Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.
Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities
CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data
Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while…
AWS successfully completed its 2025-26 NHS DSPT assessment
Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment…
Social media platforms crack down on drone factory recruiting game
Researchers found that games and major US social media platforms were used to lure young people into jobs in Russia’s drone industry.
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
This is why we can’t have nice things, people
US government will let private companies hack criminal gangs
The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.
IT Security News Hourly Summary 2026-08-13 18h : 36 posts
36 posts were published in the last hour 15:32 : Gen Threat Report Highlights H1 Global Threat Landscape 15:32 : PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers 15:32 : Enriched URL Reports: VirusTotal URL Scanning 2.0 15:32 : Google Cloud…
Gen Threat Report Highlights H1 Global Threat Landscape
The Gen Threat Report is a twice-a-year analysis of the largest cyber threats impacting the digital threat landscape, providing a detailed insight into…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Enriched URL Reports: VirusTotal URL Scanning 2.0
Introduction In today’s fast-moving cybersecurity landscape, threat analysts must move beyond basic, binary reputation scores to successfully defend…
Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone
Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration…
Threat Hunting Maturity: The Metrics Your Board Actually Needs
Threat hunting maturity scores don’t show which adversary techniques your SOC can detect.
Cyber Briefing: 2026.08.11
Critical infrastructure providers, supply chain logistics networks, and enterprise platforms continue to be disrupted by active ransomware campaigns
AWS Security Best Practices: A Complete Checklist for 2026
By HOC Team | Last updated: August 2026 | Read time: ~25 min In June 2023, a misconfigured…
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability coordination project has had a rocky few years, but a key leader says it will “flourish and improve.”
North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
A joint undercover investigation has pulled back the curtain on how North Korean IT worker operatives don’t just slip past hiring checks; they settle in,…
78 arrests in bust of major Western Mediterranean smuggling network in Spain
The operation, conducted under a newly established Europol Taskforce within Europol’s European Centre Against Migrant Smuggling, brought together officers…
Trump wants to grant private cyber firms a license to hack back
Contractors could surveil and disrupt foreign criminal networks, provided they follow strict rules and put up $1M
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages queried an Ethereum wallet to locate C2 infrastructure
Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks
Microsoft has released security updates for multiple Exchange Server vulnerabilities that could allow denial-of-service, privilege escalation, remote code…
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Cursor fixed a pre-trust code execution path in three days then closed the report as informative
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
A third-party logistics breach has put thousands of Trezor hardware wallet buyers at higher phishing risk, even though Trezor’s own systems and devices…
North Korean remote IT staffer worked for US government agency, says FBI
The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges.