10 posts published in the last hour 14:31Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing 14:31Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code 14:31Legacy Lenovo login opens 5,000 Dropbox…
Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing
Observations have shown that threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails, with attacks moving beyond…
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a…
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Cloud storage biz severs old integration and urges victims to reset credentials
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by…
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud
Beyond Agent-Washing: The Engineering Principles Behind Production-Ready AI Agents
An AI agent is not defined by how intelligently it talks. It’s defined by what it’s trusted to do. Give a language model a chat window, and you have an…
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a…
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to…
IT Security News Hourly Summary 2026-09-02 16h : 19 posts
19 posts published in the last hour 13:32Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) 13:32Anthropic: Infostealer Malware Hacks Claude Sessions to Drain Consumption Usage 13:32Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection 13:32Scammers are…
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans…
Anthropic: Infostealer Malware Hacks Claude Sessions to Drain Consumption Usage
Anthropic has warned Claude users that infostealer malware on their systems has stolen active Claude login sessions, letting threat actors to log into…
Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection
Security researcher has disclosed a technique used by the Singularity Linux rootkit to evade Elastic Defend by suppressing module-load telemetry to avoid…
Scammers are getting smarter about where they target you
New Malwarebytes research reveals how different scams are tailored to different platforms.
$536 and 8 Hours: AI Learns to Attack a Different PLC
Experts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout…
FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately
FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users…
Norway considers ban on camera-enabled wearable ‘pervert glasses’
The Nordic country says wearable camera headsets need to be regulated given their privacy risks.
AI Observability Must Evolve for the Agentic Era
In this article Traditional observability tells you whether software worked. For AI agents, the harder question is whether the system made the right…
Download: The Agentic Software Development Guide
AI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail…
Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers
Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full…
255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance…
Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials
Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI…
Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers
Mozilla has introduced a built-in ad blocker for Firefox on iOS, providing iPhone users with a native option to block many third-party advertisements and…
