Threat intelligence firm Hunt.io has documented a sophisticated Chinese-speaking cyberespionage campaign that integrated commercial AI models into live…
IT Security News Hourly Summary 2026-09-04 16h : 12 posts
12 posts published in the last hour 13:31Sangoma Switchvox Vulnerabilities Exploited in the Wild 13:31KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival 13:31OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques 13:31Compliance…
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution.
KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival
KnowBe4 is set to explore the growing challenge of determining what organisations can trust in the age of AI at an exclusive cybersecurity briefing during…
OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques
Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to…
Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up
The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published…
US military disabled ad tracking on troops’ devices following reports of targeted attacks
A senator’s letter confirms the U.S. military moved to prevent the tracking after foreign adversaries used location data to target troops.
Protecting Against Zero-Click Attacks
By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around…
Europol supports operation against amphetamine producers
As part of an extensive investigation led by the German Krefeld Public Prosecutor’s Office and Mönchengladbach Police, officers from the North…
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000…
Coder Registry Compromise: Malicious Terraform Modules Explained
Coder’s compromised module registry served malicious Terraform modules that stole cloud, CI/CD, AI, and SSH credentials during a 14-hour attack window.
X Money rollout linked to password-reset attacks
As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
Microsoft Teams to Add QR Code Protection in Teams Messaging
Microsoft Teams is preparing to introduce new QR code protection controls designed to reduce phishing and fraud risks in chats involving external users.…
IT Security News Hourly Summary 2026-09-04 15h : 16 posts
16 posts published in the last hour 12:32NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft 12:32Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code 12:31Nvidia Is Buying AI Platform Hugging Face for $13 Billion 12:31Microsoft 365 Phishing…
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging…
Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal…
Nvidia Is Buying AI Platform Hugging Face for $13 Billion
The deal highlights Nvidia’s push to champion increasingly popular open-source AI models.
Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking
Microsoft 365 users are facing a phishing technique built on a small change: attackers leave the SMTP envelope sender blank. The omission can let an…
Synology ActiveProtect Manager 2.0 improves AI-driven security
Synology launched ActiveProtect Manager 2.0 (APM 2.0), the latest software update for its ActiveProtect data protection appliances. This release…
OpenAI Agents Hijack German Wiki in AI Breakout to Share Evasion and Bypass Tactics
Autonomous AI agents that identified themselves as OpenAI systems hijacked an obscure German-language wiki this spring and turned it into a public…
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database…
Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers
Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S.…
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is…
Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws
Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The…