Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to…
Enterprise AI Coding Adoption Fuels Open-Source Security Debt
As artificial intelligence coding tools are rapidly adopted, development teams are able to develop software more quickly, however, cybersecurity teams are…
Not the Coyote, but the Road Runner: The Reality of Autonomous AI Attacks
Autonomous AI security threats aren’t novel super-weapons. They’re relentless, low-tech attacks that never stop. Learn why traditional defenses fail.
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool
Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels
Iran-linked hackers have expanded an espionage effort with a Windows backdoor and reverse SSH tunnelling utility. The activity is tied to Tortoiseshell,…
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against…
Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers
Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into…
Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects
Interpol operation leads to 58 arrests and identifies 263 suspects across 22 countries
IT Security News Hourly Summary 2026-08-26 16h : 17 posts
17 posts published in the last hour 13:31New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode 13:31Update Chrome before you browse again 13:31Critical Gitea flaw exploited in code injection attacks 13:31Four in Five AI Tools Run…
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a…
Update Chrome before you browse again
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them.
Critical Gitea flaw exploited in code injection attacks
The U.S.
Four in Five AI Tools Run with No IT Oversight, New Research Finds
Reco report reveals growing shadow AI problem and surge in vulnerability disclosures
Russia-Linked Operators Used ChatGPT to Run a Secretive Online Influence Campaign
OpenAI has disrupted a covert influence operation that used ChatGPT to promote a purported Israeli think tank, spread Russia-favorable narratives, and…
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote,…
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to…
Nutex Health Data Breach Investigation
Nutex Health has reportedly suffered a network security incident classified as a hacking or IT breach, according to an SEC filing dated August 24, 2026.
Adobe and Nvidia Patch Dozens of Vulnerabilities
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.
Microsoft urges network-level containment as patch windows
Microsoft has issued guidance urging enterprises to adopt network-level containment strategies as the window between vulnerability disclosure and active…
Treasury to help financial firms transition to quantum-resistant encryption
The government is concerned that hackers someday will be able to decrypt financial information and other secrets using code-breaking quantum computers.
Interpol Jackal IV disrupts West African crime
Interpol has concluded Operation Jackal IV, a coordinated international law enforcement effort spanning 21 countries that targeted West African cybercrime…
Stopping the AI Agent Actions No Rule Could See Coming
Check Point introduces a new class of contextual AI protection that understands an agent’s full context, intent and behavior across multiple steps, and…
Meta Enhances WhatsApp Security Features
Meta has rolled out three new security features for WhatsApp aimed at strengthening account protection and helping users identify potentially suspicious…
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen…