The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Bluesky says its recent outage was caused by another DDoS attack
This is the latest large-scale DDoS attack to hit the social networking site this year.
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
BTMob is an Android banking malware platform built to turn phones into tools for fraud. It reaches victims through fake apps, cloned download pages, and…
IT Security News Hourly Summary 2026-08-18 18h : 22 posts
22 posts published in the last hour 15:31GitLab issues emergency patch for critical code-injection flaw 15:31C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection 15:31CISA gives feds 3 days to fix actively exploited Ray RCE bug 15:31Webinar Today: Rethinking…
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.
C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection
C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer. It can run commands, inspect the…
CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks
Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest…
Vatican’s Official Prayer App Exposed Data of Over 700,000 Users
There was a security flaw in the Vatican’s official Click to Pray application that exposed personal information linked to more than 700,000 registered…
LiteLLM in the crosshairs: Supply Chain Attack on AI Infrastructure
Users of LiteLLM may have become targets of an attacker group. As early as March, it became known that the “TeamPCP” group had managed to obtain…
OpenAI Warns AI Models Can Automate Cyberattacks and Exploit Security Vulnerabilities
OpenAI has warned that advancing artificial intelligence models are increasingly capable of automating critical phases of real-world cyberattacks. This…
EU Launches New Brussels Team to Enforce AI Act Against Deepfakes and Hacking
The European Union rolled out a new enforcement team on Friday to rein in artificial intelligence companies worldwide, marking one of the most aggressive…
Why Threat Intelligence Feeds Often Fail to Meet SOC Expectations
Threat intelligence (TI) feeds are expected to close visibility gaps that inevitably emerge in enterprise SOCs and make investigations faster and more…
Amazon Handbook Warns About Online Shopping and Delivery Box Scams
Online shopping has become the new norm with millions of people shopping through online platforms like Amazon and Flipkart. Unfortunately, online shopping…
Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The…
Apple fixes another image-processing flaw that could allow code execution
Apple has released updates fixing 27 vulnerabilities in iOS, iPadOS, and macOS Tahoe, including a potentially serious image-processing flaw.
Octagon Can Steal SMS One-Time Codes During Banking and Crypto Account Takeovers
Octagon is an Android theft tool that turns an infected phone into a platform for account takeover. It can steal login details, watch the screen, and…
Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds
JWR Phishing Framework Uses Real-Time WebSocket Control and AES Encryption to Steal Banking Credentials
JWR is a phishing framework built for live fraud. It turns a fake payment or bank page into a live channel that lets criminals watch details arrive as…
Hacker Claims Millions of Records Stolen From Azure Tenants
A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns…
Kimsuky Expands Its Cyber Espionage Arsenal With Local AI Development Environment
Kimsuky, the North Korean espionage group, has expanded a campaign known as Operation GitPower with a local artificial intelligence development setup. It…
Meta Ran Ads for an App That Promised to Nudify Female Politicians
One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store…
Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS
Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application…
Apple plugs image-processing hole ripe for spyware abuse
Patch batch spans current kit, older iGadgets, Macs, and Vision Pro