ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated…
Europol-led action against nihilistic violent extremist network “The Com”
An estimated 4 340 URLs related to nihilistic violent extremism were referred during the initiative organised by Europol’s EU Internet Referral Unit – EU…
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Cisco has issued security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to access…
French-Spanish operation targets hazardous waste trafficking network: four arrested
The investigation focused on an alleged cross-border network that illegally transported tonnes of demolition waste from France to Spain, posing serious…
IT Security News Hourly Summary 2026-08-20 14h : 14 posts
14 posts published in the last hour 11:31Five arrests for smuggling migrants across the Bulgarian-Serbian green border 11:31AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking 11:31AWS limits AI agents’ data access, even when manipulated 11:31NASA AIT-GUI Flaws…
Five arrests for smuggling migrants across the Bulgarian-Serbian green border
The action day led to:5 arrests (1 High Value Target, 2 police officers and 2 associates)5 locations searched;Seizures include: 3 vehicles used for…
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
Atalanta’s Argo product is now being used to prove the resilience of Viasat’s satellite communications network.
AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and…
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL’s open-source AMMOS Instrument…
Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact…
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other…
Corero brings cloud-based AI threat analysis to SmartWall ONE
Corero Network Security has announced AI-Augmented Cloud-Assist for SmartWall ONE, extending its automated DDoS protection with cloud-delivered AI…
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with “significant enhancements,” including a set of…
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities.
ICS Operators Warned of AI-Driven Attacks on Siemens PLCs
A US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCs
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the…
Fake Gemini installer delivers Vidar infostealer via Google Colab lure
A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region,…
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code…
IT Security News Hourly Summary 2026-08-20 13h : 17 posts
17 posts published in the last hour 10:31Uber Offers Robotaxi Rides In Zagreb 10:31Europol supports operation against amphetamine producers 10:31Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud 10:31Identity Abuse Through Trusted Communication Channels 10:02Police Are Hiding…
Uber Offers Robotaxi Rides In Zagreb
Uber offers autonomous vehicle rides via its app for first time in Croatian capital, as it prepares London launch
Europol supports operation against amphetamine producers
As part of an extensive investigation led by the German Krefeld Public Prosecutor’s Office and Mönchengladbach Police, officers from the North…
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise…
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.
Police Are Hiding Their Use of Flock Surveillance Cameras
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County,…
