Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun…
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490,…
Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw
A software flaw in Coldcard hardware wallets has raised fresh concerns about the security of offline cryptocurrency storage after a software flaw in…
Cybersecurity Job Ads Requiring AI Skills Double
An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again:…
GitLab 19.3 helps enterprises scale agentic development securely
GitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run…
IT Security News Hourly Summary 2026-08-21 10h : 10 posts
10 posts published in the last hour 07:31Google Chrome 151 Chromoting Flaw Allows Attackers to Execute Malicious Code Remotely 07:31UAE Police ‘Detained’ Two Binance Employees 07:31CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach 07:31China-Linked Spy Campaign Uses Five New…
Google Chrome 151 Chromoting Flaw Allows Attackers to Execute Malicious Code Remotely
Google has released Chrome 151 Stable, fixing seven security vulnerabilities, including a critical use-after-free flaw in Chromoting that could…
UAE Police ‘Detained’ Two Binance Employees
Police in United Arab Emirates reportedly detained two employees of crypto trading giant, questioned a third amid fraud inquiries
CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach
CISA warns of hackers exploiting critical MLflow vulnerability ICS operators warned of AI-driven attacks on Siemens PLCs Electronic health record company…
China-Linked Spy Campaign Uses Five New Malware Families Against Central Asian Governments
Central Asian government bodies have been targeted in a cyberespionage operation using a compact but varied set of remote access tools. The activity,…
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
Hackers Exploit TrueConf Servers to Push Malware Through Legitimate Video Conference Downloads
Kaspersky researchers investigating attacks on Russian organizations discovered that legitimate TrueConf video conferencing client installers were…
Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks
Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research…
Apple’s Private Find My People Reversed to Decrypt Live Shared Locations on Linux
A security researcher has successfully reverse-engineered Apple’s private Find My People protocol, demonstrating that a Linux machine can register with…
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer…
IT Security News Hourly Summary 2026-08-21 09h : 9 posts
9 posts published in the last hour 06:31New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh 06:31Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials 06:31Compromised Rust Crate With…
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control…
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Threat actors are exploiting interest in generative AI software to distribute the Vidar information stealer through a fake Google Gemini installer hosted…
Compromised Rust Crate With 18,000+ Downloads Steals Source Code During Builds
A malicious update to the Rust crate called onering has been discovered, which exfiltrates source code changes from developers’ machines during the build…
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
Secure Workload Software has five nasty flaws and even SaaS users have updates to install
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate…
Microsoft Entra ID RCE Flaw Lets Unauthorized Attackers Execute Code Remotely
Microsoft has disclosed a critical remote code execution vulnerability in Microsoft Entra ID, identified as CVE-2026-69836. This flaw could enable…
CISA Warns AI-Powered Zero Day Targets Windows And VMware
Security researchers confirmed that cyber threat actors are actively using autonomous AI frameworks (powered by DeepSeek) to scan,…