Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.
IT Security News Hourly Summary 2026-10-08 16h : 39 posts
39 posts published in the last hour 13:33Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available 13:33Japan Arrests Suspected Qilin Ransomware Hacker, Extradites Him to Germany 13:33Europol and US Spending Watchdog Sound the Alarm Over Quantum Threats 13:33YouTubers targeted…
Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting…
Japan Arrests Suspected Qilin Ransomware Hacker, Extradites Him to Germany
A suspected member of the Qilin ransomware group has been arrested in Japan and extradited to Germany, where he is expected to face charges related to…
Europol and US Spending Watchdog Sound the Alarm Over Quantum Threats
Europol and US Government Accountability Office urge faster transition to post-quantum cryptography
YouTubers targeted with fake sponsorships and “channel verification” phishing
Scammers are going after YouTube creators’ Google accounts by posing as a brand looking for sponsorship partners. By sending out personalized emails that…
Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform
Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers.
Filigran announces speakers for first THREAD event
Filigran has announced the speaker line-up for THREAD, its first annual event for the cyber defence and threat intelligence community, taking place in…
The ASOS Incident: When Attackers Use the Channels Customers Trust
This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the…
7 Best Agentic AI Tools for Penetration Testing in 2026
Agentic AI is changing penetration testing in ways that go beyond simply making scanners faster.… 7 Best Agentic AI Tools for Penetration Testing in 2026…
Advantest confirms data stolen in ransomware attack
Advantest Corporation has confirmed that attackers stole sensitive personal data during a ransomware incident that occurred in February 2025.
September 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure Rise
Key takeaways Organizations experienced 2,803 weekly cyber attacks on average in September, up 16% month over month and 48% year over year. Education…
PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users’ session cookies…
Anthropic Launches Three-Tier Claude Cyber Access Program
Anthropic has launched a restructured Cyber Verification Program that divides access to Claude AI models into three distinct tiers, each calibrated to…
Japanase Media Company Nikkei Reveals Intrusions Attacking Users and Employees
Japanese media company Nikkei has disclosed two separate cyber incidents involving employee accounts on Microsoft 365 and Google Workspace. One of the…
Musician sentenced for $10M streaming fraud
A federal court sentenced a North Carolina musician to 18 months in prison for orchestrating a streaming fraud scheme that netted more than $10 million in…
Attackers Hide AI Prompt Injections Inside Phishing Emails
Barracuda finds phishing emails designed to manipulate both human users and AI assistants
Gartner Defines New ISOC Security Tool Category
Gartner has defined a new category of security tools called Integrated Security Operations Center (ISOC), marking a significant shift in how the industry…
The trust gap that AI watermarking can’t close
By Alex Laurie, GTM CTO, Ping Identity Generative AI has made content creation effortless, but establishing where content originates – and whether it can…
Chinese Hacker Uses AI in South Korean Bank Campaign
Multiple South Korean financial institutions suffered data breaches in a campaign where a suspected Chinese threat actor deployed AI-powered pentesting…
CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight…
De Kalb County, Indiana fell prey to vendor impersonation billing
The Star reports that the DeKalb County government fell victim to a cybersecurity incident for the second time in little more than a year. This time, it…
From Automation to Infection (Part III): Naming, Measuring, and Detecting Malicious AI Agent Skills
In Part I and Part II of this series, we looked at an initial sample of 3,016 AI agent skills and showed how they were becoming a new supply-chain…
UAT-11985: AI-assisted AitM phishing targeting Taiwan
Cisco Talos Intelligence has identified an advanced persistent threat campaign targeting individuals affiliated with Taiwan-based research organizations…
