A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web…
Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership
Authority in podcasting is earned slowly and lost fast. Any host can launch a show. Building a reputation that makes listeners return for your take, over…
CISA lays out new guidance for using open-source software
The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which…
AI Agents Can Pay. Can They Prove They Had Permission?
AI agents can make payments, but can they prove consent? Explore mandates, fraud controls, accountability and trust in the rise of agentic commerce.
Device Code Phishing Is How Midnight Blizzard Beat MFA on Hotel Wi-Fi
A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here’s how it works and how to shut…
Qodana 2026.2 adds post-quantum crypto checks for JVM code
Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer…
UK government investment arm cops to 40-hour leak of officials’ contact details
Employee failed to follow security policy, leaving internal management file open to the public
Simbian adds AI threat hunting agent to expand autonomous SecOps platform
Simbian has released its autonomous AI Threat Hunt Agent, that investigates potential threats and identifies malicious activity across enterprise…
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark…
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise
The OpenAI Hack Shows the Genie Is Out of the Bottle
This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another…
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword…
ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
Internal documents show ICE’s DNA collection has skyrocketed in the second Trump administration. Now hundreds of thousands of people never convicted of a…
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
IT Security News Hourly Summary 2026-08-03 12h : 6 posts
6 posts were published in the last hour 10:2 : Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys 10:2 : Silicon In Focus Podcast: AI Agents Enter the Enterprise: From Chatbots to Autonomous Digital Workers 10:2 :…
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum…
Silicon In Focus Podcast: AI Agents Enter the Enterprise: From Chatbots to Autonomous Digital Workers
Discover how AI agents are becoming autonomous digital workers, transforming enterprise productivity, governance, security and the future of work
XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands
XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a…
Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
N-able has confirmed that a critical vulnerability in N-central, its flagship remote monitoring and management (RMM) platform, is being actively exploited…
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.
Internet-Facing SonicWall SMA Appliances Face Zero-Click Root Compromise
Internet-facing SonicWall Secure Mobile Access, or SMA, appliances face a serious threat after attackers turned two flaws into a route to full VPN-gateway…
Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
OpenAI reveals how criminals used ChatGPT to run scams
OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to…