A guide on how to check if hackers have broken into your accounts on the most popular AI platforms.
GeoServer Zero Day Being Probed While No Patch Available
A newly found GeoServer zero-day is already receiving active exploitation efforts, while there is no patch ready yet. Firms using the open-source…
IT Security News Hourly Summary 2026-08-15 17h : 5 posts
5 posts published in the last hour 14:31How To Prevent The Scaling Of Identity Fraud In Online Gaming 14:31Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC 14:31CISA Warns of Critical Flaw in Johnson Controls Metasys Systems…
How To Prevent The Scaling Of Identity Fraud In Online Gaming
The online gaming industry has exploded, attracting not only millions of legitimate players but also sophisticated fraudsters who are looking to exploit…
Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC
Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security…
CISA Warns of Critical Flaw in Johnson Controls Metasys Systems
Critical Flaw Disclosed in Building Automation System A serious vulnerability in Johnson Controls’ Metasys building automation technology was reported in…
Shell Investigating Data Breach Following Cl0p Ransomware Group Claim
Multinational energy giant Shell has launched an active investigation after the notorious Cl0p ransomware syndicate claimed responsibility for…
How AI Helps Defenders Keep Up and Where It Still Falls Short
Security teams today are more capable than ever, yet they are still falling behind. Organizations have invested heavily in tools designed to stop…
UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON
UK eyes AI gene-synthesis guardrails DeadLock puts ransomware on the blockchain An evil twin flies home from DEF CON Episode show notes:…
IT Security News Hourly Summary 2026-08-15 14h : 4 posts
4 posts published in the last hour 11:31Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication 11:02ChainDrop worm crawls into npm supply chain, evades standard defenses 11:01Critical macOS Screen Sharing Bug (CVE-2026-65400) Exploitation to Install…
Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication
Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in…
ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
Critical macOS Screen Sharing Bug (CVE-2026-65400) Exploitation to Install Monero Miners
Cybersecurity agencies, including the Netherlands National Cyber Security Centre (NCSC-NL), have issued urgent warnings regarding active macOS screen…
IT Security News Hourly Summary 2026-08-15 13h : 3 posts
3 posts published in the last hour 10:31Attackers Exploit SharePoint Authentication Bypass After Public PoC Release 10:01Passwords stored in public Google Doc then showed up in search results 10:00IT Security News Hourly Summary 2026-08-15 12h : 3 posts
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The…
Passwords stored in public Google Doc then showed up in search results
Developer spotted hostname and credential string lurking in autocomplete
IT Security News Hourly Summary 2026-08-15 12h : 3 posts
3 posts published in the last hour 09:31macOS Screen Sharing Flaw Exploited to Deploy Monero Miners 09:01Microsoft Makes Passkeys Default in Entra ID, Retires SMS and Voice Authentication 09:00IT Security News Hourly Summary 2026-08-15 11h : 3 posts
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National…
Microsoft Makes Passkeys Default in Entra ID, Retires SMS and Voice Authentication
Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice…
IT Security News Hourly Summary 2026-08-15 11h : 3 posts
3 posts published in the last hour 08:31Ruby 4.0 Marshal.load RCE Gadget Chain Exposes Critical Deserialization Risk 08:31GeoServer Zero-Day Is Already Being Probed. That’s the Problem 08:01Download More RAM Attack Bypasses Windows VBS, HVCI and Disables Microsoft Defender
Ruby 4.0 Marshal.load RCE Gadget Chain Exposes Critical Deserialization Risk
A newly disclosed universal deserialization gadget chain shows how a single unsafe Marshal.load operation can reportedly produce remote command execution…
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed…
Download More RAM Attack Bypasses Windows VBS, HVCI and Disables Microsoft Defender
A newly disclosed Windows attack technique, dubbed “Download More RAM,” can undermine Virtualization-Based Security (VBS), bypass Hypervisor-Protected…
Microsoft Copilot App Overhaul Merges Personal Chats and Ends Podcasts, Deep Research
Microsoft is reshaping its consumer and productivity AI strategy with a major update to its Copilot application, merging personal chat histories and…