A long-running malware campaign on the npm registry is using malicious JavaScript packages to compromise Windows systems with remote-access malware,…
Microsoft Outlook to block MSIX attachments starting November
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows…
IT Security News Hourly Summary 2026-10-08 18h : 35 posts
35 posts published in the last hour 15:32UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML 15:32What the C-suite needs to know about AI governance 15:32PoeLLM malware has assembled a sweeping botnet, taking technical cues from a…
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT)…
What the C-suite needs to know about AI governance
As AI adoption surges, executives are learning tough lessons about security, oversight and accountability.
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem.
Cisco Patches a Dozen Critical Vulnerabilities
The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.
FBI Dismantles Scam Center in Ghana and Seizes 300+ Devices in Operation Blackout
Authorities have dismantled a scam center in Ghana as part of the FBI’s Operation Blackout, identifying 89 victims and seizing more than 300 devices. FBI…
Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Low-cost Android phones can arrive already compromised, with malware embedded in their firmware before buyers switch them on.
Asos confirms breach of customer data after hackers send rogue app notification
The hackers alerted the fashion giant’s customers through a push notification that said they had “fully compromised” the company’s cloud storage.
Rural Health Transformation Funding Can Strengthen Care and Cyber Resilience
The Rural Health Transformation Program gives states a timely opportunity to modernize rural care, connectivity, and cybersecurity together.
Fighting GenAI with GenAI: The New Email Security Landscape
SPONSORED FEATURE: Old attack, new protections
ASOS Confirms Unauthorised Hack Notification; Customer Data May Be Exposed
On 6 October 2026, thousands of ASOS customers across multiple countries received a shocking push notification via the official ASOS app, claiming that…
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence…
Co-Creator of Dark Web Marketplace “Empire Market” Sentenced to 40 Years in Prison
Raheim Hamilton, co-creator of Empire Market, was sentenced to 40 years in federal prison for running a dark web marketplace that handled more than $430…
FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users
An initial access broker is working with various ransomware groups in a global campaign.
Hackers Exploit Critical Citrix NetScaler Flaw to Deploy Web Shells and Steal Configuration Data
Hackers are exploiting CVE-2026-88771, a critical Citrix NetScaler vulnerability, to run commands, install web shells, and collect appliance configuration…
Chrome Blocks Unauthorized Certificates After Three ccTLD Hijacks
Chrome has taken steps to protect users after attackers compromised three country-code top-level domains and exploited the incidents to acquire…
GhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials
A new wave of the GhostAction supply chain campaign has compromised 772 public GitHub repositories, using fake GitHub Actions workflow files to steal…
US Probes Cyberattack on Energy Tankers Over Possible Iran Ties
One of the Journal reported that US authorities are investigating a possible Iranian connection to cyberattacks targeting two energy tankers in August…
GitHub AI Can Spot Passwords Hidden in Code Before Developers Push Them
GitHub, with Microsoft Applied Sciences, introduced an AI-powered ModernBERT classifier that detects hidden passwords before code is pushed, expanding…
Power BI phishing campaign drops rogue ScreenConnect clients
Attackers are abusing Microsoft Power BI to host phishing lures that slip past email security, before dropping multiple rogue ScreenConnect clients on…
FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away
FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out…
Uranium crypto exchange hacker convicted for stealing $53 million
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021.…
