Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow…
Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity
More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.
CISA Flags Citrix NetScaler Flaw Exploited in Ongoing Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779, a high-severity vulnerability affecting Citrix NetScaler ADC…
Detained ShinyHunters hacker reportedly helping FBI track down fellow members
A suspected ShinyHunters member known as Rey has been detained in Jordan and is reportedly helping the FBI track down the rest of the group. Reuters…
Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records
Denmark has confirmed a serious cybersecurity incident involving unauthorized access to personal information in its Central Person Register (CPR),…
IT Security News Hourly Summary 2026-10-05 13h : 10 posts
10 posts published in the last hour 10:31MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components 10:02MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board 10:02MI5 Raises Alarm Over Chinese Funding of UK Academic…
MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components
MediaTek has released its October 2026 Product Security Bulletin, which addresses 31 vulnerabilities across modem, video, AI processing, display, trusted…
MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board
CircuitMess, a Croatian electronics kit maker, is selling MAKERphone 2.0, a build-it-yourself 4G phone on Kickstarter that buyers program in MicroPython…
MI5 Raises Alarm Over Chinese Funding of UK Academic Research
MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS. On September…
Google Tightens Open-Source Bug Bounty Rules After Surge in AI-Generated Vulnerability Reports
Google has stopped accepting new “product vulnerability” reports through its Open Source Software Vulnerability Reward Program (OSS VRP) due to a…
CISA Warns of Zammad DIVD Vulnerabilities Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog after…
Microsoft: Windows KB5124010 update crashes some games and apps
Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September…
Google’s AI Hacker Finds 500+ XSS Flaws and Builds Working Exploit Chains
Google has revealed an internal AI security agent that found more than 500 verified cross-site scripting, or XSS, flaws across its own web applications.…
AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could…
CISA Adds Fortinet FortiMail 0-day Vulnerability to KEV Following Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet FortiMail vulnerability (CVE-2026-104286) , to its Known Exploited…
IT Security News Hourly Summary 2026-10-05 12h : 12 posts
12 posts published in the last hour 09:31Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE 09:31More UK Schools Are Recovering Faster from Cyber Incidents 09:31Knowing which vulnerability to fix first 09:31Modernizing data security with DSPM, AI…
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in…
More UK Schools Are Recovering Faster from Cyber Incidents
Ofqual study finds growing number of UK schools are bouncing back “immediately” from cyber-attacks
Knowing which vulnerability to fix first
Common Vulnerability Scoring System (CVSS) severity tells you how serious a vulnerability could be. Exploit Prediction Scoring System (EPSS) estimates how…
Modernizing data security with DSPM, AI and fewer tools
For organizations, the proper safeguards—such as controls or restrictions—must be put in place.
What cloud infrastructure taught me about building billing systems
For years, I thought of billing as a domain I would have to learn from scratch. Ledgers. Taxes. Proration. Regulations. Money. After 11 years building…
Why permissions must be the foundation for next-gen identity security
Authentication isn’t enough. Monitor access across humans, machines and AI agents.
JDK 27: The quiet before the storm
Every September, with metronomic regularity, we have a new version of the Java platform. One small point about timing is that the first release candidate…
Frontline Education Breach Impacts K-12 School District Staff
A breach at school software provider Frontline Education has exposed employee data
