85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and…
Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems.
Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting
A cryptocurrency fraud operation has been found using AI coding tools to turn huge phone lists into a sharper victim-targeting system. The campaign…
French Tax Authority Cyberattack Exposes Tax Data of 678,000 Individuals and Businesses
France’s Directorate General of Public Finances (DGFiP) has reported a cyberattack that resulted in unauthorized access to and extraction of tax and…
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog after confirming…
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations…
Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim’s Mouse
Shadow hVNC is a remote access tool built to operate where victims cannot see it. Instead of taking over the visible desktop, it can create a separate…
Xpander Raises $7.5 Million for AI Management and Governance
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand.
10 Best Dark Web Monitoring Tools in 2026
Dark web monitoring involves tracking activities on the hidden internet, accessible only via specialized software and configurations. This shadowy realm…
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a…
Google’s $10,000 refund test shows why AI agents need zero trust
Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can…
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware,…
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The…
IT Security News Hourly Summary 2026-08-18 14h : 15 posts
15 posts published in the last hour 11:31Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver 11:31Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud 11:31Be careful what you put in “anyone with…
Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver
GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs,…
Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the…
Be careful what you put in “anyone with the link” Google Docs
As one developer found out when his Google Doc containing company passwords showed up in Google search results.
Cyber Incident Disrupts Student Services at UT San Antonio
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to…
Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS
Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued…
Inside Astaroth’s New Spambot Component
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Inside Astaroth’s New Spambot Component
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “ CIMemories: A…
Heights Finance data breach: What customers need to know
Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and…
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment…
Can AI Coexist With Privacy? Proton’s Andy Yen Says It Will Have To
Proton’s CEO is a champion of encryption for everyone. So why is he going all in on un-encryptable AI?