Agency’s shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
IT Security News Hourly Summary 2026-09-16 23h : 3 posts
3 posts published in the last hour 20:31Microsoft’s Patching 20:01Revolut Confirms Data Breach Through Fake Government Requests 20:00IT Security News Hourly Summary 2026-09-16 22h : 7 posts
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record : Microsoft’s patch for September is a doozy, with a…
Revolut Confirms Data Breach Through Fake Government Requests
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
IT Security News Hourly Summary 2026-09-16 22h : 7 posts
7 posts published in the last hour 19:31Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe 19:02Museum heists turn violent: new Europol report on cultural property theft tactics 19:02Hackers Exploit Maximum Severity Flaw in GitLab 19:02China’s Answer to AI Safety:…
Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe
An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.
Museum heists turn violent: new Europol report on cultural property theft tactics
The spotlight features some key findings:Increasing violence: Museum thefts are becoming more aggressive, with offenders using tools like sledgehammers,…
Hackers Exploit Maximum Severity Flaw in GitLab
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
China’s Answer to AI Safety: More Controls, Not Slower Development
China is emphasizing technical controls for AI agents as U.S. leaders debate slowing frontier AI, raising new questions for businesses deploying…
Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
Scans Targeting Hospitality Applications, (Wed, Sep 16th)
Earlier today, I noted an odd request showing up in our “First Seen” report:
IT Security News Hourly Summary 2026-09-16 21h : 20 posts
20 posts published in the last hour 18:31Agents of Chaos: A New $100K Agentic Security Challenge 18:31UK.gov begins killing off passwords for 23 million users 18:31OpenSSL 3.0 End of Life 18:31Zero trust is the future. But enterprises still need their…
Agents of Chaos: A New $100K Agentic Security Challenge
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Agents of Chaos: A New $100K Agentic Security Challenge
UK.gov begins killing off passwords for 23 million users
Passkeys promise fewer phishing headaches – and £600 a day off Whitehall’s SMS bill
OpenSSL 3.0 End of Life
The OpenSSL 3.0 series has reached its End of Life (EOL). As such it will no longer receive publicly available security fixes.
Zero trust is the future. But enterprises still need their VPNs.
Zero trust shouldn’t mean sacrificing the stability and flexibility enterprises still depend on.
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search…
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
The ShinyHunters gang leaked the files online after saying the Florida state agency did not pay their ransom demand.
OpenAI Agent Swarm Hacks RubyGems Package Manager
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
Security teams are adopting AI faster than they trust it
New survey data reveals a widening gap between AI adoption and AI trust.
A week in security (September 7 – September 13)
A list of topics we covered in the week of September 7 to September 13 of 2026
US Lawmakers Raise Alarm Over Alleged Hacking by India-Based Firms
Three Indian-based companies have been accused of conducting hacking campaigns and stealing data from thousands of Americans and US businesses, according…
GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
GhostCode is a newly identified phishing kit that turns a normal Microsoft 365 sign-in into an account takeover. It does not need to steal a password.…
Google Pixel phones pwned in zero-click attacks
CISA gives federal agencies just 3 days to patch
