Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary…
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that…
CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the…
IT Security News Hourly Summary 2026-08-25 12h : 8 posts
8 posts published in the last hour 09:31Crooks push Mac malware through fake OpenAI Codex ads 09:31ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack 09:31US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks 09:02Anthropic Expands Claude MCP…
Crooks push Mac malware through fake OpenAI Codex ads
Sponsored search results lead developers straight into a ClickFix malware trap
ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a…
US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
The US has sanctioned individuals connected to hacking-for-hire group the Mabna Institute
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing…
Anthropic Rolls Out Enterprise-Managed Auth for Claude’s MCP Connectors
Anthropic has taken its Model Context Protocol (MCP) connector framework a significant step further, announcing on August 24, 2026, that…
Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers…
Fake GTA 6 Demo Is Actually Malware That Steals Your Passwords and Logged-In Sessions
A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access. The campaign turns…
IT Security News Hourly Summary 2026-08-25 11h : 7 posts
7 posts published in the last hour 08:31Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover 08:31TikTok phishing: How to spot fake login and verification pages 08:31Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac…
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard…
TikTok phishing: How to spot fake login and verification pages
Scammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.
Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into…
CISA Warns of Exploited Oracle WebLogic Vulnerability
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs…
78 arrests in bust of major Western Mediterranean smuggling network in Spain
The operation, conducted under a newly established Europol Taskforce within Europol’s European Centre Against Migrant Smuggling, brought together officers…
IT Security News Hourly Summary 2026-08-25 10h : 12 posts
12 posts published in the last hour 07:31China Approves Limited Imports Of Nvidia’s H200 07:31SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing 07:31Top Google Results for Minecraft Client Led Gamers to Malware, McAfee…
China Approves Limited Imports Of Nvidia’s H200
Large Chinese tech groups begin receiving shipments of H200 AI chips, as regulators seek to boost domestic AI development
SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing
SynkLoader throws in the kitchen sink NIST flags multi-cloud sprawl ReliaQuest blocks a ShinyHunters swing Get the show notes here:…
Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds
Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks
TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The…