Authorities arrest former senior semiconductor researcher on charges that he simultaneously ran competing Chinese chip producer
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could…
WordPress Adds Automated Security Review for Plugins
WordPress has deployed an automated security review system that evaluates every plugin release before distribution through the WordPress.org update API.
OpenAI Agents Take Over German Wiki Site
OpenAI acknowledges its agents repurposed German wiki as message board in May incident that was not previously disclosed
VMware ends public VDDK downloads
VMware has quietly discontinued public downloads of its Virtual Disk Development Kit (VDDK), a software development kit that provides APIs for accessing…
US Regulator Probes Tesla Over Cybercab Launch
US vehicle safety regulator opens audit process after Tesla puts Cybercab onto Austin streets with no human controls
IT Security News Hourly Summary 2026-09-10 16h : 15 posts
15 posts published in the last hour 13:03NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity 13:03Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks 13:03How to Use BloodHound Active Directory Setup Attack Path Analysis 13:02F5…
NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity
NeuroCyber, the organisation dedicated to improving opportunities and career outcomes for neurodivergent individuals across the cybersecurity profession,…
Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS…
How to Use BloodHound Active Directory Setup Attack Path Analysis
By HOC Team | Last updated: September 10, 2026 | Read time: ~24 min How to Use BloodHound…
F5 BIG-IP APM Malware Installs a PHP Web Shell Into Memory, Escaping Disk Scans
Sophos X-Ops has found an advanced Linux rootkit that can conceal a PHP web shell completely in server memory, which makes it harder for traditional…
Xiaomi Launches Foldable To Compete With Upcoming iPhone
Beijing-based Xiaomi launches 18 Fold wide-format foldable smartphone, as companies flock to popular category
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Nearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating…
PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA
PEEP turns browsers into backdoors Liquid loses $320M, hackers play hero BigBear claws past MFA Get the full show notes here:…
Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes
Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks.…
Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited…
How to Disable Root Login via SSH: Step-by-Step Guide (2026)
By HOC Team | Last updated: September 08, 2026 | Read time: ~12 min How to Disable Root…
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography
The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram…
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update
A significant security update was released by Microsoft on Patch Tuesday in September, addressing 974 vulnerabilities across the company’s software…
LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials
LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run…
IT Security News Hourly Summary 2026-09-10 15h : 11 posts
11 posts published in the last hour 12:31FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors 12:31Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone 12:31Australia To Let Users Switch Off Social Media Algorithms 12:31Critical…
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
Skullcandy Dime 3 wireless earbuds have a serious vulnerability related to unauthenticated Bluetooth pairing. This flaw allows nearby attackers to…
