7 posts published in the last hour 08:31Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover 08:31TikTok phishing: How to spot fake login and verification pages 08:31Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac…
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard…
TikTok phishing: How to spot fake login and verification pages
Scammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.
Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into…
CISA Warns of Exploited Oracle WebLogic Vulnerability
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs…
78 arrests in bust of major Western Mediterranean smuggling network in Spain
The operation, conducted under a newly established Europol Taskforce within Europol’s European Centre Against Migrant Smuggling, brought together officers…
IT Security News Hourly Summary 2026-08-25 10h : 12 posts
12 posts published in the last hour 07:31China Approves Limited Imports Of Nvidia’s H200 07:31SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing 07:31Top Google Results for Minecraft Client Led Gamers to Malware, McAfee…
China Approves Limited Imports Of Nvidia’s H200
Large Chinese tech groups begin receiving shipments of H200 AI chips, as regulators seek to boost domestic AI development
SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing
SynkLoader throws in the kitchen sink NIST flags multi-cloud sprawl ReliaQuest blocks a ShinyHunters swing Get the show notes here:…
Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds
Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks
TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The…
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle…
When violence shapes identities in a larger pool of perpetrators: new Europol terrorism report
Terrorism in Europe is entering a new phase. The latest European Union Terrorism Situation and Trend Report (EU TE-SAT) 2026, published today, shows how…
Threats Making WAVs – Incident Response to a Cryptomining Attack
Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report…
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens.…
What Happens When AI Becomes Your Penetration Tester? TryHackMe Research
Yes, even Penetration tester can miss hidden vulnerabilities. No matter how deeply you test a system, some security…
TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These…
IT Security News Hourly Summary 2026-08-25 09h : 7 posts
7 posts published in the last hour 06:31AI supply chain risk is showing up in developer workflows first 06:31Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions 06:03TruffleHog AWS Analyze reduces remediation time on leaked AWS…
AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still…
Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo…
TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials
Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to…
The Nansh0u Campaign – Hackers Arsenal Grows Stronger
In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses…