen in, even in standby mode 14:31NCSC Warns Shadow AI Creates New Security Risks 14:31Attackers use rogue ScreenConnect clients to spread malware 14:31Chaotic Eclipse Released A PoC…
LG TV flaws could let attackers listen in, even in standby mode
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
NCSC Warns Shadow AI Creates New Security Risks
NCSC warns unapproved AI tools can expose corporate data and create new security risks
Attackers use rogue ScreenConnect clients to spread malware
A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A…
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known…
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska,…
IT Security News Hourly Summary 2026-09-07 16h : 8 posts
8 posts published in the last hour 13:31PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells 13:31Hackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guys 13:31NoName057(16) Renews #OpJapan 13:02Telerik UI Padding-Oracle Bug Chained to…
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
A sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with…
Hackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guys
Self-described white hats promise to return ‘most’ of the 4,000 BTC once the vulnerability is fixed
NoName057(16) Renews #OpJapan
On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform,…
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against…
Your Cloud Security Checklist Doesn’t Work the Way You Think It Does
If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder…
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script…
