Small businesses and cyberattacks are often discussed as if they belong to separate worlds. E3nterprise organizations are seen as high-value targets,…
IT Security News Hourly Summary 2026-08-31 10h : 8 posts
8 posts published in the last hour 07:31A week in security (August 24 – August 30) 07:31The OpenClaw 2.0 release moves your sessions into SQLite 07:31ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach 07:31ChatGPT Conversations Are Being Used as Court…
A week in security (August 24 – August 30)
A list of topics we covered in the week of August 24 to August 30 of 2026
The OpenClaw 2.0 release moves your sessions into SQLite
OpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor…
ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach
ServiceNow warns of three maximum severity security vulnerabilities PaperCut zero-day exploited in attacks Healthcare giant McKesson discloses breach Get…
ChatGPT Conversations Are Being Used as Court Evidence With No Legal Privilege Protecting Them
It has become more and more common for people to have private conversations with AI chatbots such as ChatGPT, and such conversations do not benefit from…
TerminalFix: Fake Cloudflare CAPTCHA Campaign Deploys Reverse-Tunnel Backdoor
Security researchers at Microsoft have uncovered a sophisticated social engineering campaign called TerminalFix. A new type of ClickFix…
More Details Emerge on Exploited PaperCut Vulnerabilities
PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578.
Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files
Composer users are urged to update their software following the disclosure of a path-traversal vulnerability. This flaw could allow a malicious or…
IT Security News Hourly Summary 2026-08-31 09h : 5 posts
5 posts published in the last hour 06:31Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication 06:31What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 06:31TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to…
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
A critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via…
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point…
TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks
A sophisticated ClickFix variant dubbed TerminalFix that uses fake Cloudflare CAPTCHA prompts to trick users into executing attacker-controlled PowerShell…
Halo-record: Open-source audit trails for AI agents
Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data…
IT Security News Hourly Summary 2026-08-31 08h : 7 posts
7 posts published in the last hour 05:32Hackers Use Infostealer Malware to Steal Claude Session Cookies and Hijack Accounts 05:3150 SOC Analyst Interview Questions and Answers (2026 Guide) 05:31Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices…
Hackers Use Infostealer Malware to Steal Claude Session Cookies and Hijack Accounts
Anthropic’s Claude AI platform is currently dealing with two separate cybercrime campaigns that aim to steal account credentials, misuse paid…
50 SOC Analyst Interview Questions and Answers (2026 Guide)
By HOC Team | Last updated: August 30, 2026 | Read time: ~26 min 50 SOC Analyst Interview…
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
A recent router-level DNS change is gaining attention as a method to reduce exposure to phishing pages and malware across all devices connected to a home…
AI AppSec tools agree on just 5% of security findings
Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of…
Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
A compromised attacker-side workstation has given researchers an unusual view into the operational ecosystem behind a suspected Blind Eagle malware…
Free ChatGPT users get ads picked from whatever they just asked about
Say you’re on the free plan and you ask ChatGPT to help you pick a mattress. An ad may turn up next to the answer, and it got there because of what you…
OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
OpenAI has issued a warning regarding Astra, an upcoming artificial intelligence model, which may be close to a threshold of cybersecurity capabilities…
Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts
Anthropic’s Claude AI platform has become an active target for cybercriminals, with two distinct attack chains now confirmed to be stealing credentials,…
ShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid tech
Shiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech Host David Shipley covers…