Critical SolarWinds flaws and compromised MemTensor packages create opportunities for remote code execution and credential theft, while an AI-agent breach…
OpenAI agent breached Australian government site, took months to report it
The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?
OpenAI agent breached Medicare statistics site, then took months to report it
The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?
AvisLoader Windows Malware That Learned to Survive Even After Its Servers Are Taken Down
AvisLoader is a Windows malware loader built to keep taking instructions after server takedowns. That makes it difficult to disrupt by simply removing a…
Symphony Risk Intelligence uses AI agents to streamline financial crime investigations
SymphonyAI has introduced Symphony Risk Intelligence (SRI), an enterprise-grade, agent-native platform built to unlock Always-on Compliance. This is a…
Fake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations
A newly documented campaign targeting people and organizations focused on Ukraine uses document-themed Windows shortcuts to install a malware downloader…
IT Security News Hourly Summary 2026-09-24 16h : 27 posts
27 posts published in the last hour 13:32Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider? 13:31Crackdown on Italian organised criminal network involved in large-scale euro counterfeiting 13:31Uncovering a SectopRAT Variant Embedded in Legitimate Software 13:31ISC…
Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider?
AI agents are moving into the enterprise much faster than most security programs were designed to handle. They are no longer just answering questions or…
Crackdown on Italian organised criminal network involved in large-scale euro counterfeiting
Europol has supported an international operation targeting a criminal network linked to the Italian mafia-type organisation Camorra. The operation,…
Uncovering a SectopRAT Variant Embedded in Legitimate Software
Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control
ISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104, (Tue, Sep 22nd)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104,…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Data Quality Overtakes Skills as Top Threat Hunting Challenge
Data quality has emerged as the primary obstacle facing threat hunting teams, overtaking skills shortages for the first time in five years of tracking by…
Jev Is Not a Language Model, but It Breaks Like One: Prompt Injection Against a Typed Decision Model
A new kind of AI model returns decisions instead of text. We spent a day trying to change its mind. It cost about 50 cents. In this article Jev is a new…
The Nansh0u Campaign – Hackers Arsenal Grows Stronger
In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses…
New Browser Guard features add protection before and after you click
Spot dangerous sites before you click—and check for scams once you’re there.
NIST Updates OT Security Guide; CISA/FBI ICS Advice
The National Institute of Standards and Technology has opened Revision 4 of its operational technology security guide for public comment, with the…
CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers,…
AI-Powered Campaign Targets Hundreds of Online Retailers
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.
CISA Charts New “Quality Era” for Global CVE Program
CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise
Australia to investigate if OpenAI hack of government health website broke the law
The incident is the first known breach to affect a government agency, and Australia’s prime minister has vowed to hold OpenAI accountable.
Google to critical infra orgs: Our AI scanners won’t be evil, promise
Gemini 3.8 Flash Cyber and Wiz’s Red Agent team up to protect hospitals, public transit, and tech
Malicious Firefox Extension Disguised as PDF Tool Steals Google Account Sessions
A Firefox add-on posing as a tool for opening protected PDF documents can quietly turn a signed-in browser into a route to Google account theft. It waits…
OpenAI agent hacking spree widens to Australia, targeting government website
Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government…
