Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a…
Hackers Use ERP Web Shell and IDOR Flaws to Breach Major South Korean Churches
Attackers breached two of South Korea’s largest churches through distinct intrusion chains, combining an ERP web shell, privileged database access, leaked…
Anthropic Mythos AI Finds Rejetto HFS Flaw That Lets Attackers Forge Admin Sessions and Execute Code
Anthropic’s Mythos AI has identified a critical vulnerability in Rejetto HTTP File Server that could allow remote attackers to forge administrator…
TTY Logs and the Data it Captures, (Sun, Oct 4th)
For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they…
Critical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands
Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious…
IT Security News Hourly Summary 2026-10-07 14h : 15 posts
15 posts published in the last hour 11:02The ASOS incident: When attackers use the channels customers trust 11:02Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month 11:02Chrome 155 Update Patches 247 Vulnerabilities 11:02Elastic Patches 14 Security Flaws,…
The ASOS incident: When attackers use the channels customers trust
ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s…
Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month
COPENHAGEN, Denmark, 7 October 2026 – Heimdal today officially launches the “Cyber in 60” weekly video series in which Adam Pilton, a former cybercrime…
Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among these, a…
Anthropic Creates Three Tiers for Claude Cyber Access
Anthropic created three access tiers for Claude’s offensive security use, matching cyber capabilities and safeguards to the user’s level of trust.…
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could…
Another ShinyHunters suspect arrested
The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member.
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
Tens of thousands more victims and more ransomware groups getting in on the act
Musician sent to prison for $10 million streaming fraud using AI bots
A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music,…
OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack
OpenSSH released version 10.6 on October 6, 2026, to address security vulnerabilities that affect encrypted sessions, file transfers, authentication, and…
Update Chrome and ChromeOS to fix critical security issues
Google has released a new update for the Chrome browser and ChromeOS. There are a lot of security fixes in them so don’t delay.
Critical Veeam Backup & Replication Flaw Allows Low-Privileged Users to Execute Remote Code
Veeam released security updates to address a critical vulnerability that lets low-privileged users execute remote code on Veeam Backup Servers. Identified…
Advantest confirms personal information stolen in ransomware attack
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. […]
LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension
A campaign that uses more than 100 compromised websites to distribute LUNEXSTEALER, a Windows infostealer that installs a browser extension giving…
IT Security News Hourly Summary 2026-10-07 13h : 16 posts
16 posts published in the last hour 10:32Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns 10:32Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks 10:31Anthropic Introduces 3-Tier Cyber Verification Program for AI Access 10:31Cursor writes…
Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
A Yubico survey identified a significant gap between awareness and adoption of secure methods of authentication in enterprises
Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks
WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting, SQL injection, information disclosure, and…
Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.
