The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.
The Four-Character Password Guarding Your Company’s AI Keys
Security researchers at Wiz scanned 3,074 internet-facing deployments of LiteLLM in February and found something that should embarrass more than a few…
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered…
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection
A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud…
State authorities warn they lack resources to address cyber threat to critical sectors
A report shows that state CIOs and CISOs need additional funding, personnel and training to protect water, energy and healthcare.
The state of AI for security: Measuring what matters most for building trust
Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response,…
CrowdStrike Announces Agentic Identity Provider
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Announces Agentic Identity Provider
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together…
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
IT Security News Hourly Summary 2026-09-11 18h : 19 posts
19 posts published in the last hour 15:32Accountability, oversight and AI: Inside Microsoft’s security transformation 15:32Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway 15:32New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks 15:32OpenSSL 4.1…
Accountability, oversight and AI: Inside Microsoft’s security transformation
Stung by years of embarrassing hacks, the tech giant overhauled how it approached cybersecurity. Company leaders now say they’re seeing results.
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used…
OpenSSL 4.1 Alpha Release Announcement
The OpenSSL Project is pleased to announce that OpenSSL 4.1 Alpha1 pre-release is available, which adds significant new functionality to the OpenSSL…
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and…
EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model
ENISA has gained access to Anthropic’s Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations.
Europol and European Labour Authority strengthen cooperation against labour exploitation
The Working Arrangement formalises cooperation that has already demonstrated its value through joint involvement in EMPACT activities. It provides a…
Crypto customers targeted by scammers after email marketing provider breach
A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.
Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a…
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted…
Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis
Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a…
August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate
Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in June, while…
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA…
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA,…