A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data…
Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the…
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that…
IT Security News Hourly Summary 2026-08-11 13h : 18 posts
18 posts were published in the last hour 10:31 : Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection 10:31 : US Court Gives Go-Ahead To Thousands Of Social Media Cases 10:31 : Hacker Conversations:…
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate…
US Court Gives Go-Ahead To Thousands Of Social Media Cases
Thousands of addiction lawsuits against social media giants to proceed in California federal court after legal challenge dismissed
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did.
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and…
Levi Strauss & Co. Confirms Hackers Stole Corporate Data in Cyberattack
Levi Strauss & Co. (Levi’s) has announced a cybersecurity incident involving an unauthorized third party who used social engineering to access the…
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
GhostJacking Attacks Let Hackers Hijack AI Agents and Steal Cloud Credentials
Security researchers have disclosed “GhostJacking,” a new class of attacks that exploits trusted observability and security platforms to manipulate AI…
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open…
Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access…
LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines
A LiteLLM compromise has raised concern over how a trusted AI software component can become an entry point into a network. The supply chain incident…
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.
CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware
The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being…
Senior Police Detective Probed Over AI Use
Senior police detective in Derbyshire investigated by IOPC over alleged gross misconduct related to AI use
Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities
Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter…
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited…
New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp
A new phishing attack is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is…
IT Security News Hourly Summary 2026-08-11 12h : 8 posts
8 posts were published in the last hour 9:31 : OpenAI Pauses Some Development of Astra Model on Security Concerns 9:31 : Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 9:31 : Consulting Giant EY Sets Up Unit To…
OpenAI Pauses Some Development of Astra Model on Security Concerns
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that…
