A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks,…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
Bitget Hack Climbs to $387.5 Million as Exchange Launches Recovery Bounty and Points to North Korea
Crypto exchange Bitget confirmed on September 25 that hackers stole approximately $387.5 million from its hot and warm wallets a day earlier, revising an…
Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email…
Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction
A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for participating in a hacking and extortion campaign which…
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit…
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively…
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes…
Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world…
IT Security News Roundup: 2026-09-26
IT Security News: today roundup Manifold Security found AI agent placeholder domains redirecting to scams. Red Hat aligned RHEL 10 automation with DISA security baselines. Lunex malware exploits AMD drivers to steal user browser credentials. The US and China created…
IT Security News Daily Summary 2026-09-26
51 posts published today 20:00IT Security News Hourly Summary 2026-09-26 22h : 4 posts 19:31Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams 19:31Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2 19:01Lunex Stealer…
IT Security News Hourly Summary 2026-09-26 22h : 4 posts
4 posts published in the last hour 19:31Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams 19:31Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2 19:01Lunex Stealer Abuses AMD Driver to Disable Security Monitoring…
Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
Manifold Security found placeholder domains cited in 359,000 GitHub files and 349 AI agent skills serving cloaked scam…
Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2
For the U.S. Department of Defense (DoD) and its contractors, security has to hold up against a published baseline—not a general claim that systems are…
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider…
IT Security News Hourly Summary 2026-09-26 21h : 3 posts
3 posts published in the last hour 18:31China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks 18:02Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection 18:01F-Droid 2.0 Released After 10 years With…
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.
Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
A locally hosted, uncensored artificial intelligence model modified a Windows credential-dumping utility until it evaded two Endpoint Detection and…
F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery
F-Droid has released version 2.0 of its official Android app, delivering its largest client update in a decade. The open-source Android app repository…
AI Agents Can Be Secured. We Can Do It.
Learn of the benefits of safely securing AI agents.
IT Security News Hourly Summary 2026-09-26 19h : 3 posts
3 posts published in the last hour 16:31SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted 16:31OpenAI Agents Accessed US Government Websites Without Authorization 16:02Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
SolarWinds has issued security updates for two critical vulnerabilities in its Observability Self-Hosted product that could enable remote code execution…
OpenAI Agents Accessed US Government Websites Without Authorization
OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed…
