200 posts published today 21:31Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing 21:31MI5 Warns Over 100 Academics Helped China’s Espionage Plans 21:31Losing gamblers pushed to bet more by DraftKings’ AI, report says 21:01AI Agent Chains Zammad Zero-Days…
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic. As usual, you can also use this…
MI5 Warns Over 100 Academics Helped China’s Espionage Plans
MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute
Losing gamblers pushed to bet more by DraftKings’ AI, report says
Betting site DraftKings has been accused of using AI to target gamblers likely to lose more after receiving promotions. The company disputes the findings.
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped.…
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers’ increasingly advanced capabilities.
IT Security News Hourly Summary 2026-10-02 23h : 4 posts
4 posts published in the last hour 20:31Detecting Host Header Injection & Open Redirects 20:01Frontline Education breach exposes school district employee data 20:01ICE Has Been Dumping Protester Photos Into a Palantir Database 20:00IT Security News Hourly Summary 2026-10-02 22h :…
Detecting Host Header Injection & Open Redirects
By HOC Team | Updated: September 2026 |Read time: ~16 min While Cross-Site Scripting (XSS) and SQL Injection…
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized…
ICE Has Been Dumping Protester Photos Into a Palantir Database
DHS agents not only tracked and intimidated people observing ICE activity in Maine, but stored information about them in a Palantir-built database, newly…
IT Security News Hourly Summary 2026-10-02 22h : 11 posts
11 posts published in the last hour 19:31Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware 19:31Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path 19:31‘North Korean’ Attackers Steal $387.5m From Bitget…
Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware
Gemini 4 starts with cybersecurity MI5 flags Chinese research funding Custom GPTs steer users into ClickFix attacks Get the show notes here:…
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in…
‘North Korean’ Attackers Steal $387.5m From Bitget
Exchange Bitget resumes transactions after suspected North Korean attackers carry out biggest single crypto heist so far this year
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond andrew.gertz@t… Wed, 09/30/2026 – 20:13 Data Security Todd Moore | Global VP of Data…
Sydney Data Centre Plan Withdrawn After Protests
Developer Goodman Group pulls plan for 90 MW data centre that it intended to build in Sydney suburb near homes, schools
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting…
What enterprises need to know about the Cyber Resilience Act and software supply chain risk
In part 1 of this series, we examined why enterprises need more than an inventory of the open source components in their software. Understanding where…
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security…
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing…
What enterprises need to know about the software they depend on
Knowing an application contains open source components is not the same as understanding the software and communities behind them.For many organizations,…
IT Security News Hourly Summary 2026-10-02 21h : 10 posts
10 posts published in the last hour 18:31Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents 18:31Fire That Killed Four Linked To Lithium-Ion Battery 18:31MetaMask Security Incident Prompts Exit of Affected Ethereum Validators…
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’…
Fire That Killed Four Linked To Lithium-Ion Battery
Electrical event caused lithium-ion battery to go into thermal runaway, sparking intense fire that killed mother, three children
