Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks
TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The…
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle…
When violence shapes identities in a larger pool of perpetrators: new Europol terrorism report
Terrorism in Europe is entering a new phase. The latest European Union Terrorism Situation and Trend Report (EU TE-SAT) 2026, published today, shows how…
Threats Making WAVs – Incident Response to a Cryptomining Attack
Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report…
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens.…
What Happens When AI Becomes Your Penetration Tester? TryHackMe Research
Yes, even Penetration tester can miss hidden vulnerabilities. No matter how deeply you test a system, some security…
TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These…
IT Security News Hourly Summary 2026-08-25 09h : 7 posts
7 posts published in the last hour 06:31AI supply chain risk is showing up in developer workflows first 06:31Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions 06:03TruffleHog AWS Analyze reduces remediation time on leaked AWS…
AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still…
Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo…
TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials
Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to…
The Nansh0u Campaign – Hackers Arsenal Grows Stronger
In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses…
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods…
HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool…
IT Security News Hourly Summary 2026-08-25 08h : 7 posts
7 posts published in the last hour 05:32Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect VPN 05:32The cybercrime supply chain has five stages, each with a price 05:32Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive…
Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect VPN
A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint…
The cybercrime supply chain has five stages, each with a price
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He…
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited…
Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms
Apollo Global Management confirmed a social-engineering breach exposing sensitive personal data amid a wider hacking campaign targeting financial firms.
Microsoft Teams New Security Policy Lets Admins Automatically Block Meeting Bots
Microsoft is introducing a new Microsoft Teams meeting policy that automatically blocks identified external bots. This aims to address growing concerns…
New TCG guidance gives buyers a way to test PQC-ready TPM claims
The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM…
5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint…