A research team from Graz University of Technology in Austria has shown that a routine feature built into virtually every major operating system can be…
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI.
Fake Email Thread Tricks AI Summarizer Without Hidden Text
Forcepoint X-Labs has published new research showing that indirect prompt injection against AI email summarizers can work without…
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach
Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets
Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open
A criminal crew linked to Blackhatsect0r and DXQRTXX built an automated system designed to find weaknesses across the internet. Its exposed server…
Singapore Expands AI Cybersecurity After UNC3886 Attacks
Singapore is changing its cybersecurity strategy after a state-sponsored cyber espionage group targeted the country’s four major telecommunications…
OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code on Developer Machines
A critical attack path in OpenCode, an open-source AI coding agent, could let a malicious website execute commands on a developer’s computer. Tracked as…
Supabase Misconfigurations Leave Customer Data Publicly Exposed
A cybersecurity firm UpGuard has found that thousands of databases hosted on Supabase can expose private information to the public internet. According to…
NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
The UK National Cyber Security Center (NCSC) has urged organizations to take immediate action against eight vulnerabilities affecting customer-managed…
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed.
New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence
A new guide featuring the experiences of 16 women working in cyber threat intelligence (CTI) is challenging the idea that professionals need a…
Ex-soldier’s telecom hacking spree earns him 70 months
Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
Cyber Briefing: 2026.09.28
Storm-3168 used compromised Azure credentials to delete more than 100 cloud resources, while Psychedelic Stealer targeted Ukrainian businesses and a DC…
TrustSink Attack Uses Rogue MFA Provider to Steal Microsoft Entra Passwords During Legitimate Logins
TrustSink is a newly disclosed identity attack that turns a trusted MFA step into a password-stealing trap. Rather than sending victims to a clearly fake…
IT Security News Hourly Summary 2026-09-28 17h : 17 posts
17 posts published in the last hour 14:32NVIDIA Launches Open Agent Safety Platform With 100 Industry Partners to Secure Autonomous AI Agents 14:32ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells 14:32James Moore, CultureAI Q&A: AI…
NVIDIA Launches Open Agent Safety Platform With 100 Industry Partners to Secure Autonomous AI Agents
NVIDIA has launched the Open Agent Safety Platform, an open framework designed to secure autonomous AI agents as they gain access to models, tools, code…
ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The…
James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind
AI adoption is moving faster than most organisations can govern it. It is a familiar line by now, repeated often enough to sound routine, and that is part…
Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers
Fake storefronts appeared days after the launch of Jev, an artificial intelligence model that returns decisions rather than written answers. The sites…
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That…
Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
Cryptocurrency exchange Bitget has begun restoring withdrawals after attackers exploited its backend wallet infrastructure on September 24, stealing…
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website. The…
CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Microsoft SharePoint code injection vulnerability, tracked as CVE-2026-65660,…
