A malicious npm package that appeared to be an ordinary data-indexing tool has exposed a weakness in software supply-chain defenses. The package,…
Writing Custom Semgrep Rules for Static Analysis
By HOC Team | Updated: September 2026 | Read time: ~18 min Static Application Security Testing (SAST) is…
Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users…
Transforming Bedrock Guardrails events into OCSF with CloudWatch
Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a…
PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
A PAYLOAD ransomware attack used Active Directory Group Policy Objects to disrupt an entire Windows domain without encrypting files or deploying…
IT Security News Hourly Summary 2026-09-21 18h : 13 posts
13 posts published in the last hour 15:31Google Hit with €403m GDPR Fine Over Location Data Practices 15:31Microsoft Exposes macOS ClickFix Cloaked Gates – Research 15:31Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This…
Google Hit with €403m GDPR Fine Over Location Data Practices
The Irish DPC found that Google users were unaware that their location was being used to influence them with ads
Microsoft Exposes macOS ClickFix Cloaked Gates – Research
HOC Shorts Microsoft Uncovers Advanced macOS “ClickFix” Campaign The Scale: Spans over 250 front-end domains. The Trick: Instead…
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be…
10 Lessons Reshaping Security After Black Hat and DEF CON 2026
Ten lessons from Black Hat and DEF CON on AI agents, cheaper attacks, supply chain risk, security fundamentals and cyber skills.
Reverse-Engineering Flock Cameras
Hackers captured a Flock camera and got a look (alternate link ) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive…
Hacker vs. Hacker: ShinyHunters Outsmarts Clop Ransomware Gang
The extortion group ShinyHunters hacked the dark web leak site run by Clop, one of the most active ransomware operations in the world, defaced it with…
New Exvicy ClickFix Framework Built on Rival ErrTraffic’s Code
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic
Gemini’s breach of real companies exposes an AI guardrail problem
Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.
Malicious HEIF Upload Reached OpenAI’s Internal GitHub, Researchers Reveal
A malicious HEIF upload exploited Discourse, crossed OpenAI’s identity layer, and reached an internal GitHub repo through a connected Codex account.
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive…
CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be.
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people…
IT Security News Hourly Summary 2026-09-21 17h : 15 posts
15 posts published in the last hour 14:32Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal 14:32Researchers Escape OpenAI Codex Sandbox to Run Commands on Host 14:31The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files 14:31September 2026 Patch…
Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal
The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push.
Researchers Escape OpenAI Codex Sandbox to Run Commands on Host
In OpenAI Codex, security researchers have identified two sandbox escape vulnerabilities, one of which allows developers to execute commands on their…
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and…
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
Burger King Russia – 3,155,792 breached accounts
In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation…
