Microsoft Teams is preparing to support synthetic audio and video detection to help organizations spot deepfake attacks. The feature will connect Teams…
Making sure the checks get printed
Pierre’s debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn’t an…
Tensorlake npm Package Compromised to Spread Shai-Hulud Worm and Steal Developer Secrets
A malicious release of the Tensorlake npm package has been published with a Shai-Hulud worm variant that can steal developer secrets and attempt to spread…
Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
Hikvision Camera Vulnerability Targeted in Remote Code Execution Exploitation Attempts
Scanning and remote code execution attempts targeting video surveillance devices in Ukraine rose between September 21 and October 1, 2026. Most activity…
6 alternatives to Blackpoint for your shortlist
Blackpoint is a well-regarded provider of managed detection and response services to the MSP sector. Founded by former NSA employees, their autonomous…
Legacy sign-on service comes back to bite school software provider Bromcom
Intruders retrieved email addresses from superseded tech kept running for an internal system
FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push…
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released…
OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media
The two campaigns were rated 4 and 5 out of 6 for severity, the first time OpenAI has reported what it considers a high-impact influence campaigns.
IT Security News Hourly Summary 2026-10-08 20h : 12 posts
12 posts published in the last hour 17:31Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks 17:31Solving the Continuous Authorization Conundrum 17:02FBI, French authorities seize deepfake CSAM-for-sale websites 17:02CIA officer admits to creating fake…
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT…
Solving the Continuous Authorization Conundrum
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Solving the Continuous Authorization Conundrum
FBI, French authorities seize deepfake CSAM-for-sale websites
Some of the material appeared to be recorded or stolen video of girls through interactions on social media sites like Snapchat, TikTok, Instagram and…
CIA officer admits to creating fake top secret government program to steal over $190M, including gold bars
CIA officer David Rush, who worked on highly sensitive intelligence programs, reached a plea deal with U.S. prosecutors after he was caught siphoning…
3 lessons from frontier AI vulnerability research
Read how How Microsoft Security’s FORGE Lab is scaling vulnerability research from Windows to the Linux kernel.
Ordering violence from abroad: five suspects arrested in Spain, Morocco, and France
Five suspects linked to the organisation and recruitment of serious violence have been arrested in Spain, Morocco, and France, in the latest results of…
AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
Strands Box is the latest open source AI control tool from the cloud giant; like its predecessors, it promises tighter reins on autonomous agents
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access…
Putting Guardrails Around What Your AI Agent Is Allowed to Touch
This article is for platform engineers, data engineers, security architects, and AI application teams building enterprise agents that retrieve data, call…
Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we…
Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise
Credential-stealing malware detected within minutes of npm release, but impact remains unknown
IT Security News Hourly Summary 2026-10-08 19h : 30 posts
30 posts published in the last hour 16:32Attackers hijack country-code domains to impersonate Google and other services 16:32How DNS, Firewalls and Endpoint Tools Block Websites 16:31Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance 16:31AI Watermarking Meant to…
Attackers hijack country-code domains to impersonate Google and other services
Cybercriminals compromised three country-code namespaces to get certificates that could help them impersonate trusted sites.
