Red Hat has disclosed an Important security vulnerability in the OpenShift oc-mirror tool that could allow attackers to bypass PGP signature verification…
Belgian Sports Federations Hit by Cyberattacks
Two Belgian sports federations are investigating separate cybersecurity incidents involving potential theft of member data.
Only 13% of OT Network Segments Keep Operational Technology Isolated
New research from Forescout Vedere Labs has found that critical operational and medical devices are frequently sharing network segments with IT and IoT…
Gartner: 55% of VMware users will explore alternatives by 20
Gartner forecasts that more than half of VMware customers will begin evaluating alternative hybrid cloud platforms by 2029, reflecting growing…
Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying…
British Columbia sues OpenAI over Tumbler Ridge shooting
The government of British Columbia has sued OpenAI in San Francisco federal court, alleging the company failed to prevent a mass shooting that killed…
Veeam Agent Flaw Actively Exploited to Gain SYSTEM Privileges on Windows
A critical local privilege escalation flaw in Veeam Agent for Microsoft Windows is drawing attention after public proof-of-concept exploit code became…
Amiga Unix gets modern revival with AI-assisted updates
A team of Finnish developers has successfully modernized Amiga Unix (Amix), a Unix System V Release 4 port originally released by Commodore in 1991 for…
IT Security News Hourly Summary 2026-09-22 16h : 8 posts
8 posts published in the last hour 13:32Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents 13:31AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds 13:31New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited…
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, 22nd September 2026, CyberNewswire
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds
A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista…
Europol celebrates the International Day of Police Cooperation
On 7 September, Europol is marking the International Day of Police Cooperation together with its partners to recognise the central role our network plays…
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.
LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially…
AI Agents Are Rewriting the Rules of Lateral Movement
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an…
IT Security News Hourly Summary 2026-09-22 15h : 19 posts
19 posts published in the last hour 12:32Only 13% of OT Network Segments Are Fully Isolated: Analysis 12:32Context Bombs Trick Autonomous Qwen AI Agents Into Stopping Cyberattacks 12:32Critical Linux KVM Flaw Enables Guest-to-Host Escape on ARM64 Systems 12:31GHAPPIER Supply Chain…
Only 13% of OT Network Segments Are Fully Isolated: Analysis
Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets.
Context Bombs Trick Autonomous Qwen AI Agents Into Stopping Cyberattacks
A hidden “context bomb” prompt in a cloud decoy can disrupt AI agents and force Qwen3.8-27B to stop simulated attacks. The technique worked against both…
Critical Linux KVM Flaw Enables Guest-to-Host Escape on ARM64 Systems
A critical vulnerability in the Linux Kernel-based Virtual Machine (KVM) for ARM64 systems could let attackers escape a virtual machine and gain read and…
GHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package
A newly uncovered software supply chain attack has shown how quickly a trusted developer account can become a delivery route for malware. The operation,…
The next intellectual property thief may sound like your CEO
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of…
Hackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords
A suspected Chinese-speaking threat actor has used WordPress vulnerabilities to break into at least 49 organizations across 29 countries. The campaign…
Deepfake Phishing Attacks: Detection and Prevention Guide
By HOC Team | Updated: September 2026 | Read time: ~18 min A finance manager at a UK…
