TrustSink is a newly disclosed identity attack that turns a trusted MFA step into a password-stealing trap. Rather than sending victims to a clearly fake…
IT Security News Hourly Summary 2026-09-28 17h : 17 posts
17 posts published in the last hour 14:32NVIDIA Launches Open Agent Safety Platform With 100 Industry Partners to Secure Autonomous AI Agents 14:32ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells 14:32James Moore, CultureAI Q&A: AI…
NVIDIA Launches Open Agent Safety Platform With 100 Industry Partners to Secure Autonomous AI Agents
NVIDIA has launched the Open Agent Safety Platform, an open framework designed to secure autonomous AI agents as they gain access to models, tools, code…
ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The…
James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind
AI adoption is moving faster than most organisations can govern it. It is a familiar line by now, repeated often enough to sound routine, and that is part…
Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers
Fake storefronts appeared days after the launch of Jev, an artificial intelligence model that returns decisions rather than written answers. The sites…
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That…
Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
Cryptocurrency exchange Bitget has begun restoring withdrawals after attackers exploited its backend wallet infrastructure on September 24, stealing…
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website. The…
CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Microsoft SharePoint code injection vulnerability, tracked as CVE-2026-65660,…
Protecting citizens, preserving rights
How can law enforcement make effective use of data and technology while ensuring that fundamental rights and the rule of law remain protected? This…
DC Health Agency Exposes 400K Records
A health agency in Washington, DC has disclosed a data exposure affecting roughly 400,000 beneficiaries of Medicaid and the DC Healthcare Alliance program.
FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable,…
Nvidia AI Agent Safety Platform Launch
Nvidia has introduced an AI Agent Safety Platform designed to prevent autonomous AI agents from exceeding their designated operational boundaries.
NVIDIA Launches Open Platform to Secure Autonomous AI Agents
NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents
Drunk AI models leak secrets, easier to jailbreak
Researchers at the University of New South Wales (UNSW) Sydney have found that artificial intelligence models trained to write like intoxicated people…
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data
A flaw in Titan, an internal Microsoft analytics service, could have let an attacker read employee records and Bing search analytics, a 16-year-old…
New Mexico Jury Finds Facebook Liable for Privacy Deception
A jury in New Mexico has delivered a verdict against Facebook, finding the social media giant liable for deceiving users about the privacy protections…
IT Security News Hourly Summary 2026-09-28 16h : 11 posts
11 posts published in the last hour 13:31OpenAI pauses work on top AI models after agent slips past internet controls 13:31Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data 13:31Psychedelic Stealer Campaign Targets Ukrainian Businesses 13:31Deepfakes Are…
OpenAI pauses work on top AI models after agent slips past internet controls
An OpenAI agent bypassed internet restrictions and kept running after an alert. It’s another case of AI misalignment no one can afford to ignore.
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
An internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined…
Psychedelic Stealer Campaign Targets Ukrainian Businesses
Arctic Wolf researchers have uncovered a malware campaign targeting legitimate Ukrainian businesses with an information stealer called Psychedelic Stealer.
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns
A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms don’t understand the threat
Storm-3168/JADEPUFFER Azure Credential Abuse
Microsoft has released its first comprehensive report on Storm-3168, a threat actor that Sysdig previously identified as JADEPUFFER and linked to what…
