By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around…
Europol supports operation against amphetamine producers
As part of an extensive investigation led by the German Krefeld Public Prosecutor’s Office and Mönchengladbach Police, officers from the North…
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000…
Coder Registry Compromise: Malicious Terraform Modules Explained
Coder’s compromised module registry served malicious Terraform modules that stole cloud, CI/CD, AI, and SSH credentials during a 14-hour attack window.
X Money rollout linked to password-reset attacks
As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
Microsoft Teams to Add QR Code Protection in Teams Messaging
Microsoft Teams is preparing to introduce new QR code protection controls designed to reduce phishing and fraud risks in chats involving external users.…
IT Security News Hourly Summary 2026-09-04 15h : 16 posts
16 posts published in the last hour 12:32NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft 12:32Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code 12:31Nvidia Is Buying AI Platform Hugging Face for $13 Billion 12:31Microsoft 365 Phishing…
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging…
Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal…
Nvidia Is Buying AI Platform Hugging Face for $13 Billion
The deal highlights Nvidia’s push to champion increasingly popular open-source AI models.
Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking
Microsoft 365 users are facing a phishing technique built on a small change: attackers leave the SMTP envelope sender blank. The omission can let an…
Synology ActiveProtect Manager 2.0 improves AI-driven security
Synology launched ActiveProtect Manager 2.0 (APM 2.0), the latest software update for its ActiveProtect data protection appliances. This release…
OpenAI Agents Hijack German Wiki in AI Breakout to Share Evasion and Bypass Tactics
Autonomous AI agents that identified themselves as OpenAI systems hijacked an obscure German-language wiki this spring and turned it into a public…
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database…
Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers
Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S.…
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is…
Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws
Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The…
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine.
Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help…
VMware Workstation and Fusion Updates Patch Critical Vulnerability
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of…
Catch Raises $5 Million for AI Executive Assistant With Guardrails
Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access.
IT Security News Hourly Summary 2026-09-04 14h : 8 posts
8 posts published in the last hour 11:31Security Vulnerability in a Voting System 11:31MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution 11:31Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign 11:02Critical Super Forms WordPress Flaw Actively Exploited…
Security Vulnerability in a Voting System
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original…