A large-scale phishing operation has compromised thousands of Microsoft 365 accounts by stealing authenticated session cookies that remain valid even…
ASML Breaks Ground On New Plant Amid Booming Demand
Netherlands’ ASML begins construction of 35-hectare plant 7km from headquarters, as Samsung, TSMC adopt new tools
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The…
Amazon Sued For Firing Pregnant Workers
US federal lawsuit claims Amazon routinely denies basic accommodations to pregnant workers, fired some for taking time off
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
The three Indian companies are accused of using hackers to steal information used to sway litigation.
EU’s Cyber Resilience Act starts the 24-hour vulnerability clock
Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA’s new reporting platform
This $50 lifetime VPN adds AI-powered protection to your connection
Get AI-powered threat protection, encrypted connections, and more with this VPN lifetime subscription today.
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities…
AI adoption that pays off is built around keeping humans in the driver’s seat
I’ve spent enough time around AI adoption now to notice a pattern. Ask a business how AI is going for them and the honest answer is, lately, “we’ve got…
Singapore man pleads guilty to $245M crypto theft
A 22-year-old Singapore national has admitted to leading a criminal operation that stole more than $245 million in cryptocurrency from victims’ digital…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
NHIs Now the Number One Corporate Entry Point for Hackers
SpyCloud claims non-human identities are the most likely route into the enterprise
Jellyfin 12.0 releases security fixes
Jellyfin has released version 12.0 of its media server platform with several critical security patches addressing vulnerabilities that could expose files…
IT Security News Hourly Summary 2026-09-11 14h : 16 posts
16 posts published in the last hour 11:32cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw 11:32Check Point Patches Critical VPN Vulnerabilities 11:32Sequoia doubles down on Cymphony as AI agents create new enterprise security risks 11:32ShinyHunters claims Florida…
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands…
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Cymphony gives security teams a single view of employees, AI agents, and other nonhuman identities, including the systems and sensitive data they can…
ShinyHunters claims Florida DMV breach
The notorious cybercrime group ShinyHunters has claimed responsibility for breaching Florida’s Department of Highway Safety and Motor Vehicles, allegedly…
Cliff Stoll’s DEF CON Talk
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.
WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
DeepSeek Harness Sandbox Bypass Flaw
Security researchers have identified a critical sandbox escape vulnerability in DeepSeek Harness, the open-source framework developed by DeepSeek for…
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.
Open Standard for Revocable API Keys Proposed
Security researchers have proposed an open standard designed to make API keys self-destruct within 60 seconds of being detected as leaked.
IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web
IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500…