Researchers used AI to build WeWorm, a zero-click WeChat exploit that could hijack accounts through unanswered calls before Tencent mitigated the flaw.
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent of organizations believe they have visibility into their AI and machine…
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams,…
Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories
Cybercriminals are widening the reach of information-stealing malware by targeting the local data created by AI coding agents. The shift puts access…
Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs
Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using…
IT Security News Hourly Summary 2026-09-09 15h : 9 posts
9 posts published in the last hour 12:31$245 million in stolen crypto funded racketeering crew’s lavish lifestyle 12:31Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root 12:02Windows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote…
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth…
Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root
Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access,…
Windows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote Code
Microsoft has released security updates for CVE-2026-69485, an Important-rated remote code execution vulnerability affecting the Windows Remote Desktop…
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting “systematic extraction” of…
Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented…
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only…
Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Hackers are using Google Sheets as an unlikely control channel in a cryptocurrency theft campaign. The operation turns a familiar browser session into a…
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek’s open-source tool for running AI coding agents on a developer’s machine, let a sandboxed agent turn off its own…
IT Security News Hourly Summary 2026-09-09 14h : 8 posts
8 posts published in the last hour 11:31No alternative? A dangerous phrase for digital sovereignty 11:31Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory 11:31Claude Fable Solves a Historical Cipher 11:31Hack of the Berlin Senate…
No alternative? A dangerous phrase for digital sovereignty
The debate over the use of a US company within the Berlin administration serves as a prime example of the challenge Germany faces when it comes to digital…
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5…
Claude Fable Solves a Historical Cipher
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that…
Hack of the Berlin Senate Administration Will Have Consequences for Decades
A phishing email sets a consequential attack by a ransomware group in motion: In August 2026, data from the Berlin Senate Administration was leaked. The…
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.
Teaching AI to Reason Through Detection Triage
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Teaching AI to Reason Through Detection Triage
GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter…
IT Security News Hourly Summary 2026-09-09 13h : 27 posts
27 posts published in the last hour 10:32Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems 10:32Top 10 Best Mobile Threat Defense (MTD) Solutions in 2026 10:32Zscaler Agentic SOC combines AI agents with zero trust telemetry 10:32Ivanti Patches Critical…