Reco report reveals growing shadow AI problem and surge in vulnerability disclosures
Russia-Linked Operators Used ChatGPT to Run a Secretive Online Influence Campaign
OpenAI has disrupted a covert influence operation that used ChatGPT to promote a purported Israeli think tank, spread Russia-favorable narratives, and…
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote,…
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to…
Nutex Health Data Breach Investigation
Nutex Health has reportedly suffered a network security incident classified as a hacking or IT breach, according to an SEC filing dated August 24, 2026.
Adobe and Nvidia Patch Dozens of Vulnerabilities
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.
Microsoft urges network-level containment as patch windows
Microsoft has issued guidance urging enterprises to adopt network-level containment strategies as the window between vulnerability disclosure and active…
Treasury to help financial firms transition to quantum-resistant encryption
The government is concerned that hackers someday will be able to decrypt financial information and other secrets using code-breaking quantum computers.
Interpol Jackal IV disrupts West African crime
Interpol has concluded Operation Jackal IV, a coordinated international law enforcement effort spanning 21 countries that targeted West African cybercrime…
Stopping the AI Agent Actions No Rule Could See Coming
Check Point introduces a new class of contextual AI protection that understands an agent’s full context, intent and behavior across multiple steps, and…
Meta Enhances WhatsApp Security Features
Meta has rolled out three new security features for WhatsApp aimed at strengthening account protection and helping users identify potentially suspicious…
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen…
Cyble and DRONA Launch AI Cyber Defense Initiative
Cyble and DRONA Cyber Solutions formally launched an AI-powered cyber defense initiative Tuesday at DRONA’s Command and Control Centre in Ahmedabad,…
IT Security News Hourly Summary 2026-08-26 15h : 10 posts
10 posts published in the last hour 12:31Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware 12:31SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root 12:31Spyware for Babies 12:31Popular school apps may be sharing…
Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware
Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access…
SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that…
Spyware for Babies
The New York Times has a long article ( alt link ) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to…
Popular school apps may be sharing student data with advertisers
A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages
Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing pages. The campaign does not…
Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code
WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary…
Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2
A fake Claude Desktop installer campaign is using Bing malvertising to impersonate trusted Claude. ai-hosted content, DLL sideloading, and…
Average Cyber Insurance Losses Increase Despite Fewer Claims
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we’ve always known was built around a model that guarantees most of the alert queue will never receive analyst review. There’s never time. In a…
IT Security News Hourly Summary 2026-08-26 14h : 11 posts
11 posts published in the last hour 11:31Why Provision 29 is raising the bar for board accountability 11:31The MFA Identity Trap: When Authentication Creates a False Sense of Security 11:31Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 11:31CISA: Over…