Docker patched two serious vulnerabilities in Docker Sandboxes that could let a malicious guest workload break out of its intended shared workspace and…
The latest AI doomsayer is China’s intelligence boss
Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service…
Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM
A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation. The…
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The…
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be…
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its…
North Korean IT Workers Use AI and Remote Desktop Tools to Fake Technical Interviews
North Korean operators are using artificial intelligence, remote-control software, and hired stand-ins to make fraudulent job candidates look genuine…
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new…
FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor
FamousSparrow has introduced a new backdoor called SparroWocky after breaking into public-facing Microsoft Exchange servers. The campaign shows how a…
CISO’s Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one…
Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino
A compromised Thai college website was quietly turned into a springboard for an illegal online casino, according to new findings from anti-fraud platform…
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the…
SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis…
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on…
Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated…
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in…
IT Security News Hourly Summary 2026-09-17 16h : 24 posts
24 posts published in the last hour 13:32AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape 13:32ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th) 13:32Download: The IT leader’s guide to AI…
AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape
Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their…
ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094,…
Download: The IT leader’s guide to AI code sprawl
AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI…
HBO Max Reddit account hijacked for malware
Cybercriminals compromised HBO Max’s verified Reddit account and used it to distribute malware through 108 malicious advertisements over approximately 48…
