A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent…
IT Security News Hourly Summary 2026-08-10 10h : 8 posts
8 posts were published in the last hour 7:32 : A week in security (August 3 – August 9) 7:32 : OpenAI slows Astra, Irregular won’t talk, Senate confirms Cassady 7:32 : Rural Yorkshire, Lincolnshire Premises Get Fibre Links 7:31…
A week in security (August 3 – August 9)
A list of topics we covered in the week of August 3 to August 9 of 2026
OpenAI slows Astra, Irregular won’t talk, Senate confirms Cassady
OpenAI slows release of Astra model citing cyber capabilities Irregular won’t say if there were more rogue incidents U.S. cyber ambassador nominee Cassady…
Rural Yorkshire, Lincolnshire Premises Get Fibre Links
Some 60,000 rural homes and businesses in region linked to ultra-fast broadband network under government-funded Project Gigabit
OpenAI locks down Astra over potential critical cyber capabilities
OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude…
North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings
North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with…
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no…
OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal…
IT Security News Hourly Summary 2026-08-10 09h : 6 posts
6 posts were published in the last hour 6:31 : Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System 6:31 : Meta Confirms One of Its AI Models Breached a Company During a Misconfigured Cyber Test 6:1…
Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System
An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes…
Meta Confirms One of Its AI Models Breached a Company During a Misconfigured Cyber Test
Meta has confirmed that one of its AI models breached a real organization during cybersecurity testing. Thank you for being a Ghacks reader.
Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude…
Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger…
Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph…
IT Security News Hourly Summary 2026-08-10 08h : 7 posts
7 posts were published in the last hour 5:31 : New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users 5:31 : Product showcase: Enpass Password Manager breaks away from the proprietary cloud model 5:31 : Metabase…
New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to…
Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information…
Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials
Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects…
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies.
71% of CISOs spend 10+ hours on board reports
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance.…
Levi Strauss Hit by Cyberattack, Hackers Use Social Engineering to Steal Corporate Data
Levi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three…
IT Security News Hourly Summary 2026-08-10 07h : 4 posts
4 posts were published in the last hour 4:31 : How to report an AI Act violation in the EU 4:1 : Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts 4:1 : Claude-Powered OpenClaw AI…
How to report an AI Act violation in the EU
The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began…
