A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs,…
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL…
IT Security News Hourly Summary 2026-09-24 12h : 5 posts
5 posts published in the last hour 09:02Google’s location data privacy failures draw a €403 million fine 09:02New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network 09:02September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical…
Google’s location data privacy failures draw a €403 million fine
Turning off Location History did not necessarily stop Google from recording where users went. Ireland’s privacy regulator has now fined the company €403…
New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
AvisLoader, a newly observed Windows malware loader designed to maintain operator access even when conventional command-and-control infrastructure is…
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
IT Security News Hourly Summary 2026-09-24 11h : 10 posts
10 posts published in the last hour 08:32Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds 08:31Apple’s new iOS 27 feature looks for signs you’re being scammed 08:31TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords 08:31Government…
Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds
SANS Institute report claims data rather than skills is now the main hurdle for threat hunters
Apple’s new iOS 27 feature looks for signs you’re being scammed
Apple introduced a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature allows supported apps to request a…
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts…
Government contractor exposed path to immigration records
IT took a shortcut when the boss was away, and it led to danger!
GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany…
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister…
Claude.ai is about 3x faster after 3,000+ changes
Anthropic engineers made claude.ai and the Claude desktop app roughly three times faster during a two-week sprint in August, with Claude finding the…
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is…
Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
An Integrated Security Operations Center (ISOC) in Microsoft Defender, unifying security information and event management (SIEM) and threat-protection…
IT Security News Hourly Summary 2026-09-24 10h : 6 posts
6 posts published in the last hour 07:31RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials 07:31Critical WordPress Vulnerability Exploited Immediately After Disclosure 07:31ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon’s cyber appetite grows…
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East,…
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon’s cyber appetite grows
ShinyHunters peeks at FBI assignments WordPress flaw wastes no time Pentagon’s cyber appetite grows Get the show notes here:…
Protecting citizens, preserving rights
How can law enforcement make effective use of data and technology while ensuring that fundamental rights and the rule of law remain protected? This…
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation. This flaw could…
IT Security News Hourly Summary 2026-09-24 09h : 7 posts
7 posts published in the last hour 06:31One URL, Three Different Tricks, (Thu, Sep 24th) 06:31New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group 06:31OpenAI Releases Lower-Cost Sol, Luna Models 06:31CLOSEDQUORUM, the malware that asks four AI models…
