The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server
cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of…
Threats Making WAVs – Incident Response to a Cryptomining Attack
Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report…
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or…
New Windows Defender ShieldCrash 0-Day Bypasses Microsoft Patch to Read Files as SYSTEM
A newly published ShieldCrash proof of concept from researcher MSNightmare claims that Microsoft Defender remains vulnerable to an arbitrary file-read…
Securin Platform helps security teams prove when attack paths are closed
Securin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three…
Windows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely
Microsoft has disclosed a new security flaw in Windows BitLocker, the operating system’s built-in disk encryption feature, that could let an attacker…
Chrome 153 Patches Seventh Zero-Day of 2026
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.
Top 10 Best Application Control & Allowlisting Tools in 2026
Allowlisting inverts the security model: instead of detecting bad software, only approved software runs. Done well, it stops ransomware protection threats…
Chinese AI firms are siphoning capabilities from American models, CISA warns
China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint…
CISA Warns Chinese AI Firms Extract Billions of Tokens From Claude, GPT, Gemini and Grok
A new U.S. government advisory has raised concerns over large-scale attempts to copy the capabilities of leading artificial intelligence systems. The…
IT Security News Hourly Summary 2026-09-09 12h : 13 posts
13 posts published in the last hour 09:32SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution 09:32Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox 09:31PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells…
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that…
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The…
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical…
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability,…
Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation
Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance,…
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an…
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that…
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related…
Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for…
The Nansh0u Campaign – Hackers Arsenal Grows Stronger
In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses…
The push to stop algorithms controlling social media feeds has begun
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM
A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain…