Canterbury deploys miniature cellular cells on furniture such as lampposts to increase density of coverage in key areas
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external…
IT Security News Hourly Summary 2026-09-10 10h : 9 posts
9 posts published in the last hour 07:31New Apple Chief Ternus Launches Foldable iPhone Duo 07:31Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. 07:31New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender 07:31McKesson – 6,404,340 breached accounts 07:31Fortinet…
New Apple Chief Ternus Launches Foldable iPhone Duo
iPhone Duo enters lucrative foldables market with passport-shaped form-factor and ‘iPad-like’ experience
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
Threat actors are increasingly using ClickFix social-engineering lures and search-engine malvertising to deploy MacSync Stealer, a macOS-focused…
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
The exploit provides full System privileges on Windows machines running the September 2026 patches.
McKesson – 6,404,340 breached accounts
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently…
Fortinet auth holes, China distills AI, Mythos vulnerability
Fortinet plugs two critical auth holes US says China is distilling AI at scale Mythos vulnerability hits human bottleneck Get the show notes here:…
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.
Ringleader Pleads Guilty To Organising $245m US Crypto Gang
Malone Lam, 22, admits to leading gang of youths who stole more than $245m of cryptocurrency through social engineering attacks, break-ins
Dental contractor set up secret account with access to 4,000 patient records then left the company
Toothless security
IT Security News Hourly Summary 2026-09-10 09h : 7 posts
7 posts published in the last hour 06:31Google To Invest €13bn In Finland AI Infrastructure 06:31Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America 06:31Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12…
Google To Invest €13bn In Finland AI Infrastructure
Spending includes deal to buy up to half of output of one of Finland’s nuclear plants, three new data centres, expansion of a fourth
Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows,…
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed…
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few…
Emergency Zero-Day Alert: ‘ShieldCrash’ Bypass Microsoft Defender Patch | Threat Hunting
HOC Shorts Critical Security Report: Exposed as ‘ShieldCrash‘ Bypasses Microsoft Defender just after release September 2026 Patch Tuesday.…
Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside…
IT Security News Hourly Summary 2026-09-10 08h : 6 posts
6 posts published in the last hour 05:31Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers 05:31China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks 05:02Anthropic Claude AI Models Attack Real Systems During Misconfigured Cybersecurity Tests 05:02A…
Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
Threat intelligence firm GreyNoise has identified an AI-driven intrusion campaign, likely orchestrated by a Russian-speaking threat actor, that…
China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel…
Anthropic Claude AI Models Attack Real Systems During Misconfigured Cybersecurity Tests
Anthropic has reported four cybersecurity evaluation incidents in which pre-release Claude AI models gained unauthorized access to real third-party…
A new open standard locks AI weights to approved hardware
OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open…
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.