Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such…
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.
Former X-Force hackers chase the offensive cyber gold rush
RemoteThreat launches with $7M, 1,000 attack tools, and ambitions to equip enterprises and Uncle Sam for AI-speed operations
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
A teen hacker found an authentication flaw in Microsoft’s Titan analytics service, where metadata indicated an estimated 17.3…
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.
Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.
Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain
Threat actors are abusing ChatGPT’s Custom GPT feature to funnel victims into a ClickFix attack that ends with a full-featured remote access trojan (RAT),…
Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
A malicious file could trigger the vulnerability. Apple says it may already have been used against iPhone users.
Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk
Proton has extended Easy Switch for Business, its guided migration tool, to Microsoft 365. Organisations can now move email, calendars and contacts from…
IT Security News Hourly Summary 2026-09-29 13h : 19 posts
19 posts published in the last hour 10:32Fake iPhone Duo preorder scam triggers DarkSword attack 10:31Cyber Resilience Act Single Reporting Platform (CRA-SRP) obligations for software companies selling globally 10:31DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware 10:31CrowdStrike…
Fake iPhone Duo preorder scam triggers DarkSword attack
A fake iPhone Duo preorder page promises a $500 voucher. Open it on a vulnerable iPhone, and it tries to break in before you fill out the form.
Cyber Resilience Act Single Reporting Platform (CRA-SRP) obligations for software companies selling globally
I wrote here about the CRA and the deployment plan: https://www.sorinmustaca.com/eu-cyber-resilience-act-cra-overview/ We are past September 11th and the…
DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a…
CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
OpenAI Model Gained Unauthorized Access to Australian Government Systems
OpenAI has disclosed that an experimental internal AI model accessed several Australian government systems without authorization during training and…
OperTraitors: How Kubernetes Operators Betray Your Security Posture
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities.
Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
WatchGuard has announced the discovery of three high-impact vulnerabilities in its wireless access point platform. Two of these critical issues allow…
Palo Alto Networks and NVIDIA want tighter control over AI agents
Palo Alto Networks is expanding its work with NVIDIA to help companies control what AI agents can access and do. The collaboration covers agent activity,…
wolfSSL 5.9.4 Patches 11 Security Flaws Affecting TLS and Certificate Validation
wolfSSL has released version 5.9.4, which addresses 11 security vulnerabilities related to TLS and DTLS handshakes, X.509 certificate validation,…
SilverFox Built Fake Software Sites That Know When Researchers Are Watching
SilverFox-linked operators are evolving beyond counterfeit software portals and signed-binary abuse by using visitor-aware delivery infrastructure that…
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. “It is true that this…
Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core…
Japanese Railway Operators Hit with Weekend Cyber Attacks
Tokyo Metro and Keio have revealed separate cyber-attacks
Protego Ventures closes debut $125 million fund for Israeli defense tech
Protego Ventures, the first and largest dedicated defense tech VC in Israel, just completed its final $125 million closing, TechCrunch learned exclusively.
