4 posts published in the last hour 18:31Hackers Expose Data of 1.2 Million Heights Finance Customers 18:01DDoS Attack Knocks Threema Messaging Service Offline for Hours 18:01Microsoft Confirms ShieldBreak Defender Flaw, Windows Defender Fix Still Pending 18:00IT Security News Hourly Summary…
Hackers Expose Data of 1.2 Million Heights Finance Customers
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights…
DDoS Attack Knocks Threema Messaging Service Offline for Hours
A large-scale DDoS attack disrupted Threema for hours, knocking hosted messaging offline as OnPrem deployments stayed online and attackers remained…
Microsoft Confirms ShieldBreak Defender Flaw, Windows Defender Fix Still Pending
Microsoft is working on a fix for the ShieldBreak Windows Defender vulnerability as a public proof of concept raises privilege-escalation concerns.
IT Security News Hourly Summary 2026-08-18 20h : 10 posts
10 posts published in the last hour 17:31French Tax Authority Data Breach Exposes 600,000+ Users Personal Tax-Related Data 17:31Anthropic Launches New /design Skill for Claude Code UI Workflows 17:31Project noRecognition: Teaching AI to Fool Surveillance Cameras 17:31Critical MLflow SSRF Vulnerability…
French Tax Authority Data Breach Exposes 600,000+ Users Personal Tax-Related Data
France’s tax authority has confirmed a data breach affecting approximately 678,000 individuals and businesses after threat actors gained unauthorized…
Anthropic Launches New /design Skill for Claude Code UI Workflows
Anthropic has introduced a new /design skill for Claude Code, expanding its developer-focused AI platform into user interface design workflows. The…
Project noRecognition: Teaching AI to Fool Surveillance Cameras
Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The…
Critical MLflow SSRF Vulnerability Exploited by Hackers in the Wild
Threat actors are actively exploiting a critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, the popular open-source…
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using…
Microsoft 365 Search Outage Disrupts SharePoint, OneDrive, and Outlook Users Worldwide
Microsoft is actively managing a service disruption that has left a subset of enterprise users unable to search for content across SharePoint Online,…
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14…
Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware
A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal…
Comcast adds motion sensing to millions of its newer routers, with a privacy catch
A new feature added to Comcast’s newest routers can detect if there is motion is inside your home without needing traditional motion sensors.
IT Security News Hourly Summary 2026-08-18 19h : 6 posts
6 posts published in the last hour 16:02Projextor Shows How Malware Can Hide Behind Trusted Electron Executables 16:02DevSecOps Tutorial: Embedding Security into CI/CD Pipelines (2026) 16:02Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed 16:01Bluesky says its…
Projextor Shows How Malware Can Hide Behind Trusted Electron Executables
Projextor is a malware campaign that turns ordinary-looking desktop tools into a doorway for hidden code. Its operators package it inside working document…
DevSecOps Tutorial: Embedding Security into CI/CD Pipelines (2026)
By HOC Team | Last updated: August 2026 | Read time: ~25 min In December 2020, security researchers…
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Bluesky says its recent outage was caused by another DDoS attack
This is the latest large-scale DDoS attack to hit the social networking site this year.
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
BTMob is an Android banking malware platform built to turn phones into tools for fraud. It reaches victims through fake apps, cloned download pages, and…
IT Security News Hourly Summary 2026-08-18 18h : 22 posts
22 posts published in the last hour 15:31GitLab issues emergency patch for critical code-injection flaw 15:31C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection 15:31CISA gives feds 3 days to fix actively exploited Ray RCE bug 15:31Webinar Today: Rethinking…
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.
C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection
C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer. It can run commands, inspect the…
CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks
