The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
Medical records, SSNs, and bank details exposed in CareCloud data breach
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.
New Agent Tesla Malware Variant Boosts Evasion Capabilities
An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed
Bandwidth-Sharing App Can Turn Employee Devices Into Gateways to Internal Networks
A bandwidth-sharing app installed by an employee can quietly turn a work device into a gateway for outside traffic. The software may not behave like…
Attackers impersonate popular AI brands to spread malware
Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser…
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal…
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense…
Russian Hackers Abuse OAuth and WhatsApp Device Linking to Hijack High-Value Accounts
Suspected Russian cyber-espionage groups are increasingly turning ordinary sign-in and device-linking features into tools for account takeover. Their…
IT Security News Hourly Summary 2026-08-21 14h : 5 posts
5 posts published in the last hour 11:31OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing 11:31Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 11:31Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault…
OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private…
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal…
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
Cybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or…
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers…
IT Security News Hourly Summary 2026-08-21 13h : 5 posts
5 posts published in the last hour 10:31Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords 10:31Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing 10:02More Incidents of AIs Going Rogue in Cybersecurity…
Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and…
Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender’s threat model. Its latest…
More Incidents of AIs Going Rogue in Cybersecurity Challenges
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior —while being tested…
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska,…
IT Security News Hourly Summary 2026-08-21 12h : 11 posts
11 posts published in the last hour 09:31Sakura Internet Breach – Hackers Accessed 1.36 million Customers’ Personal Records 09:31Rust Supply Chain Attack Linked to North Korean Hackers 09:31DOJ Charges 17 Iranian Hackers in IRGC-Linked Campaign That Stole 31.5TB of Research…
Sakura Internet Breach – Hackers Accessed 1.36 million Customers’ Personal Records
Sakura Internet has disclosed a potential breach involving its sales management system, placing the personal records of up to 1.36 million customer…
Rust Supply Chain Attack Linked to North Korean Hackers
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
DOJ Charges 17 Iranian Hackers in IRGC-Linked Campaign That Stole 31.5TB of Research Data
The U.S. Department of Justice has unsealed a 14-count superseding indictment against 17 alleged members of the Iran-based Mabna Institute, accusing them…
Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to…
OpenAI Offers Zero Data Retention for Frontier AI Models With Private Safety Processing
OpenAI has announced Zero Data Retention for eligible API customers using its frontier AI models, alongside a new Private Safety Processing system…