VB Congratulates the researchers shortlisted for the 2026 Péter Szőr Award. Read more
FBI: Fake cop and government impersonation scams cost victims $1.6B
AI, fake uniforms, and mock government offices help crooks sell the con
Google Pixel owners urged to patch actively exploited modem flaw
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
Weekly summary of Cybersecurity Insider newsletters
Passwd Enterprise Review: Features, Pricing & Security
Review Passwd Enterprise pricing, security, Google Workspace integration, and private Google Cloud deployment to see if it fits your organization.
New Android malware uses AI to steal bank logins and PINs
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks…
Android Apps Can Now Check If Your Phone Is Missing Critical Security Patches
Android has released new Security State libraries that allow apps and enterprise tools to check whether a device is missing important security patches.…
Ministry of Justice apologizes after court staff accessed Southport victims’ files
Sensitive personal data was involved, but there is no evidence it was shared with third parties
Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than…
FBI, Coast Guard boarded hacked oil tankers heading towards US coast
The feds are said to be investigating the compromise of the tankers’ networks, which in one case interfered with one of the tanker’s navigation and…
MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login
MikroTik router owners face a security problem after researchers reproduced a takeover chain that can hand an outsider full administrator control without…
Atomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.
Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws
Google has released Chrome 153 to the Stable channel for Windows, macOS, and Linux, addressing 16 security vulnerabilities, including two critical…
IT Security News Hourly Summary 2026-09-18 18h : 14 posts
14 posts published in the last hour 15:32AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators 15:31Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access 15:31NightEagle targets Russian companies 15:31Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI…
AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators
Ransomware attacks are entering a new phase. Researchers have documented a campaign in which an AI agent planned, executed, and escalated an extortion…
Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access
Four newly disclosed Linux kernel vulnerabilities could allow local attackers to corrupt kernel memory and escalate privileges to root on affected…
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is…
Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
ChatGPT subscription notices have become the latest cover for credential-stealing emails. The campaign uses a familiar billing problem to push recipients…
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports.
Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
Feral Wolf is using exposed business software and weak server settings to reach corporate networks, then locking files with ransomware. The campaign shows…
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
Two Hugging Face accounts reveal that OpenAI’s agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.
Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications…
Did an AI really try to break free from human control?
An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.
