Officials discussed setting up a mechanism for the two countries to notify each other of AI incidents which could threaten national security.
ShinyHunters hacks rival extortion gang and takes over its dark web site
Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.
IT Security News Hourly Summary 2026-09-21 13h : 17 posts
17 posts published in the last hour 10:32Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO 10:31TerminalFix: PNG Steganography, (Mon, Sep 21st) 10:31Hackers Hide Malware Servers on Blockchain to Steal Bank Logins and 2FA Codes 10:31From Exposure to Lockdown: How…
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active…
TerminalFix: PNG Steganography, (Mon, Sep 21st)
Microsoft Security Research published an interesting blog post “TerminalFix campaign deploys a reverse tunnel through multistage intrusion” about a…
Hackers Hide Malware Servers on Blockchain to Steal Bank Logins and 2FA Codes
A new malware campaign is using blockchain technology to keep its control servers out of reach. The operation tricks visitors to compromised business…
From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.
Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware
Hackers are exploiting a critical cPanel and WHM flaw to place Mirai malware on exposed servers, extending a botnet threat normally associated with…
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
MSNightmare has Released a Windows Defender Update DoS Vulnerability Called BigDiskBuster
Security researcher MSNightmare, also known as Nightmare-Eclipse, has released BigDiskBuster, a proof-of-concept denial-of-service technique designed to…
Top 10 Best Identity & Access Management (IAM) Solutions in 2026
Quick Answer: Microsoft Entra ID wins on bundled value inside M365 estates; Okta wins on neutrality and app-catalog breadth; Ping Identity (which now…
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
A breach at image-sharing service Gyazo on September 11 affected over 23 million customers
Top 10 Best Privileged Access Management (PAM) Solutions in 2026
Quick Answer: CyberArk remains the enterprise PAM benchmark; BeyondTrust and Delinea complete the leader trio; ManageEngine PAM360 wins value; HashiCorp…
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection
Hackers are using a layered Windows malware chain to run an XMRig cryptocurrency miner while keeping its key parts out of sight. The operation hides code…
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning…
OpenAI Codex Sandbox Flaws Let Malicious Repositories Execute Commands on Host Systems
OpenAI Codex recently faced two significant security vulnerabilities that allowed malicious repositories to potentially execute commands on a developer’s…
Siemba brings continuous IDOR testing to production APIs
Siemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST,…
Hackers Can Manipulate Web Cache Keys to Access Restricted Data and Poison Websites
A web cache poisoning technique called cache key injection could let attackers access restricted data, disrupt websites, or poison cached pages with…
IT Security News Hourly Summary 2026-09-21 12h : 16 posts
16 posts published in the last hour 09:32Top 10 Best Multi-Factor Authentication (MFA) Solutions in 2026 [Ranked & Scored] 09:32Hackers exploit Gyazo server flaw to steal 23.6 million user records 09:32SIRIUS SPoC network meets as EU enters new era for…
Top 10 Best Multi-Factor Authentication (MFA) Solutions in 2026 [Ranked & Scored]
Push-bombing, real-time phishing kits, and helpdesk social engineering broke “any MFA is fine.” The 2026 question is which MFA survives an attacker who…
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in…
SIRIUS SPoC network meets as EU enters new era for electronic evidence
The 7th SIRIUS Single Point of Contact (SPoC) Network Meeting, organised by Europol’s EU Internet Referral Unit (EU IRU) together with the German Federal…
More CVEs than ever. The same old ones keep getting exploited.
Vulnerability volume is climbing fast. The exploited ones are old and already patchable.
