Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on…
Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated…
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in…
IT Security News Hourly Summary 2026-09-17 16h : 24 posts
24 posts published in the last hour 13:32AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape 13:32ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th) 13:32Download: The IT leader’s guide to AI…
AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape
Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their…
ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094,…
Download: The IT leader’s guide to AI code sprawl
AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI…
HBO Max Reddit account hijacked for malware
Cybercriminals compromised HBO Max’s verified Reddit account and used it to distribute malware through 108 malicious advertisements over approximately 48…
SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
A wider cluster of SpiceRAT command-and-control infrastructure has been linked to the SilkParasite cyber-espionage activity targeting government,…
The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the…
Comp AI Raises $34 Million for AI-Native Compliance and Security
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure.
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of…
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of…
Cisco drops another exploited zero-day, this time a perfect 10
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities
Could an Email You Never Read Hijack Your AI Assistant?
Cybersecurity awareness has traditionally focused on teaching people not to click suspicious links, open unexpected attachments or hand over their…
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection…
Critical ScreenConnect flaw actively exploited
The U.S.
North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer
North Korean IT-worker operators are recruiting foreign nationals to sit on camera during remote job interviews. At the same time, the real candidate…
Anthropic tests Claude Money for bank data analysis
Anthropic has begun testing Claude Money, a personal finance feature that enables users to connect their bank accounts directly to the Claude AI assistant.
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
Google Launches Gemini 3.8 Live AI Models
Google has launched two new audio AI models designed to help enterprises deploy conversational voice agents with enhanced reasoning capabilities.
Salt Security expands CrowdStrike integration to tackle AI agent security
Salt Security has expanded its integration with CrowdStrike to give security teams greater visibility into how AI agents connect to enterprise systems,…
