Cybercriminals are increasingly hijacking Node.js, the widely used JavaScript runtime, to slip malicious code past security defenses, according to new…
IT Security News Hourly Summary 2026-09-03 14h : 12 posts
12 posts published in the last hour 11:31Attackers Exploit CVE-2026-82329 to Forge JFrog Artifactory Admin Tokens 11:31I’ve been deepfaked: What do I do? 11:31HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning 11:31Attackers Turn Trusted Node.js Runtime Into Malware…
Attackers Exploit CVE-2026-82329 to Forge JFrog Artifactory Admin Tokens
Cybersecurity researchers have observed attackers exploiting a critical JFrog Artifactory vulnerability shortly after its public disclosure. The flaw…
I’ve been deepfaked: What do I do?
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning
QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from…
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new…
Researching Employment Scams
Researchers built a fake company to study fake employee scams .
Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This…
Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations…
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
153 Million Driver License Images Offered on Dark Web
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
Russian man indicted for spreading malware to 80,000 freelancers
A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by…
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and…
IT Security News Hourly Summary 2026-09-03 13h : 10 posts
10 posts published in the last hour 10:31Uber, Wayve Offer First Paid London Robotaxi Rides 10:31Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank 10:31Google, Anthropic, and OpenAI Unveil Advanced Cyber AI Models, Defense Programs, and Safety Controls 10:31This Is Flock’s AI Search…
Uber, Wayve Offer First Paid London Robotaxi Rides
Paid autonomous taxi rides go live on Uber’s app in London, as UK AI start-up makes worldwide commercial debut
Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank
Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic…
Google, Anthropic, and OpenAI Unveil Advanced Cyber AI Models, Defense Programs, and Safety Controls
AI is quickly changing the way we approach cybersecurity. Google, Anthropic, and OpenAI are now developing new Cyber…
This Is Flock’s AI Search Tool for Cops
WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for…
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations.
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone
The iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to new findings from the…
FBI Probes Possible Breach of 153 Million Driver’s Licenses
The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web
CISA Warns of SonicWall SMA1000 Vulnerabilities Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added two SonicWall SMA1000 appliance vulnerabilities to its Known Exploited Vulnerabilities…
Google Spared Adtech Sell-Off In Monopoly Ruling
US federal judge approves limited behavioural remedies, rejecting break-up of Google’s illegal adtech monopoly
IT Security News Hourly Summary 2026-09-03 12h : 18 posts
18 posts published in the last hour 09:322,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators 09:32UK’s Online Safety Act has made ‘absolutely no difference,’ kids say 09:32WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into…
