10 posts published in the last hour 08:31Microsoft Rolls Out 22 Fresh Security Patches 08:31Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access 08:31GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure 08:31The invisible passenger…
Microsoft Rolls Out 22 Fresh Security Patches
Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities.
Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access
Three suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats,…
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability…
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun…
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490,…
Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw
A software flaw in Coldcard hardware wallets has raised fresh concerns about the security of offline cryptocurrency storage after a software flaw in…
Cybersecurity Job Ads Requiring AI Skills Double
An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again:…
GitLab 19.3 helps enterprises scale agentic development securely
GitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run…
IT Security News Hourly Summary 2026-08-21 10h : 10 posts
10 posts published in the last hour 07:31Google Chrome 151 Chromoting Flaw Allows Attackers to Execute Malicious Code Remotely 07:31UAE Police ‘Detained’ Two Binance Employees 07:31CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach 07:31China-Linked Spy Campaign Uses Five New…
Google Chrome 151 Chromoting Flaw Allows Attackers to Execute Malicious Code Remotely
Google has released Chrome 151 Stable, fixing seven security vulnerabilities, including a critical use-after-free flaw in Chromoting that could…
UAE Police ‘Detained’ Two Binance Employees
Police in United Arab Emirates reportedly detained two employees of crypto trading giant, questioned a third amid fraud inquiries
CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach
CISA warns of hackers exploiting critical MLflow vulnerability ICS operators warned of AI-driven attacks on Siemens PLCs Electronic health record company…
China-Linked Spy Campaign Uses Five New Malware Families Against Central Asian Governments
Central Asian government bodies have been targeted in a cyberespionage operation using a compact but varied set of remote access tools. The activity,…
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
Hackers Exploit TrueConf Servers to Push Malware Through Legitimate Video Conference Downloads
Kaspersky researchers investigating attacks on Russian organizations discovered that legitimate TrueConf video conferencing client installers were…
Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks
Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research…
Apple’s Private Find My People Reversed to Decrypt Live Shared Locations on Linux
A security researcher has successfully reverse-engineered Apple’s private Find My People protocol, demonstrating that a Linux machine can register with…
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer…
IT Security News Hourly Summary 2026-08-21 09h : 9 posts
9 posts published in the last hour 06:31New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh 06:31Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials 06:31Compromised Rust Crate With…
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control…
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Threat actors are exploiting interest in generative AI software to distribute the Vidar information stealer through a fake Google Gemini installer hosted…
Compromised Rust Crate With 18,000+ Downloads Steals Source Code During Builds
A malicious update to the Rust crate called onering has been discovered, which exfiltrates source code changes from developers’ machines during the build…
