Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete…
WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2
A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete…
WhatsApp brings end-to-end encrypted voice and video calls to the web
WhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without…
Root Evidence puts real-world evidence at the center of vulnerability prioritization
Root Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world…
Torq makes AI SOC investigations continuously self-learning
Torq has introduced Torq SOC Brain, a new layer of the Torq AI SOC Platform that continuously learns from historical investigations, analyst decisions,…
Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection
A newly analyzed Android remote access trojan (RAT) dubbed “Flying Eagle” is leveraging Accessibility Services to enable large-scale surveillance,…
1Password targets standing privileges with new access management capabilities
1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables…
Google Australia Customers Now Benefit From Imperva Cloud-Native WAAP Security
Many Australian businesses have moved their applications and data to cloud-native architectures for agility, scalability, and sovereignty. However, this…
Tines introduces AI-native platform for secure enterprise workflow automation
Tines has launched Tines 3B, an AI-native platform for building, running and governing enterprise workflows, applications and agents securely at scale. AI…
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent…
Mend.io enhances application security with AI runtime protection and faster zero-day response
Mend.io has announced new capabilities across Mend AI and Mend AppSec to help organizations respond faster to both application risk and the expanding…
Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets…
Realm Security adds Detection Integrity and Data Haven Search to cut SIEM costs
Realm Security has announced two new capabilities. Detection Integrity proves that reducing SIEM log volume never breaks a threat detection. New search…
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities.
Abnormal AI extends behavioral security to identities, AI systems, and insider threats
Abnormal AI has announced the expansion of its Behavioral Security Platform across the enterprise, introducing three new products: Identity Threat…
ZeroFox unveils HNTR and Executive Protection for AI-driven threat detection
ZeroFox has launched HNTR, a new AI-first platform that brings digital risk protection and threat intelligence together to discover, validate, and disrupt…
JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox
Multiple zero-day vulnerabilities in self-hosted Artifactory after OpenAI’s frontier models autonomously exploited them to escape a sandboxed research…
Leaky BMCs, Claude finds encryption flaws, Google’s new names
Thousands of server BMCs leak password hashes Claude finds flaws in encryption Google gives old threat actors new names Get the show notes here:…
Sensitive, Bizarre Anthropic Claude Chats Exposed Online
Anthropic limits accessibility after hundreds of personal chats with Claude bot exposed through public searches
Infoblox enters EASM market with attack surface and supply chain risk tools
Infoblox has announced its entry into the external attack surface management (EASM) market. Together, with the introduction of Supply Chain Intelligence,…
Bank of Baroda Confirms Data Breach After Employee Email Account Compromised
Bank of Baroda has confirmed a cybersecurity incident involving the compromise of an employee’s email account, which allowed unauthorized access to…
Reco enhances AI Runtime with browser-based AI security and automated remediation
Reco has announced an expansion of AI Runtime, a core component of the Reco Platform. This update adds browser-based enforcement, real-time prompt…
IT Security News Hourly Summary 2026-07-29 09h : 6 posts
6 posts were published in the last hour 7:2 : OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach 6:31 : Hackers Are Hiding Commands in Emails to Trick the AI Systems Protecting You 6:31 : An…
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s…
