Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to…
Exploits and vulnerabilities in Q2 2026
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in…
Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This…
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6,…
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to…
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which…
Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator…
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents…
Chrome 152 Patches Over 300 Vulnerabilities
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.
Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best…
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password
Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The…
IT Security News Hourly Summary 2026-08-26 12h : 15 posts
15 posts published in the last hour 09:32NVIDIA NemoClaw Flaw Lets Attackers Hijack AI Agents With One Website Visit 09:31The Planting Seeds philosophy. Selling into schools takes years, not quarters 09:31Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor…
NVIDIA NemoClaw Flaw Lets Attackers Hijack AI Agents With One Website Visit
A critical vulnerability in NVIDIA NemoClaw that could let attackers hijack an AI agent after a victim visits a malicious website. The issue, tracked as…
The Planting Seeds philosophy. Selling into schools takes years, not quarters
It’s tempting for MSPs to write off event sponsorship in education as a waste of money. You sponsor an event, hand out flyers, follow up with an email,…
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno…
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States…
Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code…
Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities
Google has released Chrome 152 for Windows, macOS, and Linux, delivering 327 security fixes and improvements. The update addresses 10 critical…
DDoS Attack Hits Norwegian Government Services
A coordinated DDoS campaign has caused disruption among Norwegian government services
28,000 Exposed Git Repositories Reveal API Keys, Bank Details and Employee Disciplinary Files
A routine development mistake has exposed thousands of software repositories. Researchers found 28,000 publicly reachable .git repositories containing…
88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report…
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a…
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…