IT Security News: today roundup Apple patched an actively exploited CoreGraphics flaw allowing remote code execution. Manus launched autonomous AI agent tools to compete with Meta. Nvidia introduced hardware and runtime security controls for AI agents. Cyberattacks on two federal…
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped.…
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers’ increasingly advanced capabilities.
IT Security News Hourly Summary 2026-10-02 23h : 4 posts
4 posts published in the last hour 20:31Detecting Host Header Injection & Open Redirects 20:01Frontline Education breach exposes school district employee data 20:01ICE Has Been Dumping Protester Photos Into a Palantir Database 20:00IT Security News Hourly Summary 2026-10-02 22h :…
Detecting Host Header Injection & Open Redirects
By HOC Team | Updated: September 2026 |Read time: ~16 min While Cross-Site Scripting (XSS) and SQL Injection…
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized…
ICE Has Been Dumping Protester Photos Into a Palantir Database
DHS agents not only tracked and intimidated people observing ICE activity in Maine, but stored information about them in a Palantir-built database, newly…
IT Security News Hourly Summary 2026-10-02 22h : 11 posts
11 posts published in the last hour 19:31Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware 19:31Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path 19:31‘North Korean’ Attackers Steal $387.5m From Bitget…
Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware
Gemini 4 starts with cybersecurity MI5 flags Chinese research funding Custom GPTs steer users into ClickFix attacks Get the show notes here:…
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in…
‘North Korean’ Attackers Steal $387.5m From Bitget
Exchange Bitget resumes transactions after suspected North Korean attackers carry out biggest single crypto heist so far this year
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond
Halfway is No Way: Why DSPM Fails if it Can Detect, But Not Respond andrew.gertz@t… Wed, 09/30/2026 – 20:13 Data Security Todd Moore | Global VP of Data…
Sydney Data Centre Plan Withdrawn After Protests
Developer Goodman Group pulls plan for 90 MW data centre that it intended to build in Sydney suburb near homes, schools
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting…
What enterprises need to know about the Cyber Resilience Act and software supply chain risk
In part 1 of this series, we examined why enterprises need more than an inventory of the open source components in their software. Understanding where…
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security…
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing…
What enterprises need to know about the software they depend on
Knowing an application contains open source components is not the same as understanding the software and communities behind them.For many organizations,…
IT Security News Hourly Summary 2026-10-02 21h : 10 posts
10 posts published in the last hour 18:31Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents 18:31Fire That Killed Four Linked To Lithium-Ion Battery 18:31MetaMask Security Incident Prompts Exit of Affected Ethereum Validators…
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it will add new controls around macOS’s Full Disk Access permission, warning that increasingly capable AI agents make broad access to users’…
Fire That Killed Four Linked To Lithium-Ion Battery
Electrical event caused lithium-ion battery to go into thermal runaway, sparking intense fire that killed mother, three children
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively…
Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds
Most organizations around the world are spending more on cybersecurity than at any point in their history. Very few are spending it on the threats that…
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad…
OpenAI alerts 100+ orgs that its ‘misaligned models’ attempted to break in – or worse
Mostly ‘routine research tasks,’ and ‘some involved government websites, which our models often use,’ AI giant tells The Reg
