JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation…
Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer…
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
Origin Confirms Data Breach – Hackers Accessed 900,000 Customers’ Data
Origin Energy, an Australian energy provider, has confirmed that unauthorized access to customer information has affected approximately 900,000 current…
OT Security Startup Frenos Raises $1.52 Million
The company will use the fresh investment to grow its customer success and AI R&D teams.
Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation
Bugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale…
Microsoft Launches Cybersecurity AI Model MDASH
Microsoft has introduced MAI-Cyber-1-Flash, marking the company’s entry into purpose-built artificial intelligence models for cybersecurity operations.
From Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global Investing
See how stablecoins, tokenized stocks and fractional investing lower costs and expand global access to US markets through modern financial super apps…
Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here’s how the eval() injection works and who still needs to…
An SOC Story Why Fast Answers Beat Perfect Answers in Cyber Incident Response
A Formula 1 pit crew doesn’t wait until every sensor, camera, and engineer agrees that a tire needs changing. They have a few seconds to make a decision…
Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting
Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The…
Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users
Kratos is a phishing service built to steal Microsoft 365 credentials at scale. It evolved from the Sneaky2FA kit and gave affiliates ready-made login…
BlackCloak extends deepfake protection to the executive’s trusted circle
Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building…
Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions
Criminals are using convincing cryptocurrency wallet screens and browser extensions to steal recovery phrases, login data, and active browser sessions.…
Cyberhaven launches Flow to secure data across human and AI workflows
Cyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage,…
Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations
A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against organizations in the United States, putting Java…
IT Security News Hourly Summary 2026-07-28 15h : 16 posts
16 posts were published in the last hour 13:3 : Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays 13:3 : We rebuilt Malwarebytes Mobile Security for the scams of today 13:3 : Dismantled Kratos Phishing Kit Becomes…
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been…
We rebuilt Malwarebytes Mobile Security for the scams of today
Your phone needs more than a lock screen to stay safe. We’ve rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security…
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first
Washington rallies allies to shape next-generation networks after spending 18 months rattling them
EShare App Vulnerability CVE-2026-55977
The Cyber Security Agency of Singapore has assigned CVE-2026-55977 to a vulnerability in EShare’s wireless screen mirroring and collaboration application.
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence
Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale,…