A Russian national has been indicted in the United States over an alleged malware operation that targeted roughly 80,000 freelance workers worldwide.…
Building Securely From Day One: Palo Alto Networks Partners with the Zendesk Startup Program
A secure workspace for your team – so you can focus on building, not on what could go wrong. Every customer support agent starts their day the same way:…
Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools
Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and…
CISA scraps 6 free cybersecurity assessments for critical infrastructure operators
The agency’s decision, spurred by workload concerns, could leave organizations without valuable insights into their vulnerabilities.
Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token
A newly disclosed vulnerability in Cleo Harmony, a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk…
IT Security News Hourly Summary 2026-09-02 17h : 10 posts
10 posts published in the last hour 14:31Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing 14:31Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code 14:31Legacy Lenovo login opens 5,000 Dropbox…
Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing
Observations have shown that threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails, with attacks moving beyond…
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a…
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Cloud storage biz severs old integration and urges victims to reset credentials
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by…
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud
Beyond Agent-Washing: The Engineering Principles Behind Production-Ready AI Agents
An AI agent is not defined by how intelligently it talks. It’s defined by what it’s trusted to do. Give a language model a chat window, and you have an…
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a…
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to…
IT Security News Hourly Summary 2026-09-02 16h : 19 posts
19 posts published in the last hour 13:32Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) 13:32Anthropic: Infostealer Malware Hacks Claude Sessions to Drain Consumption Usage 13:32Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection 13:32Scammers are…
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans…
Anthropic: Infostealer Malware Hacks Claude Sessions to Drain Consumption Usage
Anthropic has warned Claude users that infostealer malware on their systems has stolen active Claude login sessions, letting threat actors to log into…
Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection
Security researcher has disclosed a technique used by the Singularity Linux rootkit to evade Elastic Defend by suppressing module-load telemetry to avoid…
Scammers are getting smarter about where they target you
New Malwarebytes research reveals how different scams are tailored to different platforms.
$536 and 8 Hours: AI Learns to Attack a Different PLC
Experts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout…
FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately
FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users…
Norway considers ban on camera-enabled wearable ‘pervert glasses’
The Nordic country says wearable camera headsets need to be regulated given their privacy risks.
AI Observability Must Evolve for the Agentic Era
In this article Traditional observability tells you whether software worked. For AI agents, the harder question is whether the system made the right…