A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically…
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
Pony AI Sees Surge In Robotaxi Sales
Self-driving taxi sales to outside customers on track to more than triple this year, as Pony plans thousands of overseas deployments
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files…
Critical Cursor 0-day Vulnerability Enables Arbitrary Code Execution Attacks
A binary planting vulnerability in the Cursor IDE that lets a malicious git.exe file, placed at the root of a repository, run automatically the moment a…
ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts
The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations
BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges
BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with…
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and…
CISA Warns of VMware vCenter Path Traversal Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Broadcom VMware vCenter vulnerability, tracked as CVE-2026-59310, to its…
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring…
Google Fixes Two Critical Chrome Flaws in WebGL and Dawn — Update Your Browser
Google has released a new Chrome Stable channel update that fixes two critical security vulnerabilities affecting graphics-related components. Users…
Oracle Releases 943 Security Patches to Fix Critical Vulnerabilities Across Enterprise Products
Oracle has released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing newly disclosed vulnerabilities…
Claude Can Now Send Emails in Gmail and Manage Files in Google Drive
Anthropic has moved Claude out of the draft-only inbox and into live Google accounts. In an August 18, 2026 post, the company said users can ask Claude to…
IT Security News Hourly Summary 2026-08-19 12h : 16 posts
16 posts published in the last hour 09:31Flock Has a Powerful New AI Tool for Police. We Got Its Code 09:31Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains 09:31Brinqa acquires PlexTrac to bring validated remediation to exposure management…
Flock Has a Powerful New AI Tool for Police. We Got Its Code
Flock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it…
Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains
Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other…
Brinqa acquires PlexTrac to bring validated remediation to exposure management
Brinqa has announced its acquisition of PlexTra, adding the ability to verify that remediation efforts have actually worked. The combined capabilities…
943 Patches Rolled Out With Oracle’s August 2026 Security Update
The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs.
Apple Changes EU Fees For Third-Party App Stores
Apple says latest fee structure to come into effect on 1 October, as EU seeks to force app competition
50,000 Stripe Secrets Leaked in Public Code
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have…
Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found…
France Probes Major Tax Authority Data Breach
Paris public prosecutor’s office begins investigation after hack steals tax data on hundreds of thousands of individuals, businesses
Chrome, Firefox Updates Patch Dozens of Vulnerabilities
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control,…