Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of…
IT Security News Hourly Summary 2026-09-22 13h : 23 posts
23 posts published in the last hour 10:32Rogue AI agents put trusted access under scrutiny 10:32WordPress Patches ‘Click2Shell’ Vulnerability 10:32Researchers used Claude to hack OpenAI 10:32U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog 10:32A New Tool Found…
Rogue AI agents put trusted access under scrutiny
Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently…
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
Researchers used Claude to hack OpenAI
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something…
Top 10 Best Passwordless Authentication Solutions in 2026 [Ranked & Scored]
The password’s obituary has been written for a decade, but 2026 is the year the funeral actually gets scheduled: platform passkeys are mainstream,…
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure.
Texas utility CenterPoint confirms breach after attacker leaks customer data
Texas utility CenterPoint Energy has confirmed a data breach after a threat actor published customer information online and claimed to have stolen around…
CISA Warns of Zyxel GS1900 Switches Flaw Actively Exploited in Attacks
CISA added CVE-2026-7273, a critical stack-based buffer overflow in the CGI program of Zyxel GS1900 Series Switches, to its KEV catalog after confirming…
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical Orkes Conductor flaw is under active attack, with 6,696 exploit attempts blocked in a week. Defenders should upgrade to version 3.30.2 or later.
Top 10 Best Customer Identity & Access Management (CIAM) Solutions in 2026 [Ranked & Scored]
Customer identity is where security meets revenue: every point of login friction costs conversions, while every authentication gap invites account…
Gemini crosses the line in cybersecurity test
Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets…
ZTE SmartLife Flaws Let Attackers Hijack Accounts by Resetting Passwords Without Verification
ZTE has addressed four vulnerabilities in its SmartLife mobile application following the discovery of critical weaknesses that allowed attackers to…
Vidar Malware Rewrites Its Obfuscation With Every Build to Make Detection Harder
Vidar has spent years stealing the data people keep closest: saved passwords, browser cookies, wallet files and system details. Now its operators have…
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to…
Hackers Steal NTDS.dit to Dump Active Directory Password Hashes and Forge Golden Tickets
Threat actors that gain a foothold in a Windows network are increasingly aiming for the domain controller, the server that manages identities and…
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in…
Top 10 Best Identity Threat Detection & Response (ITDR) Tools in 2026 [Ranked & Scored]
The modern breach doesn’t kick the door in it signs in. Stolen sessions, abused service accounts, and helpdesk-reset social engineering made identity the…
LimeLeads – 17,838,396 breached accounts
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The…
D-Link Router Hit by CVSS 10.0 Flaw Exploitable Remotely Without Authentication
D-Link Systems has disclosed that it is investigating a critical security vulnerability in its DIR-822A router, tracked as CVE-2026-86296. The flaw has…
Introducing CAIRN: Frontier tracking for AI-integrated malware
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
Windows COM Flaw Lets Attackers Gain SYSTEM Privileges With a Malicious DLL
A newly detailed Windows privilege escalation flaw tracked as CVE-2026-66804 allowed a standard, low-privileged user to plant a malicious DLL and execute…
