A large-scale phishing operation has compromised thousands of Microsoft 365 accounts by stealing authenticated session cookies that remain valid even…
IT Security News Hourly Summary 2026-09-09 16h : 23 posts
23 posts published in the last hour 13:32Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy 13:32NHIs Now the Number One Corporate Entry Point for Hackers 13:32Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms 13:32This…
Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.
NHIs Now the Number One Corporate Entry Point for Hackers
SpyCloud claims non-human identities are the most likely route into the enterprise
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
The three Indian companies are accused of using hackers to steal information used to sway litigation.
This $50 lifetime VPN adds AI-powered protection to your connection
Get AI-powered threat protection, encrypted connections, and more with this VPN lifetime subscription today.
Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain…
Orchid Security targets AI agent risk with drift detection and kill switches
Orchid Security has announced identity drift detection and application-level kill switches for AI agents. They can complete authorized objectives beyond…
Singapore man pleads guilty to $245M crypto theft
A 22-year-old Singapore national has admitted to leading a criminal operation that stole more than $245 million in cryptocurrency from victims’ digital…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
Jellyfin 12.0 releases security fixes
Jellyfin has released version 12.0 of its media server platform with several critical security patches addressing vulnerabilities that could expose files…
AI adoption that pays off is built around keeping humans in the driver’s seat
I’ve spent enough time around AI adoption now to notice a pattern. Ask a business how AI is going for them and the honest answer is, lately, “we’ve got…
Open Standard for Revocable API Keys Proposed
Security researchers have proposed an open standard designed to make API keys self-destruct within 60 seconds of being detected as leaked.
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Cymphony was valued at more than $100 million in a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund.
DeepSeek Harness Sandbox Bypass Flaw
Security researchers have identified a critical sandbox escape vulnerability in DeepSeek Harness, the open-source framework developed by DeepSeek for…
FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs
A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy…
ShinyHunters claims Florida DMV breach
The notorious cybercrime group ShinyHunters has claimed responsibility for breaching Florida’s Department of Highway Safety and Motor Vehicles, allegedly…
WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
AI-Assisted WeChat Worm Put 1 Billion Accounts at Potential Risk
Researchers used AI to build WeWorm, a zero-click WeChat exploit that could hijack accounts through unanswered calls before Tencent mitigated the flaw.
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent of organizations believe they have visibility into their AI and machine…
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams,…
Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories
Cybercriminals are widening the reach of information-stealing malware by targeting the local data created by AI coding agents. The shift puts access…
Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs
Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using…
