12 posts published in the last hour 09:31Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer 09:31Europol celebrates the International Day of Police Cooperation 09:31Four AI Agent Security Risks Organisations Can’t Afford to Ignore 09:31Plugin4Shell Zero-Click RCE…
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as…
Europol celebrates the International Day of Police Cooperation
On 7 September, Europol is marking the International Day of Police Cooperation together with its partners to recognise the central role our network plays…
Four AI Agent Security Risks Organisations Can’t Afford to Ignore
AI agents are quickly moving from experimentation into everyday business operations. Unlike traditional generative AI tools that wait for a user to ask a…
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace…
Filigran, CyberASAP and Pulse Conferences Unite to Champion Cybersecurity’s Unsung Heroes
London, UK – 18th September 2026 –Eskenzi PR, the cybersecurity PR agency, are pleased to announce that Filigran, the European open-source threat…
Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication
Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik…
Android apps can now check security patches down to individual device components
New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0…
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.…
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an…
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
Arcjet brings security controls and audit trails to AI agents
Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams…
IT Security News Hourly Summary 2026-09-18 11h : 9 posts
9 posts published in the last hour 08:3112 Best CDR Solutions Compared (2026): Features & Pricing 08:31Fake parcel delivery messages steal your card and bank details 08:3112 Best SSPM Tools Compared (2026): Features & Pricing 08:31Manufacturing Accounts for 22% of…
12 Best CDR Solutions Compared (2026): Features & Pricing
Quick Answer: Cloud detection has a real free floor Falco (OSS, on this list in its own right) plus usage-priced native services (GuardDuty-class) so paid…
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.
12 Best SSPM Tools Compared (2026): Features & Pricing
Quick Answer: SSPM bills two ways per employee (predictable, punishes big headcount) or per connected app (bounded, punishes SaaS sprawl) and your…
Manufacturing Accounts for 22% of all Ransomware Victims
Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026
12 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing
Quick Answer: Multi-cloud doesn’t just triple your attack surface it triples your billing surface, and vendors price the same workload differently per…
Buying or selling a second-hand phone? How to protect your personal data
Buying or selling a used phone can be safe – but only if you wipe the old device properly and reset any phone you receive…
Slow is a design principle, not a delay
Two things happened last week, one day apart, and almost nobody connected them. On 11 September, the EU Cyber Resilience Act’s vulnerability reporting…
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST…
IT Security News Hourly Summary 2026-09-18 10h : 8 posts
8 posts published in the last hour 07:31Beware the SparroWock: The backdoor that bites, the commands that catch 07:31Nuclear-style AI safeguards, AI legislation shelved, CISA’s decoy guidance 07:31MIND Secures $72 Million for AI-Powered DLP 07:31AI Cloud Firm Nebius Hikes GPU,…
Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
Nuclear-style AI safeguards, AI legislation shelved, CISA’s decoy guidance
Nuclear-style safeguards proposed for AI risks Key lawmaker suggests action on AI safety legislation will wait until 2027 CISA releases cyber decoy…
