The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
A BYD Shark 6 Hack Shows the Risks of Connected Cars
A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A…
Scammers impersonate cops, use arrest threats to extort victims
Scammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint…
Rustaceans warned of job interviews with a malicious payload
Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls
US and China Discuss Alerting Each Other to AI National Security Threats
Officials discussed setting up a mechanism for the two countries to notify each other of AI incidents which could threaten national security.
ShinyHunters hacks rival extortion gang and takes over its dark web site
Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.
IT Security News Hourly Summary 2026-09-21 13h : 17 posts
17 posts published in the last hour 10:32Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO 10:31TerminalFix: PNG Steganography, (Mon, Sep 21st) 10:31Hackers Hide Malware Servers on Blockchain to Steal Bank Logins and 2FA Codes 10:31From Exposure to Lockdown: How…
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active…
TerminalFix: PNG Steganography, (Mon, Sep 21st)
Microsoft Security Research published an interesting blog post “TerminalFix campaign deploys a reverse tunnel through multistage intrusion” about a…
Hackers Hide Malware Servers on Blockchain to Steal Bank Logins and 2FA Codes
A new malware campaign is using blockchain technology to keep its control servers out of reach. The operation tricks visitors to compromised business…
From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.
Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware
Hackers are exploiting a critical cPanel and WHM flaw to place Mirai malware on exposed servers, extending a botnet threat normally associated with…
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
MSNightmare has Released a Windows Defender Update DoS Vulnerability Called BigDiskBuster
Security researcher MSNightmare, also known as Nightmare-Eclipse, has released BigDiskBuster, a proof-of-concept denial-of-service technique designed to…
Top 10 Best Identity & Access Management (IAM) Solutions in 2026
Quick Answer: Microsoft Entra ID wins on bundled value inside M365 estates; Okta wins on neutrality and app-catalog breadth; Ping Identity (which now…
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
A breach at image-sharing service Gyazo on September 11 affected over 23 million customers
Top 10 Best Privileged Access Management (PAM) Solutions in 2026
Quick Answer: CyberArk remains the enterprise PAM benchmark; BeyondTrust and Delinea complete the leader trio; ManageEngine PAM360 wins value; HashiCorp…
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection
Hackers are using a layered Windows malware chain to run an XMRig cryptocurrency miner while keeping its key parts out of sight. The operation hides code…
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning…
OpenAI Codex Sandbox Flaws Let Malicious Repositories Execute Commands on Host Systems
OpenAI Codex recently faced two significant security vulnerabilities that allowed malicious repositories to potentially execute commands on a developer’s…
Siemba brings continuous IDOR testing to production APIs
Siemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST,…
Hackers Can Manipulate Web Cache Keys to Access Restricted Data and Poison Websites
A web cache poisoning technique called cache key injection could let attackers access restricted data, disrupt websites, or poison cached pages with…
IT Security News Hourly Summary 2026-09-21 12h : 16 posts
16 posts published in the last hour 09:32Top 10 Best Multi-Factor Authentication (MFA) Solutions in 2026 [Ranked & Scored] 09:32Hackers exploit Gyazo server flaw to steal 23.6 million user records 09:32SIRIUS SPoC network meets as EU enters new era for…
