Security researchers have identified a privilege escalation vulnerability in Windows 11 that exploits the operating system’s Plug and Play service to…
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to…
Chainloop: Open-source supply chain security tool
A new open-source tool called Chainloop provides organizations with an evidence store and policy engine for tracking software supply chain security.
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
The March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can…
Ceva Logistics Data Breach Impacts European Clients
Ceva Logistics disclosed a data breach affecting its European contract logistics operations, with eight warehouses compromised between July 29 and August…
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the cellular modules built into electric-vehicle…
Ransom Cartel Leader Sentenced to 16 Years
A federal court has sentenced Maksim Silnikau to 16 years in prison for leading the Ransom Cartel ransomware operation.
Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks
Police and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past…
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
Are AI tutors safe for your kids?
AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
IT Security News Hourly Summary 2026-08-11 14h : 15 posts
15 posts were published in the last hour 11:31 : AI for Military Support 11:31 : Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware 11:31 : OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber…
AI for Military Support
Interesting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming…
Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware
Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote…
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models
Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment
Proactive AI-native security vendor Horizon3 has announced a major $20 million investment into its global partner ecosystem. The funding reinforces the…
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July…
Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems
Security researchers have discovered 23 vulnerabilities in Copeland’s XWEB Pro commercial refrigeration controllers, with 21 rated as high severity. These…
New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines
A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings,…
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and…
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous…
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data…