A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against organizations in the United States, putting Java…
IT Security News Hourly Summary 2026-07-28 15h : 16 posts
16 posts were published in the last hour 13:3 : Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays 13:3 : We rebuilt Malwarebytes Mobile Security for the scams of today 13:3 : Dismantled Kratos Phishing Kit Becomes…
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been…
We rebuilt Malwarebytes Mobile Security for the scams of today
Your phone needs more than a lock screen to stay safe. We’ve rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security…
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first
Washington rallies allies to shape next-generation networks after spending 18 months rattling them
EShare App Vulnerability CVE-2026-55977
The Cyber Security Agency of Singapore has assigned CVE-2026-55977 to a vulnerability in EShare’s wireless screen mirroring and collaboration application.
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence
Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale,…
Shared Claude chats were searchable on Google
Reddit users found that by using a specific search query, they could find shared Claude conversations in search results.
Act Security Launches Patch Management Solution
Act Security has officially launched from stealth mode with a patch management solution targeting a critical challenge facing cloud security teams: the…
SpecterOps brings AWS attack path management and AI to hybrid identity security
SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the…
Tribeca Film Festival Data Breach Exposes 666K Records
Security researcher Jeremiah Fowler discovered four publicly accessible databases containing nearly 666,000 records linked to the Tribeca Film Festival,…
Update your iPhone, iPad and Mac to fix Apple security holes
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.
Senator Wyden urges federal VPN purge
Senator Ron Wyden has urged federal cybersecurity agencies to remove all insecure, internet-facing VPN systems from government networks within two years,…
Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response
Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and…
Fake IT Calls Deploy GoGRPC Backdoor via Teams
Cybersecurity researchers have identified a social engineering campaign where threat actors pose as internal IT helpdesk staff to gain unauthorized access…
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The…
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet…
July Apple updates are especially important if you receive images
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.
VERITAS project could change the way scientists secure AI
The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to…
Confidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in Use
Modern AI runs on shared, high-performance infrastructure that processes enormous volumes of sensitive data and valuable model weights.…
One-click Claude Desktop flaw could enable hidden prompt injection and code execution
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local…
Act Security Emerges from Stealth to Fight the Patch Problem
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments.
