19 posts published in the last hour 13:32Threats Making WAVs – Incident Response to a Cryptomining Attack 13:31WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover 13:31Crypto hardware wallet owners face fresh security risks after recent spate of personal data…
Threats Making WAVs – Incident Response to a Cryptomining Attack
Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report…
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
The hacks at shipping companies used to mail out hardware wallets puts crypto owners at greater risk of real-world attacks.
Anthropic adds invisible watermarks to Claude text
Anthropic has announced plans to implement invisible watermarking technology for text generated by its Claude AI assistant, marking a significant step…
RingCentral Breach Exposes Personal Data of 1.6 Million Accounts
An attack on RingCentral, which was targeted at social engineering, has led to a data breach that could have exposed personal information of around 1.6…
Evooo1Bot Linux Botnet Exploits Known Flaws
A previously unknown Linux botnet called Evooo1Bot has been identified by cybersecurity researchers, representing the latest evolution of threats derived…
Europol and Frontex strengthen cooperation with new Working Arrangement
The new arrangement replaces the agreement signed in 2015 and reflects the significantly expanded mandates that both agencies have received in recent…
Philips and GE investigating Clop ransomware breaches
General Electric and Philips have confirmed they are investigating claims that the Clop ransomware gang successfully breached their systems and…
Migrant smuggling network using rental cars dismantled across the Balkans
Led by the Greek authorities and supported by Europol, the investigation targeted a criminal network composed mainly of Syrian and Egyptian nationals…
Google Workspace Gemini data access default settings
Google Workspace administrators are discovering that Gemini, Google’s AI assistant, has default access to user data across multiple core services…
Season 4 of The Europol Podcast available now
The Europol Podcast is the official podcast of the EU’s agency for law enforcement cooperation. This season, we spoke to our Europol experts on the…
Zhipu GLM-5.3 AI model claims superior vulnerability detection
Chinese AI developer Zhipu launched GLM-5.3 last week, claiming the model matches American AI systems in detecting software vulnerabilities.
Threema Secure Messaging Service Hit by Massive DDoS Attack
Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily…
French-Spanish operation targets hazardous waste trafficking network: four arrested
The investigation focused on an alleged cross-border network that illegally transported tonnes of demolition waste from France to Spain, posing serious…
The Oracle of Delphi Will Steal Your Credentials
Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced…
Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely
Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or…
Europol-led action against nihilistic violent extremist network “The Com”
An estimated 4 340 URLs related to nihilistic violent extremism were referred during the initiative organised by Europol’s EU Internet Referral Unit – EU…
Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities
Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code…
IT Security News Hourly Summary 2026-08-17 15h : 8 posts
8 posts published in the last hour 12:31Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer 12:31How MCP Servers Can Expose Enterprise Secrets 12:31Irregular Details How a Naming Error Let AI Models Attack a Real Company 12:31Unisoc VoLTE Video…
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a…
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security…
Irregular Details How a Naming Error Let AI Models Attack a Real Company
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc…
