A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen…
Cyble and DRONA Launch AI Cyber Defense Initiative
Cyble and DRONA Cyber Solutions formally launched an AI-powered cyber defense initiative Tuesday at DRONA’s Command and Control Centre in Ahmedabad,…
IT Security News Hourly Summary 2026-08-26 15h : 10 posts
10 posts published in the last hour 12:31Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware 12:31SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root 12:31Spyware for Babies 12:31Popular school apps may be sharing…
Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware
Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access…
SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that…
Spyware for Babies
The New York Times has a long article ( alt link ) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to…
Popular school apps may be sharing student data with advertisers
A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages
Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing pages. The campaign does not…
Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code
WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary…
Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2
A fake Claude Desktop installer campaign is using Bing malvertising to impersonate trusted Claude. ai-hosted content, DLL sideloading, and…
Average Cyber Insurance Losses Increase Despite Fewer Claims
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we’ve always known was built around a model that guarantees most of the alert queue will never receive analyst review. There’s never time. In a…
IT Security News Hourly Summary 2026-08-26 14h : 11 posts
11 posts published in the last hour 11:31Why Provision 29 is raising the bar for board accountability 11:31The MFA Identity Trap: When Authentication Creates a False Sense of Security 11:31Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 11:31CISA: Over…
Why Provision 29 is raising the bar for board accountability
By Tim Williams, CEO at Quod Orbis Under the 2024 UK Corporate Governance Code, the revised Provision 29 requires boards to demonstrate that their…
The MFA Identity Trap: When Authentication Creates a False Sense of Security
Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are…
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the…
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.
WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks
A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully…
OpenAI Bans Russia ChatGPT Accounts Used to Run Covert Influence Operation
OpenAI Bans Russian ChatGPT accounts participating in a covert online influence operation aimed at manufacturing authority and promoting…
RightCrowd Pass unifies mobile, physical, and biometric credentials
RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single…
Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access
A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems. The campaign uses…
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning…
SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root
SonicWall has disclosed two security vulnerabilities in its NetExtender Linux client, including a critical path traversal flaw that could allow an…
IT Security News Hourly Summary 2026-08-26 13h : 12 posts
12 posts published in the last hour 10:31Bogus recruiters go after high-value corporate credentials on mobile 10:31Exploits and vulnerabilities in Q2 2026 10:31Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities 10:31Claude Opus 4.6 Bypasses Gym Booking Limit,…