Springfield Public Schools shut down operations mid-week following a cyberattack that forced all schools to close and left thousands of families…
Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide
A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which compromised more than 1,000…
Trezor, BitBox users targeted in phishing campaign
Trezor and BitBox, two major cryptocurrency hardware wallet manufacturers, have issued urgent warnings after attackers compromised their shared email…
New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax,…
Coding Start-Up Cognition AI Raises $2bn At $48bn Value
AI programming start-up’s latest funding round nearly doubles its value after a $1bn round three months ago
Ukrainian lawyer’s second career as a Conti coder earns him 4 years behind bars
Swapping legal work for malware development ended in extradition and a guilty plea
Cyber Briefing: 2026.09.09
Authenticated sessions exploited, application security flaws, weak account-recovery mechanisms, and exposed credentials to gain unauthorized access, steal…
Ransomware Affiliate Pretends to be Recovery Service for Extortion
An alleged ransomware affiliate is pretending to be a ransomware recovery service named “Ransom Busters,” reaching out to victims before the attacks…
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
Gigabud Uses Android App Cloning to Evade Fraud Detection
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
Google fixes the seventh actively exploited Chrome zero-day of 2026
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google…
NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses
The UK’s National Cyber Security Centre (NCSC) has warned organisations about the security risks posed by “shadow AI”, as employees continue to turn to…
Meta Rolls Out Assistant With Email, Payment Capabilities
New Muse AI assistant can access apps on user’s phone, autonomously sending emails, making payments, booking travel, amid security concerns
Forescout Expands Global Investment in Channel Partners
Forescout has expanded its investment in its global partner ecosystem to strengthen technical expertise and help partners support customers managing…
France’s Mistral AI Raises Record €3bn, Amid Strategy Shift
Latest funding round values French start-up at €21bn, as it devotes capital to building data centres, offers AI integration services
IT Security News Hourly Summary 2026-09-11 15h : 19 posts
19 posts published in the last hour 12:32Ireland Probes X Over Age Assurance, Parental Controls 12:32ClickFix Moves into the Browser to Steal Cryptocurrency 12:32VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data 12:32Critical FreeIPA Bug Can Let…
Ireland Probes X Over Age Assurance, Parental Controls
Ireland’s media regulator cites concerns over ineffective measures to protect children from adult material permitted on platform
ClickFix Moves into the Browser to Steal Cryptocurrency
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities…
Critical FreeIPA Bug Can Let Attackers Take Over Admin Rights
FreeIPA users and Red Hat Identity Management administrators should treat CVE-2026-76578 as a critical authentication-bypass flaw that can lead to full…
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to…
BigBear 2.0 phishing campaign hijacks M365 sessions
A large-scale phishing operation has compromised thousands of Microsoft 365 accounts by stealing authenticated session cookies that remain valid even…
ASML Breaks Ground On New Plant Amid Booming Demand
Netherlands’ ASML begins construction of 35-hectare plant 7km from headquarters, as Samsung, TSMC adopt new tools