An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
NHIs Now the Number One Corporate Entry Point for Hackers
SpyCloud claims non-human identities are the most likely route into the enterprise
Jellyfin 12.0 releases security fixes
Jellyfin has released version 12.0 of its media server platform with several critical security patches addressing vulnerabilities that could expose files…
IT Security News Hourly Summary 2026-09-11 14h : 16 posts
16 posts published in the last hour 11:32cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw 11:32Check Point Patches Critical VPN Vulnerabilities 11:32Sequoia doubles down on Cymphony as AI agents create new enterprise security risks 11:32ShinyHunters claims Florida…
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands…
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Cymphony gives security teams a single view of employees, AI agents, and other nonhuman identities, including the systems and sensitive data they can…
ShinyHunters claims Florida DMV breach
The notorious cybercrime group ShinyHunters has claimed responsibility for breaching Florida’s Department of Highway Safety and Motor Vehicles, allegedly…
Cliff Stoll’s DEF CON Talk
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.
WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
DeepSeek Harness Sandbox Bypass Flaw
Security researchers have identified a critical sandbox escape vulnerability in DeepSeek Harness, the open-source framework developed by DeepSeek for…
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.
Open Standard for Revocable API Keys Proposed
Security researchers have proposed an open standard designed to make API keys self-destruct within 60 seconds of being detected as leaked.
IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web
IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500…
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate…
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Austin, Texas / USA, 9th September 2026, CyberNewswire SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the…
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams,…
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.
Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly…
IT Security News Hourly Summary 2026-09-11 13h : 15 posts
15 posts published in the last hour 10:32Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code 10:32U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok 10:31The AI Energy Paradox: Can Data Centres…
Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and…
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting “systematic extraction” of…
The AI Energy Paradox: Can Data Centres Scale Without Derailing Sustainability?
Can AI data centres scale sustainably? Explore how smarter cooling, cleaner power and tighter governance can curb their growing energy and water demands.
AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents…
