Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The…
Critical MLflow SSRF Vulnerability Exploited by Hackers in the Wild
Threat actors are actively exploiting a critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, the popular open-source…
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using…
Microsoft 365 Search Outage Disrupts SharePoint, OneDrive, and Outlook Users Worldwide
Microsoft is actively managing a service disruption that has left a subset of enterprise users unable to search for content across SharePoint Online,…
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14…
Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware
A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal…
Comcast adds motion sensing to millions of its newer routers, with a privacy catch
A new feature added to Comcast’s newest routers can detect if there is motion is inside your home without needing traditional motion sensors.
IT Security News Hourly Summary 2026-08-18 19h : 6 posts
6 posts published in the last hour 16:02Projextor Shows How Malware Can Hide Behind Trusted Electron Executables 16:02DevSecOps Tutorial: Embedding Security into CI/CD Pipelines (2026) 16:02Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed 16:01Bluesky says its…
Projextor Shows How Malware Can Hide Behind Trusted Electron Executables
Projextor is a malware campaign that turns ordinary-looking desktop tools into a doorway for hidden code. Its operators package it inside working document…
DevSecOps Tutorial: Embedding Security into CI/CD Pipelines (2026)
By HOC Team | Last updated: August 2026 | Read time: ~25 min In December 2020, security researchers…
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Bluesky says its recent outage was caused by another DDoS attack
This is the latest large-scale DDoS attack to hit the social networking site this year.
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
BTMob is an Android banking malware platform built to turn phones into tools for fraud. It reaches victims through fake apps, cloned download pages, and…
IT Security News Hourly Summary 2026-08-18 18h : 22 posts
22 posts published in the last hour 15:31GitLab issues emergency patch for critical code-injection flaw 15:31C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection 15:31CISA gives feds 3 days to fix actively exploited Ray RCE bug 15:31Webinar Today: Rethinking…
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.
C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection
C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer. It can run commands, inspect the…
CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks
Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest…
Vatican’s Official Prayer App Exposed Data of Over 700,000 Users
There was a security flaw in the Vatican’s official Click to Pray application that exposed personal information linked to more than 700,000 registered…
LiteLLM in the crosshairs: Supply Chain Attack on AI Infrastructure
Users of LiteLLM may have become targets of an attacker group. As early as March, it became known that the “TeamPCP” group had managed to obtain…
OpenAI Warns AI Models Can Automate Cyberattacks and Exploit Security Vulnerabilities
OpenAI has warned that advancing artificial intelligence models are increasingly capable of automating critical phases of real-world cyberattacks. This…
EU Launches New Brussels Team to Enforce AI Act Against Deepfakes and Hacking
The European Union rolled out a new enforcement team on Friday to rein in artificial intelligence companies worldwide, marking one of the most aggressive…
Why Threat Intelligence Feeds Often Fail to Meet SOC Expectations
Threat intelligence (TI) feeds are expected to close visibility gaps that inevitably emerge in enterprise SOCs and make investigations faster and more…
Amazon Handbook Warns About Online Shopping and Delivery Box Scams
Online shopping has become the new norm with millions of people shopping through online platforms like Amazon and Flipkart. Unfortunately, online shopping…