Authorities have identified a 16-year-old as the suspected main operator of the KillSec ransomware group after an international law-enforcement operation…
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system…
Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor
A fake Zoom installer is tricking Mac users into handing over their login passwords and launching CloudSyncD, a newly identified backdoor. The malware…
IT Security News Hourly Summary 2026-10-01 19h : 12 posts
12 posts published in the last hour 16:31Humans are reviewing Copilot users’ bizarre and abusive image-editing requests 16:31Kiteworks Urges Customers to Restart Systems After Shutdown Notice 16:31The 6 Best VPN for Streaming Compared: Key Features + Pricing 16:31Securing the keys…
Humans are reviewing Copilot users’ bizarre and abusive image-editing requests
Copilot users asked for upskirt images and sexualized edits of people in uploaded photos. Human contractors were asked to judge the results.
Kiteworks Urges Customers to Restart Systems After Shutdown Notice
Kiteworks has lifted a temporary shutdown recommendation which was issued on the back of federal intelligence
The 6 Best VPN for Streaming Compared: Key Features + Pricing
Key takeaways: The right VPN for streaming depends on what you need most, such as access to regional content or support for multiple devices. VPNs…
Securing the keys to the kingdom: Announcing Executive Threat Detection
This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most…
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.
September 2026 Cyber Attacks Timeline
A live, continuously updated timeline of the cyber attacks reported in September 2026 — tracking threat actors, attack techniques, targeted sectors and…
Researchers Discover Exploit Kit Targeting iPhones in Mobile Malware
Researchers at the Ukrainian Cyber Security Institute have warned that there are mobile malware campaigns targeting both Android and iOS devices, with…
CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
AI Safety Concerns Put OpenAI and Anthropic Under FTC Scrutiny
Artificial intelligence companies are facing another layer of scrutiny in the United States, with the Federal Trade Commission examining whether…
Are Passphrases Still Secure in the Age of AI?
The short answer up front: Yes, but only if the passphrase is genuinely random . Passphrases emerged as a direct response to a well-known problem with…
Half a Million GitHub Credentials Are Still Active, Most Have Been Sitting in the Open for Years
Researchers at Truffle Security tested 543,699 API keys, database passwords, and access tokens found in public GitHub repositories last July. Every single…
IT Security News Hourly Summary 2026-10-01 18h : 29 posts
29 posts published in the last hour 15:32Building a Security-First Culture for an Accelerating Threat Landscape 15:32GPT-6 Astra goes off script, ShinyHunters suspect arrested, Nvidia corrals rogue AI agents 15:32Why OT Resilience Is Now a Boardroom Imperative 15:32AI Security Testing:…
Building a Security-First Culture for an Accelerating Threat Landscape
As AI accelerates the attack lifecycle, organizations must treat everyday security behaviors as essential operational controls.
GPT-6 Astra goes off script, ShinyHunters suspect arrested, Nvidia corrals rogue AI agents
GPT-6 Astra goes off script in attack simulations Dutch police arrest “reformed” hacker in ShinyHunters probe Nvidia builds a browser for AI agents Get…
Why OT Resilience Is Now a Boardroom Imperative
For decades, industrial cybersecurity rested on a comfortable assumption: operational technology (OT) was protected by physical isolation. The “air gap”…
AI Security Testing: How to Red Team an LLM Application
By HOC Team | Updated: October 2026 | Read time: ~24 min Red teaming an LLM application is…
SOC staffers generally pleased with AI’s impact, but worries remain
AI is likely to eliminate some entry-level SOC roles, a survey found, but it is also creating opportunities to develop more strategic skills.
Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators
A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, with recent attacks striking…
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real…
OpenAI Cancels Model Release Over Security Concerns
OpenAI says it will not publicly release GPT-6.1 Astra after model performed poorly on security assessments during testing
