By HOC Team | Last updated: September 05, 2026 | Read time: ~24 min Cybersecurity Risk Assessment: Step-by-Step…
Tag: EN
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft.
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
redactproxy, a tool that lets pentesters use AI without leaking client data
AI coding agents are now part of a lot of security work. They are good at the parts a tester has no time for: going through every request, every parameter…
OpenAI Agents Hacked Another Website
Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad…
Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security
Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software…
Microsoft Teams Desktop Client Fails to Load on Windows System – Microsoft Investigating
Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams…
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named…
AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials
A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a…
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant…
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and…
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data…
CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each
Used-car platform CARS24 has alleged that confidential information belonging to approximately 3,100 customers was stolen and supplied to a rival business…
Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours
A threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root…
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory…
Defenders call out OpenAI defense pledge, Astra release timing
OpenAI has pledged $1 billion to support frontline defenders just days after calling for a collective surge in cyberdefense. Yet that pledge arrived on…
Surviving and thriving in the AI Vulnpocalypse
Katie Moussouris on AI’s Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David…
numbat – AI agent observability, (Fri, Sep 4th)
​​​​​​​