The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years…
Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps
Splunk has released security updates for 17 vulnerabilities affecting several apps and add-ons, including Splunk MCP Server, Splunk AI Toolkit, and Splunk…
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview…
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan
U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S.…
New “Zombie Card” Flaw Lets Expired Visa Cards Make Contactless Payments
Security researchers have demonstrated that an expired credit card is not as dead as most cardholders believe. A new study from the University of…
IT Security News Hourly Summary 2026-08-20 12h : 10 posts
10 posts published in the last hour 09:31Fractile Seeks $6.5bn Valuation In New Funding Round 09:31OpenAI previews privacy-focused system for detecting AI misuse 09:31CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access 09:31US agencies warn of AI-powered attacks on…
Fractile Seeks $6.5bn Valuation In New Funding Round
London-based AI inference chip start-up reportedly raising about $600m at value roughly six times that of previous round in May
OpenAI previews privacy-focused system for detecting AI misuse
OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become…
CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access
Researchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker…
US agencies warn of AI-powered attacks on Siemens industrial controllers
Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water,…
Hackers Trick AI Agents Into Telling Users to Install the Malware Themselves
A supply-chain campaign targeting OpenClaw has shown how threat actors can turn autonomous AI agents into persuasive malware-delivery intermediaries.…
AI GP Receptionist Struggles With Yorkshire Accents
AI system brought in to cut down wait times in some Yorkshire GP surgeries unable to understand some local accents, says group
Claude AI Finds Authentication Bypass Flaws in Multiple SAML Implementations
Multiple critical vulnerabilities in SAML implementations after employing Anthropic’s Claude Code in an AI-assisted vulnerability research pipeline.…
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.
Zimbra RCE Vulnerability Lets Remote Attackers Execute System Commands
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise…
IT Security News Hourly Summary 2026-08-20 11h : 9 posts
9 posts published in the last hour 08:31ClearFake Fake CAPTCHA Campaigns Use New WordlistLoader to Deploy Amatera Stealer 08:31Yorkshire Village To Get 98-Foot 5G Mast 08:02US Charges Iranians With University Hacks 08:02Claude AI Finds SAML Security Flaws That Can Let…
ClearFake Fake CAPTCHA Campaigns Use New WordlistLoader to Deploy Amatera Stealer
A new ClearFake infection chain using a previously undocumented intermediate payload dubbed WordlistLoader to deploy Amatera Stealer. The campaign…
Yorkshire Village To Get 98-Foot 5G Mast
Infrastructure operator Cornerstone wins approval for 98-foot tower providing 2G, 3G, 4G and 5G services in Nether Poppleton
US Charges Iranians With University Hacks
Seventeen Iranians charged with carrying out hacks on thousands of academic, government and private groups around the world in long-running campaign
Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts
Security researchers have used Anthropic’s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations that could…
Critical GitLab Flaw Exploited Shortly After Disclosure
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation
Tufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain…
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check…