Siemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST,…
Hackers Can Manipulate Web Cache Keys to Access Restricted Data and Poison Websites
A web cache poisoning technique called cache key injection could let attackers access restricted data, disrupt websites, or poison cached pages with…
IT Security News Hourly Summary 2026-09-21 12h : 16 posts
16 posts published in the last hour 09:32Top 10 Best Multi-Factor Authentication (MFA) Solutions in 2026 [Ranked & Scored] 09:32Hackers exploit Gyazo server flaw to steal 23.6 million user records 09:32SIRIUS SPoC network meets as EU enters new era for…
Top 10 Best Multi-Factor Authentication (MFA) Solutions in 2026 [Ranked & Scored]
Push-bombing, real-time phishing kits, and helpdesk social engineering broke “any MFA is fine.” The 2026 question is which MFA survives an attacker who…
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in…
SIRIUS SPoC network meets as EU enters new era for electronic evidence
The 7th SIRIUS Single Point of Contact (SPoC) Network Meeting, organised by Europol’s EU Internet Referral Unit (EU IRU) together with the German Federal…
More CVEs than ever. The same old ones keep getting exploited.
Vulnerability volume is climbing fast. The exploited ones are old and already patchable.
Top 10 Best Single Sign-On (SSO) Solutions in 2026
Quick Answer: Microsoft Entra ID is the bundled default for M365 estates; Okta leads neutral catalog breadth; Ping Identity owns complex enterprise;…
Revolut Customers Targeted with New Wave of Phishing Attacks
Following a major data breach, Revolut customers are being sent convincing phishing messages
North Korean WaterPlum Hackers Infect 30,000 PCs via Fake Job Interviews, Steal $10.7M Crypto
North Korean-linked WaterPlum operators have turned job hunting into a route for theft. By posing as recruiters, they persuaded software developers to run…
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into…
New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN
A newly identified Android banking Trojan called RatHat uses phone features for account theft. The malware can guide itself through an infected device,…
Security’s 30-year habit: layering around the problem
The nurse isn’t careless. Every safe path is slower than Outlook.
Top 10 Best Identity Governance & Administration (IGA) Tools in 2026
Quick Answer: SailPoint remains the IGA benchmark with AI-driven certifications; Saviynt leads cloud-native converged governance; Microsoft Entra ID…
The Target Is No Longer the Model. It’s the Agent.
AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI…
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized…
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has…
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached…
IT Security News Hourly Summary 2026-09-21 11h : 5 posts
5 posts published in the last hour 08:31HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise 08:02Month-Old UK Start-Up Achieves Nearly $4bn Valuation 08:02Your bank is calling, but is it really your bank? How impersonation…
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote…
Month-Old UK Start-Up Achieves Nearly $4bn Valuation
‘World model’ start-up Emulate, founded by former Google DeepMind researchers, reportedly raising $700m at $3.7bn valuation
Your bank is calling, but is it really your bank? How impersonation scams work
Receiving a call or email that appears to come from your bank can be unsettling. The message may warn that someone accessed your account, a…
UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns
A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has…
IT Security News Hourly Summary 2026-09-21 10h : 8 posts
8 posts published in the last hour 07:31New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets 07:31India’s Second-Phase Semiconductor Push Attracts $12bn 07:31Google Confirms Gemini AI Breached Three Firms 07:31A week in security (September 14 –…
