A new attack technique called Ghostjacking exploits AI coding agents to bypass firewall defenses at major corporations, according to research presented at…
ICE Can Now Buy Your Credit Card Information
Every time you apply for a credit card or update your account details, you may be sharing your data with ICE. A research by 404 Media said that personal…
Cloudflare launches AI-powered Radar Researcher
Cloudflare has released a beta version of Radar Researcher, an artificial intelligence tool that translates natural language questions into queries…
Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks
Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose…
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The…
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular…
Interlock Turns the Tools Incident Responders Use Into Weapons for Stealing Windows Passwords
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft. The group has turned memory analysis software into a…
IT Security News Hourly Summary 2026-08-10 14h : 10 posts
10 posts were published in the last hour 11:31 : Metabase Patches Vulnerability Exploited as Zero-Day 11:31 : Framework loses customer data in Metabase zero-day attack 11:31 : MITRE ATT&CK Framework Explained: How to Use It for Threat Detection (2026)…
Metabase Patches Vulnerability Exploited as Zero-Day
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
Framework loses customer data in Metabase zero-day attack
Repairable hardware is little comfort when personal details escape
MITRE ATT&CK Framework Explained: How to Use It for Threat Detection (2026)
By HOC Team | Last updated: July 2026 | Read time: ~22 min In the months following the…
Python Now Has a Post-Quantum Encryption Library
This is good : Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we…
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems,…
Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS
Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A…
Claude Code puts auto mode in the driver’s seat
Walk away and hope the classifier catches anything irreversible or destructive
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports
Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware
Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into…
IT Security News Hourly Summary 2026-08-10 13h : 16 posts
16 posts were published in the last hour 10:32 : Go-Based macOS Malware Steals Crypto and Secrets 10:31 : IT threat evolution in Q2 2026. Non-mobile statistics 10:31 : Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a…
Go-Based macOS Malware Steals Crypto and Secrets
A macOS malware variant has been detected stealing crypto, passwords and more
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT)…
Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through…
Connective eID Extension Flaws Let Attackers Steal Belgian ID PINs and Trigger Drive-By RCE
Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic…
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
