15 posts published in the last hour 13:03NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity 13:03Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks 13:03How to Use BloodHound Active Directory Setup Attack Path Analysis 13:02F5…
NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity
NeuroCyber, the organisation dedicated to improving opportunities and career outcomes for neurodivergent individuals across the cybersecurity profession,…
Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS…
How to Use BloodHound Active Directory Setup Attack Path Analysis
By HOC Team | Last updated: September 10, 2026 | Read time: ~24 min How to Use BloodHound…
F5 BIG-IP APM Malware Installs a PHP Web Shell Into Memory, Escaping Disk Scans
Sophos X-Ops has found an advanced Linux rootkit that can conceal a PHP web shell completely in server memory, which makes it harder for traditional…
Xiaomi Launches Foldable To Compete With Upcoming iPhone
Beijing-based Xiaomi launches 18 Fold wide-format foldable smartphone, as companies flock to popular category
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Nearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating…
PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA
PEEP turns browsers into backdoors Liquid loses $320M, hackers play hero BigBear claws past MFA Get the full show notes here:…
Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes
Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks.…
Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited…
How to Disable Root Login via SSH: Step-by-Step Guide (2026)
By HOC Team | Last updated: September 08, 2026 | Read time: ~12 min How to Disable Root…
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography
The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram…
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update
A significant security update was released by Microsoft on Patch Tuesday in September, addressing 974 vulnerabilities across the company’s software…
LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials
LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run…
IT Security News Hourly Summary 2026-09-10 15h : 11 posts
11 posts published in the last hour 12:31FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors 12:31Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone 12:31Australia To Let Users Switch Off Social Media Algorithms 12:31Critical…
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
Skullcandy Dime 3 wireless earbuds have a serious vulnerability related to unauthenticated Bluetooth pairing. This flaw allows nearby attackers to…
Australia To Let Users Switch Off Social Media Algorithms
Draft ‘duty of care’ legislation to be proposed this week would give users choice of whether to use platforms’ algorithms
Critical NetScaler Vulnerability Exploited in Attacks
Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.
Will AI kill us all within the next decade?
AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.
Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O archive parser could allow a malicious static library to crash Xcode build…
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to…
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain…