A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in…
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that…
National cyber director defends private-sector hacking program, urges focus on security basics
Letting businesses help the government deter cybercrime will benefit all Americans, Sean Cairncross said.
Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular…
MCP Python SDK Flaw Exposes OAuth Credentials
A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth…
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in…
Opsec Fail Leaks a Rare Look Inside a Media-Buy-Powered Scam Operation
Inside the leaked Keitaro-powered backend of a cloaked investment scam targeting South Africa.
Legit Security launches agentic remediation for open-source dependency vulnerabilities
Tel Aviv, Israel, 30th September 2026, CyberNewswire
Six arrests for smuggling migrants via Schengen airports
Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in…
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation…
IT Security News Hourly Summary 2026-09-30 17h : 12 posts
12 posts published in the last hour 14:31Cyber Briefing: 2026.09.30 14:31Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments 14:31Google: AI Is Changing the Pace and Profile of Vulnerability Discovery 14:31The devil is still in the…
Cyber Briefing: 2026.09.30
Executive phishing, browser flaws, and AI-assisted development workflows are creating paths to account compromise, system exploitation, and unintended…
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments
DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last…
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.
The devil is still in the email – but wears a new mask
When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack
Jailbreaking AI: What It Is and Why It Matters for Security
By HOC Team | Updated: October 2026 Read time: ~20 min In March 2023, a researcher posted…
Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks
ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake…
Timeshare exit scams: From fake buyers to recovery fraud
Con artists are targeting timeshare owners who want out – and some victims are hit twice
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise
Oracle launches Fusion Claw AI agentic runtime
Oracle has introduced Fusion Claw, a governed agentic execution runtime designed to automate complex business processes for Oracle Fusion Applications…
Quantum teleportation breakthrough: Scientists crack a 25-year entanglement challenge
Scientists have developed and experimentally demonstrated a long-sought method for identifying W states, an important form of multi-photon quantum…
RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked…
IT Security News Hourly Summary 2026-09-30 16h : 14 posts
14 posts published in the last hour 13:31Signal adds encrypted backups, cross-platform restore 13:31AI Coding Agents Leak 13K Internal Images on GitHub 13:31EU CRA requirements for containers and Kubernetes 13:31WatchGuard Patches Critical Fireware OS Code Injection Vulnerability 13:31US CSuite Phishing…
Signal adds encrypted backups, cross-platform restore
Signal has finished rolling out cross-platform encrypted backup capabilities with iOS version 8.30, enabling users to transfer their complete message…
