Security researchers have disclosed a critical pre-authentication RCE chain in CyberPanel that could let attackers gain a shell on vulnerable hosting…
ISO 27001 Implementation Guide: Step-by-Step Roadmap for 2026
By HOC Team | Last updated: August 2026 | Read time: ~28 min Most organisations pursuing ISO 27001…
US says hackers are targeting vulnerable water systems with the help of AI
Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States.
New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments
Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC…
US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate
Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high
The Nansh0u Campaign – Hackers Arsenal Grows Stronger
In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses…
Grok chat duped into swallowing injected instructions
A spoonful of encryption helps the malware go down
Claude AI Agents Escalate Into Malware Conflict During Anthropic Tests
During anthropopic’s latest testing, the company discovered a unique security risk associated with autonomous artificial intelligence systems. AI agents…
NCSC Urges Stronger Controls for Agentic AI Systems
NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents
IT Security News Hourly Summary 2026-08-20 15h : 20 posts
20 posts published in the last hour 12:31Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters 12:31Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities 12:31OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities 12:31Cisco External…
Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters
Red Hat has disclosed CVE-2026-66794, a high-severity Server-Side Request Forgery vulnerability affecting the cluster-proxy-addon component in…
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.
OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities
OpenAI has temporarily slowed the development of its latest frontier AI models after initial testing suggested that its upcoming Astra system may meet the…
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated…
Europol and Frontex strengthen cooperation with new Working Arrangement
The new arrangement replaces the agreement signed in 2015 and reflects the significantly expanded mandates that both agencies have received in recent…
Hackers Hide Malware Code Inside English Words to Infect Windows Users
A new Windows malware campaign is hiding malicious code inside ordinary English words, making the payload look less suspicious during analysis. The…
MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.
OpenAI Pauses AI Training Amid Concerns of New Model Potentially Discovering 0-Day Flaws
OpenAI has temporarily slowed frontier AI training after internal testing suggested that its upcoming Astra model may reach a critical cybersecurity…
Migrant smuggling network using rental cars dismantled across the Balkans
Led by the Greek authorities and supported by Europol, the investigation targeted a criminal network composed mainly of Syrian and Egyptian nationals…
Hackers Are Turning Claude, ChatGPT and Copilot Into Bait for Real Malware
Cybercriminals are increasingly using trusted artificial intelligence names as a shortcut to infect users with malware. Fake download pages, browser…
Using Microsoft Graph and Powershell to Mine for Information – Stale Accounts and Licenses, (Thu, Aug 20th)
Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s…
The Oracle of Delphi Will Steal Your Credentials
Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced…
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.
Season 4 of The Europol Podcast available now
The Europol Podcast is the official podcast of the EU’s agency for law enforcement cooperation. This season, we spoke to our Europol experts on the…