IT Security News: today roundup Organizations must adapt training strategies to build cybersecurity workforces capable of countering evolving threats. Europol assisted in dismantling a European criminal network that trafficked horses using forged documents and modified microchips. Security Affairs released a…
OpenAI’s malicious bot swarm attacked RubyGems
Ruby are you ok? Ruby are you ok? Are you ok Ruby?
ClickFix attacks are tricking Mac and Windows users into hacking themselves
If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising ‘ClickFix’ security threat.
Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Researchers have uncovered an exposed attacker-controlled staging server containing evidence of a wide-ranging intrusion targeting 3BB, the consumer brand…
Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform
Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus…
UK Government Begins Moving 23 Million Users Away From Passwords
The UK government has begun rolling out passkeys across GOV.UK One Login, offering more than 23 million users a passwordless way to access public…
Data Governance for the Agentic Era
The modern enterprise generates and consumes unprecedented volumes of data across operational systems, customer interactions, partner ecosystems, cloud…
Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials
Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials,…
AWS Security Reference Architecture: A deep dive into PCI DSS compliance
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data…
Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console
Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could let a nearby attacker execute unauthorized code and access…
IT Security News Hourly Summary 2026-09-14 20h : 8 posts
8 posts published in the last hour 17:31Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries 17:31New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing 17:02Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to…
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to…
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently…
Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability…
FedRAMP Moderate Authorization for Palo Alto Networks Quantum-Safe Security
Palo Alto Networks has achieved FedRAMP Moderate authorization for Quantum-Safe Security (QSS), a turnkey Automated Cryptography Discovery and Inventory…
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update…
New York Seizes a Dozen Celebrity Deepfake Websites
In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively…
One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
A single click on a malicious link could have given attackers a direct path into Windows systems running Sogou Input Method. The flaw turned a commonly…
IT Security News Hourly Summary 2026-09-14 19h : 15 posts
15 posts published in the last hour 16:32WhatsApp’s New Restricted Chat Feature Locks Conversation on Your Primary Phone 16:32Your Company’s Phishing Tests Are Measuring the Wrong Thing 16:32Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users 16:32Using…
WhatsApp’s New Restricted Chat Feature Locks Conversation on Your Primary Phone
WhatsApp is developing a new privacy control called Restricted Chat that will keep selected conversations accessible only from a user’s primary mobile…
Your Company’s Phishing Tests Are Measuring the Wrong Thing
When a phishing simulation returns a low click rate, security teams tend to relax. Leadership checks a compliance box. The program gets renewed. But a…
Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on,…
Using AI for Weapons Development
Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag…
Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning
Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall…
FedRAMP Moderate Authorization for Palo Alto Networks’ Quantum-Safe Security
Palo Alto Networks has achieved FedRAMP Moderate authorization for Quantum-Safe Security (QSS), a turnkey Automated Cryptography Discovery and Inventory…