The cyberattack involving Ernst & Young (EY) has entered a new phase after the ShinyHunters extortion group claimed responsibility for the intrusion,…
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move…
OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money
OpenAI agent’s escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here:…
Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control
Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android…
IT Security News Hourly Summary 2026-07-30 09h : 13 posts
13 posts were published in the last hour 7:2 : Cisco Secure FMC Zero-Day Exploited in the Wild 7:2 : Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet 7:1 : Headteacher had the most guessable username-password…
Cisco Secure FMC Zero-Day Exploited in the Wild
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as…
Headteacher had the most guessable username-password combo you could imagine
Schools often don’t prioritize or understand cybersecurity
Data breach cost 2026 averaged $4.99 million, AI attacks ran higher
More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the…
Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling
The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These…
Excuses like ‘AI did it’ don’t exist in the eyes of the law
If your AI goes rogue, better have a good lawyer
Cisco Firewall Management Center 0-Day Actively Exploited to Access Sensitive Data
Cisco has released security updates for an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. This…
200 new CVEs a day and no realistic way to patch them all
Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor…
North Korean Hackers Compromise Popular npm Packages to Target Developer Environments
North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining…
TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch
TA488 has been linked to a new campaign that turns a routine Outlook Web Access email into a gateway for mailbox compromise. The operation abused a…
Google Chrome 151 Fixes 370 Security Flaws, Including 7 Critical Bugs
Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes…
North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks
North Korean-linked hackers are turning trusted npm packages into an entry point for widespread software supply-chain attacks. By compromising the…
GitLab Patches 13 Security Flaws Enabling Data Exposure, CI/CD Tampering and DoS Attacks
GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow…
Top companies to visit at Black Hat USA 2026
Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global…
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall…
TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent…
Impersonation protection: How to protect your executives when the truth isn’t clear
How do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently…
Claude Global Outage Hits Users With “529 Overloaded” Error Messages
Users of Claude experienced service disruptions on Wednesday when Anthropic reported elevated error rates across all Claude models. This incident affected…
Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents
Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could…
