Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom…
NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
Russia Issues Arrest Warrant For Telegram’s Durov
Telegram allegedly used by Ukrainian security services to recruit Russians to carry out sabotage, Russian authorities say
Rogue OpenAI Agents Breached Four Third-Party Services
Out-of-control AI models accessed four third-party services in addition to hacking Hugging Face, OpenAI says
Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft
Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure…
Shein Faces FTC Probe Ahead Of Hong Kong IPO
Cross-border fast-fashion retailer discloses that US trade regulator is investigating it, as it prepares for flotation
Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls,…
Meta, BlackRock To Jointly Fund Texas AI Data Centre
Under the deal to finance the $14bn data centre near El Paso, BlackRock will end up owning 80 percent of the 1 GW project
US and Allies Update SBOM Guidance
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.
Hackers Steal Data On Thousands From Education Department
Data breach affecting DfE help desk, Turing Scheme steals 607,000 records, data reportedly offered for sale online
Chrome 151 Patches 370 Vulnerabilities
The major browser update resolves roughly 80 critical- and high-severity security defects.
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another…
ShinyHunters Claims Responsibility for EY Data Breach as Investigation Continues
The cyberattack involving Ernst & Young (EY) has entered a new phase after the ShinyHunters extortion group claimed responsibility for the intrusion,…
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move…
OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money
OpenAI agent’s escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here:…
Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control
Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android…
IT Security News Hourly Summary 2026-07-30 09h : 13 posts
13 posts were published in the last hour 7:2 : Cisco Secure FMC Zero-Day Exploited in the Wild 7:2 : Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet 7:1 : Headteacher had the most guessable username-password…
Cisco Secure FMC Zero-Day Exploited in the Wild
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as…
Headteacher had the most guessable username-password combo you could imagine
Schools often don’t prioritize or understand cybersecurity
Data breach cost 2026 averaged $4.99 million, AI attacks ran higher
More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the…
Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling
The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These…
Excuses like ‘AI did it’ don’t exist in the eyes of the law
If your AI goes rogue, better have a good lawyer
Cisco Firewall Management Center 0-Day Actively Exploited to Access Sensitive Data
Cisco has released security updates for an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. This…