RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through…
Connective eID Extension Flaws Let Attackers Steal Belgian ID PINs and Trigger Drive-By RCE
Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic…
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails
Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into…
IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to…
Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT
Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan. The campaign shows…
HP ThinPro TPM Flaw Lets Attackers Bypass Full Disk Encryption and Steal LUKS Keys
A security researcher has revealed a critical design flaw in HP ThinPro versions 8 and 9, which allows attackers with physical access to a thin client’s…
Hackers Distributing Malicious VBS/PowerShell RAT Chain Via Multiple DuckDNS Hosts
A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft. The chain relies on Visual Basic…
WordPress Supply Chain Attack Exploits BdThemes Plugins to Create Rogue Admin Accounts and Install Webshells
A supply chain compromise affecting multiple BdThemes WordPress plugins has allowed attackers to hijack administrator sessions, create unauthorized admin…
Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval
RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira,…
Apple Private Cloud Compute Path Traversal Flaw Lets Attackers Write Files as Root
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a…
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.
Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a…
IT Security News Hourly Summary 2026-08-10 12h : 7 posts
7 posts were published in the last hour 9:31 : A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark 9:31 : US Sanctions Iranian $6bn Crypto “Exchange” Shelbit 9:31 : Ransomware Attackers Compromise Multiple Employees Inside the Same Company…
A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark
Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes…
US Sanctions Iranian $6bn Crypto “Exchange” Shelbit
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange
Ransomware Attackers Compromise Multiple Employees Inside the Same Company
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month…
Anthropic to put AI in charge of reviewing Claude Code actions by default
Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a…
DeepSeek Restarts Second Funding Round
AI start-up reportedly recommences second funding round, seeking funds for data centre investment, at valuation of nearly $74bn
Corporate Data Stolen in Levi Strauss Cyberattack
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.
IT Security News Hourly Summary 2026-08-10 11h : 7 posts
7 posts were published in the last hour 8:31 : Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials 8:31 : Claude Opus 5 Most Resistant to Indirect Prompt Injection Attacks, With Just 2% Success Rate 8:31…
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been…
Claude Opus 5 Most Resistant to Indirect Prompt Injection Attacks, With Just 2% Success Rate
Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15…
Nscale May Hold IPO In September – Report
London-based data centre start up reportedly says it has $51bn in contracted revenue, could make US market debut as early as September