The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an…
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote…
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply…
Redefining Network Security for the Frontier AI Era
Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both today’s…
IT Security News Hourly Summary 2026-08-04 15h : 32 posts
32 posts were published in the last hour 13:3 : Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th) 13:3 : RapidFort Runtime brings continuous CVE monitoring and tamper detection 13:3 : CVE-2026-58048: cPanel Bug Enables Full Database Administrator…
Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
This morning, I noticed specific sources “hunting” for vulnerabilities in URLs that I haven&#;x26;#;39;t noticed before. All of these URLs appear to be…
RapidFort Runtime brings continuous CVE monitoring and tamper detection
RapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The…
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a…
Almost Half of Malware Samples Communicate Direct to IP
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.
Malicious NPM Packages Attack Alibaba Users and Companies
Cybersecurity experts have found a new set of harmful npm packages that attack users of Alibaba developer tools via cross-platform RAT (Remote Access…
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could…
OWASP Introduces Subtractive Security Top 10 to Eliminate Attack Paths and Reduce Cyber Risk
OWASP has launched the Subtractive Security Top 10 project, a security engineering initiative that shifts the focus from adding more detection controls to…
Black Hat 2026: Improving CISO to Board Cyber Risk Reporting
A Pulse Security report finds that effective board cyber risk reporting depends more on governance than presentations.
Phishing attacks evolving with AI, OAuth exploits
Cybercriminals have elevated phishing attacks to new levels of sophistication by combining generative AI with advanced technical exploits.
AI Threatens Entry-Level Jobs as Automation Accelerates Across Industries
As artificial intelligence rapidly transforms the global workforce, new research suggests that entry-level positions in technology, finance, customer…
Midnight Blizzard targets hotel Wi-Fi for credential theft
Russian state-sponsored threat actor Midnight Blizzard, linked to Russia’s foreign intelligence service, has conducted a months-long campaign targeting…
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break.…
Liechtenstein VwbP Register Breached; 31K Entities Affected
Liechtenstein authorities are investigating a cyberattack that compromised the country’s Register of Beneficial Owners (VwbP), resulting in the…
OpenAI Shuts Down ChatGPT Accounts Powering a Cambodia-Based Scam Factory
OpenAI has shut down a coordinated network of ChatGPT accounts that powered a Cambodia-based scam factory running multi-vector fraud and…
Former FBI supervisor pleads guilty to $1M crypto theft
Identity and access management provider Okta has acquired Permiso, a cloud-native identity platform that specializes in behavioral analytics and threat…
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing…
Okta Acquires Cloud-Native Identity Platform Permiso
Identity and access management provider Okta has acquired Permiso, a cloud-native identity platform that specializes in behavioral analytics and threat…
Travelers targeted when logging into hotel Wi-Fi networks
Russian cybercrime groups are running a campaign that abuses hospitality Wi-Fi to steal information from travelers worldwide.
CISA Adds Exploited N-able N-central Flaw Enabling Remote Admin Takeover to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in…