Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment.…
MCP Python SDK Flaw Exposes OAuth Credentials
A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth…
Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks
Red Hat has fixed a high-impact vulnerability in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host…
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Google and Mozilla have released major security updates for Chrome and Firefox, collectively patching more than 100 vulnerabilities across both browsers.
Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials
Hackers are turning trusted software updates into a route for stealing developer and cloud credentials. Recent supply chain incidents show how a single…
Federal Agencies Disrupt Ransomware Gang Involving A 16-Year Old Member
An international law enforcement operation known as “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, resulting in…
Multiple Cpanel/WHM Vulnerabilities Allow Arbitrary Command Execution On Server
Multiple security flaws in cPanel & WHM could let attackers run malicious scripts in an administrator’s browser session or execute arbitrary commands as…
Cyber Briefing: 2026.09.30
Executive phishing, browser flaws, and AI-assisted development workflows are creating paths to account compromise, system exploitation, and unintended…
OpenClaw Launches Free Open-source Enterprise Agent Platform for AI Agents
OpenClaw has launched OpenClaw Enterprise (OCE), a free, open-source platform that helps organizations run persistent AI agents with stronger security and…
Oracle launches Fusion Claw AI agentic runtime
Oracle has introduced Fusion Claw, a governed agentic execution runtime designed to automate complex business processes for Oracle Fusion Applications…
Jailbreaking AI: What It Is and Why It Matters for Security
By HOC Team | Updated: October 2026 Read time: ~20 min In March 2023, a researcher posted…
AI Coding Agents Leak 13K Internal Images on GitHub
Security firm Glow has uncovered a widespread data exposure incident involving AI coding assistants that inadvertently published thousands of sensitive…
Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF
A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This…
Signal adds encrypted backups, cross-platform restore
Signal has finished rolling out cross-platform encrypted backup capabilities with iOS version 8.30, enabling users to transfer their complete message…
Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks
ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake…
Shadow AI governance creates security gaps
Employees are increasingly using unauthorized generative AI tools in ways that circumvent corporate security policies, creating what experts call “shadow…
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise
EU CRA requirements for containers and Kubernetes
The European Union’s Cyber Resilience Act (CRA), formally designated as regulation EU 2024/2847, entered its initial phase on December 10, 2024,…
IT Security News Hourly Summary 2026-10-02 16h : 31 posts
31 posts published in the last hour 13:32Crypto Scammers Hijack Microsoft’s Official X Account 13:32Shadow AI and the permissions problem: what to check before handing AI the keys 13:32AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub…
Crypto Scammers Hijack Microsoft’s Official X Account
Cybercriminals successfully hijacked Microsoft’s verified X account, leveraging its 13 million followers to promote a cryptocurrency scam built around the…
Shadow AI and the permissions problem: what to check before handing AI the keys
AI tools have moved from novelty to daily habit with remarkable speed, and for many people they are now as much a part of the working day as email. For…
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company…
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
Convincing Free Mobile phishing emails appear after data breach
Free Mobile customers received very convincing phishing emails after major data breach.
