7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange…
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware,…
Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
OpenAI Unveils Ultrafast Mode in GPT‑5.6 Sol That Works 14× Faster Than Standard Mode
OpenAI has introduced Ultrafast, a new service tier for GPT-5.6 Sol that it says can run up to 14× faster than Standard processing. The feature launches…
Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors
President Trump has signed a national security presidential memorandum allowing federal law enforcement agencies to partner with private technology…
AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges
AI credentials are drawing criminal attention. A growing form of abuse, called AI token jacking, lets intruders take API keys and consume expensive model…
AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers
AmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser.…
GeoServer 0-Day Vulnerability Enables Remote Code Execution Attacks
A newly disclosed zero-day vulnerability in GeoServer is being targeted by attackers, raising concern for organizations that publish or manage geospatial…
IT Security News Hourly Summary 2026-08-14 12h : 8 posts
8 posts were published in the last hour 9:2 : Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access 9:2 : APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit 9:2 : Prompt Injections for Defense…
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.…
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections…
Prompt Injections for Defense
This seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other…
Scottish prosecutors cast eye over leaky supplier after staff data exposed
Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected
French Press Group Challenges Google Over AI Summaries
Press trade body calls on competition regulator to take action after Google introduces AI Overviews in France, amid EU probe
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code…
Letting Agents Hit By AI-Generated Complaints
Most tenants’ complaints now lengthy, legally complex, at times citing legislation inaccurately, say letting agents
IT Security News Hourly Summary 2026-08-14 11h : 26 posts
26 posts were published in the last hour 8:32 : US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks 8:32 : 24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services 8:32 : Malicious LiteLLM Releases…
US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks
Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump…
24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors…
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys,…
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.
AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B)…
Supreme Court Rejects Suspension Of Apple App Store Case
Proceedings will now go ahead in California district court to determine fees Apple can charge for transactions outside App Store
Meet Huntress at International Cyber Expo 2026
Huntress will be heading to International Cyber Expo 2026, where visitors can meet the team on Stand K94 and discover how the company is helping…