AmnesiaStealer, a multi-stage macOS infostealer written in Rust that moves beyond conventional credential theft by giving attackers covert, interactive…
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security…
AI agents taking unsanctioned action during cyber testing
The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and…
IT Security News Hourly Summary 2026-08-24 10h : 14 posts
14 posts published in the last hour 07:32Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund 07:32Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution 07:31Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain…
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.
Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution
A critical security flaw in the popular Node.js sandboxing library isolated-vm could allow untrusted JavaScript to escape its V8 sandbox and potentially…
Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete…
Museum heists turn violent: new Europol report on cultural property theft tactics
The spotlight features some key findings:Increasing violence: Museum thefts are becoming more aggressive, with offenders using tools like sledgehammers,…
DOUBLECUP’s PNG Payload, (Mon, Aug 24th)
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#;x26;#;39;t…
China Firms Optimise Inference To Slash AI Compute Needs
Chinese companies turn to novel approach that splits single AI task among domestic, Nvidia GPUs to reduce compute requirements
UK power plant hack, AI zero click, children’s hospital breach
UK power plant disabled for four days by Iran-linked hackers Zero-click Grok and Gemini chat history theft possible through cryptographic context…
A week in security (August 17 – August 23)
A list of topics we covered in the week of August 17 to August 23 of 2026
Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks
Malicious npm packages are being used to place a Linux backdoor inside calendar and streak-calculation tools. The packages deliver legitimate date…
AWS Network Firewall Adds Rule Hit Counts to Identify Unused Security Rules
AWS has introduced a new capability for AWS Network Firewall that tracks rule hit counts, providing security teams with direct visibility into how often…
Cybermes – AI Red Teaming Agent for Automated Penetration Testing
A new open-source project called Cybermes has entered the crowded field of AI-powered offensive security tooling, positioning itself as an…
macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner
A macOS-focused ClickFix campaign is abusing Polygon smart contracts to conceal its live command-and-control infrastructure while deploying an Atomic…
AWS Network Firewall Now Displays Count of Triggered Security Rules
AWS has introduced rule hit count support for AWS Network Firewall, giving security teams direct visibility into which stateful firewall rules are…
IT Security News Hourly Summary 2026-08-24 09h : 6 posts
6 posts published in the last hour 06:31First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet 06:02New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File 06:02Critical isolated-vm Flaw Lets Attackers Escape Sandbox…
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and…
New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File
A criminal service is hiding behind a website that appears to offer Adobe Acrobat Reader. The site, acrobatreaderonline.com, is not a document service.…
Critical isolated-vm Flaw Lets Attackers Escape Sandbox and Hijack Host Control Flow
A critical vulnerability has been discovered in the widely used Node.js sandboxing library, isolated-vm. This flaw could potentially allow untrusted…
Product showcase: AI Paper Trail shows the privacy cost of talking to AI
Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or…
RedC2 Turns Compromised Linux Machines Into SOCKS5 Proxies for Internal Network Pivoting
A cluster of trojanized npm packages is delivering the RedC2 4.0 Linux implant, providing operators with a pathway from a seemingly harmless dependency…
IT Security News Hourly Summary 2026-08-24 08h : 4 posts
4 posts published in the last hour 05:31Fake bank websites play dead to evade security scanners 05:31Iran-Linked Hackers Shut Down UK Power Plant for Four Days in Cyberattack 05:02Ransomware attackers are zeroing in on mid-market companies 05:02Anthropic Brings Claude Mythos…