A recent evaluation by the UK AI Safety Institute (AISI) revealed that GPT-6 Astra engaged in unauthorized supply-chain attack activities in simulated…
ShinyHunters expands Oracle PeopleSoft campaign
Google Threat Intelligence Group warned Friday that ShinyHunters (tracked as UNC6240) has launched an expanded campaign targeting vulnerable Oracle…
OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to
OpenAI’s GPT-6 Astra carried out supply chain attacks on software outside the scope of a security test, according to the UK AI Security Institute (AISI).…
GitHub AI Agent Uncovers 24 Android App Vulnerabilities
GitHub Security Lab has disclosed 24 vulnerabilities in Android applications discovered through its open-source AI security agent and specialized audit…
wolfSSL 5.9.4 Fixes 11 TLS Security Flaws and Expands Post-Quantum Cryptography Support
wolfSSL has released version 5.9.4, fixing 11 security vulnerabilities in its embedded TLS and cryptography library while adding major post-quantum…
Four Cyber Threats Harboring Big Plans for the Future
– AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of…
Modulate Raises $25M to Fight Deepfake Voices With Next-Generation Audio AI
Modulate has secured $25 million in funding to expand its audio-native AI platform as enterprises confront deepfake voice fraud, impersonation, and unsafe…
Deepfakes become a board priority once an executive falls for one
Nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year, while just 10% say their organizations have…
OpenAI’s AI Agents Went Beyond Their Tasks and Triggered New Security Concerns
OpenAI has acknowledged that one of its experimental AI agents gained unauthorized access to an Australian government health statistics portal during…
Malicious Custom GPT on chatgpt.com lures users into installing a RAT
Malware peddlers are using sponsored Google results to push a malicious ChatGPT Custom GPT named “Plus 5.6,” created to lead users to a fake Cloudflare…
AgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows Systems
A newly tracked Windows remote access trojan called AgtaBackup RAT is using fake Microsoft Store pages to gain a foothold on victims’ computers. The…
IT Security News Hourly Summary 2026-09-29 14h : 12 posts
12 posts published in the last hour 11:31New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits 11:31Cybersecurity hiring practices leave little room for junior talent 11:31Using Device Linking to Eavesdrop on WhatsApp and Signal 11:31OpenAI Calls Off GPT-6.1…
New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits
A newly identified Windows botnet dubbed x47.c is marketing a blend of conventional DDoS tooling, credential theft, SOCKS5 proxying, fast-flux…
Cybersecurity hiring practices leave little room for junior talent
Twenty-minute training sessions that fit into the workweek could help new hires become productive sooner, keep employees’ skills current and build…
Using Device Linking to Eavesdrop on WhatsApp and Signal
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such…
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.
Former X-Force hackers chase the offensive cyber gold rush
RemoteThreat launches with $7M, 1,000 attack tools, and ambitions to equip enterprises and Uncle Sam for AI-speed operations
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
A teen hacker found an authentication flaw in Microsoft’s Titan analytics service, where metadata indicated an estimated 17.3…
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.
Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.
Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain
Threat actors are abusing ChatGPT’s Custom GPT feature to funnel victims into a ClickFix attack that ends with a full-featured remote access trojan (RAT),…
Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
A malicious file could trigger the vulnerability. Apple says it may already have been used against iPhone users.
Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk
Proton has extended Easy Switch for Business, its guided migration tool, to Microsoft 365. Organisations can now move email, calendars and contacts from…
IT Security News Hourly Summary 2026-09-29 13h : 19 posts
19 posts published in the last hour 10:32Fake iPhone Duo preorder scam triggers DarkSword attack 10:31Cyber Resilience Act Single Reporting Platform (CRA-SRP) obligations for software companies selling globally 10:31DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware 10:31CrowdStrike…
