A Formula 1 pit crew doesn’t wait until every sensor, camera, and engineer agrees that a tire needs changing. They have a few seconds to make a decision…
Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting
Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The…
Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users
Kratos is a phishing service built to steal Microsoft 365 credentials at scale. It evolved from the Sneaky2FA kit and gave affiliates ready-made login…
BlackCloak extends deepfake protection to the executive’s trusted circle
Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building…
Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions
Criminals are using convincing cryptocurrency wallet screens and browser extensions to steal recovery phrases, login data, and active browser sessions.…
Cyberhaven launches Flow to secure data across human and AI workflows
Cyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage,…
Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations
A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against organizations in the United States, putting Java…
IT Security News Hourly Summary 2026-07-28 15h : 16 posts
16 posts were published in the last hour 13:3 : Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays 13:3 : We rebuilt Malwarebytes Mobile Security for the scams of today 13:3 : Dismantled Kratos Phishing Kit Becomes…
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been…
We rebuilt Malwarebytes Mobile Security for the scams of today
Your phone needs more than a lock screen to stay safe. We’ve rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security…
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first
Washington rallies allies to shape next-generation networks after spending 18 months rattling them
EShare App Vulnerability CVE-2026-55977
The Cyber Security Agency of Singapore has assigned CVE-2026-55977 to a vulnerability in EShare’s wireless screen mirroring and collaboration application.
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence
Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale,…
Shared Claude chats were searchable on Google
Reddit users found that by using a specific search query, they could find shared Claude conversations in search results.
Act Security Launches Patch Management Solution
Act Security has officially launched from stealth mode with a patch management solution targeting a critical challenge facing cloud security teams: the…
SpecterOps brings AWS attack path management and AI to hybrid identity security
SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the…
Tribeca Film Festival Data Breach Exposes 666K Records
Security researcher Jeremiah Fowler discovered four publicly accessible databases containing nearly 666,000 records linked to the Tribeca Film Festival,…
Update your iPhone, iPad and Mac to fix Apple security holes
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.
Senator Wyden urges federal VPN purge
Senator Ron Wyden has urged federal cybersecurity agencies to remove all insecure, internet-facing VPN systems from government networks within two years,…
Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response
Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and…
Fake IT Calls Deploy GoGRPC Backdoor via Teams
Cybersecurity researchers have identified a social engineering campaign where threat actors pose as internal IT helpdesk staff to gain unauthorized access…
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The…