Amazon thinks it knows your body, your family, and your life. You didn’t sign up for it, and we couldn’t find a way to opt-out.
Middle managers want tighter human oversight of AI than their bosses, TeamViewer research finds
Executives may be more relaxed about handing IT decisions to AI than the managers who answer to them, according to new research from TeamViewer. The study…
What Is Agentic Pentesting? What It Proves, and Where It Stops.
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it…
Hackers exploit critical Atlassian flaw after public PoC release
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in…
Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls
The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and…
It Wasn’t Me, It Was the AI Agent” May Not Avoid Liability Under New Senate Proposal
Odia Kagan of FoxRothschild writes: “It wasn’t me, it was the AI agent” may not help companies avoid civil or criminal liability under a new bipartisan…
Context Over Alerts: SOC Evolution Strategy
Security operations centers face a fundamental challenge that more alerts cannot solve.
US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward
Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive…
Europol and US GAO Warn of Quantum Computing Threats
Europe’s leading law enforcement agency and the US government’s spending watchdog released reports this week urging organizations to accelerate adoption…
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. […]
Ransomware Recovery Scheme Nets $11M Markup
A ransomware recovery operator has been exposed for running a scheme that generated $11 million in markups by secretly paying ransoms and reselling…
Microsoft Teams to get support for third-party deepfake detection tools
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. […]
Oracle Health breach affects nearly 20M
Oracle Health has confirmed that a data breach impacted approximately 20 million individuals, marking a substantial increase from figures reported in…
IT Security News Hourly Summary 2026-10-08 15h : 32 posts
32 posts published in the last hour 12:32CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026 12:32Verify it, don’t assume it: why untested security controls are making life easy for attackers 12:31Telegram Account Behind ASOS Rogue…
CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
Verify it, don’t assume it: why untested security controls are making life easy for attackers
This year’s Cybersecurity Awareness Month theme, “Don’t Make It Easy for Them”, is usually read as advice for individuals. Cynthia Overby, director of…
Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
A Group-IB researcher has found the Telegram account linked to the unauthorized ASOS customer notification previously engaged in gaming-item trading
AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes
BlueKit puts account-hijacking tools in more criminals’ hands, making it easier to target you with convincing fake login pages and scam messages.
16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys during wallet imports. Disguised as…
KR: Coupang files lawsuits against 620 billion won fine over data leak
The Coupang breach in South Korea has stayed in the news cycle for nine months and may offer a useful case study in how not to respond to an incident. In…
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an…
Encrypted instructions trick Copilot CLI into spilling developer secrets
GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security…
