A critical vulnerability chain in the popular Avada theme for WordPress could allow an unauthenticated attacker to execute arbitrary PHP code on the…
Making User-Generated Sites Embeddable: X-Frame-Options vs CSP Frame-Ancestors
If you let users publish something, such as a page, prototype, or dashboard, sooner or later you want an “embed this” button so they can drop it into a…
Flock Sought to Expand Surveillance Through Uber and Lyft Drivers
By using rideshare and delivery vehicles as mobile surveillance platforms, Flock Safety may be able to extend its automated license plate reader network…
US government snitch-finder pleads guilty to leaking state secrets to foreign spies
The IT specialist began contacting a foreign government within days of being assigned to the DIA’s Insider Threat Division
IT Security News Hourly Summary 2026-08-28 17h : 10 posts
10 posts published in the last hour 14:31Cyber Briefing: 2026.08.28 14:31Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix 14:02Secure Agent Harness Execution: Preventing Escape 14:02Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against…
Cyber Briefing: 2026.08.28
Espionage campaigns, actively exploited vulnerabilities, large-scale data exposure, infrastructure targeting, and expanding AI-driven risks underscore the…
Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix
A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an…
Secure Agent Harness Execution: Preventing Escape
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Secure Agent Harness Execution: Preventing Escape
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent…
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited…
Russian APT BlueDelta Uses HOOKEDGE Against European Government
Recorded Future’s Insikt Group has documented a sustained espionage campaign by BlueDelta, a Russian GRU-linked threat group overlapping with APT28,…
ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
Protect your WhatsApp account with new passkey and 2FA upgrades
WhatsApp has introduced three security upgrades. Here’s what to turn on to better protect your account.
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415…
IT Security News Hourly Summary 2026-08-28 16h : 16 posts
16 posts published in the last hour 13:32Key Reasons Why Identity Fabric Matters in 2026 13:32Zero-Day Dominance: How Akamai Defends Before the Industry Discloses 13:31Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign 13:31PaperCut Emergency Patch for Zero-Day 13:31Manchester Airports Group…
Key Reasons Why Identity Fabric Matters in 2026
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and…
Zero-Day Dominance: How Akamai Defends Before the Industry Discloses
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Zero-Day Dominance: How Akamai Defends Before the Industry Discloses
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious…
PaperCut Emergency Patch for Zero-Day
PaperCut has issued an emergency security update to address a zero-day vulnerability in its NG and MF print management products that is being actively…
Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers
Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising…
Hackers Use Fake Student Resume to Secretly Install Malware on Researchers’ Computers
A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an…
Tech Giants Back OpenAI-Led Cyber Defense Pledge
Nearly 130 technology and cybersecurity companies have united behind an OpenAI-led pledge to strengthen collective cyber defenses in response to the…
Cyberattack on 3 UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports.
Chinese QTFY Group Targets US Infrastructure
A Chinese state-linked hacking group known as QTFY has been conducting a sustained campaign against US government agencies and critical infrastructure…