The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email
A new credential phishing campaign is using a fake “New Audio MSG” email to draw recipients toward a convincing Google-themed sign-in page. The message…
Prompt Injections for Defense
This seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other…
Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and…
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
French Press Group Challenges Google Over AI Summaries
Press trade body calls on competition regulator to take action after Google introduces AI Overviews in France, amid EU probe
ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT
ClickFix campaigns are once again turning an ordinary user action into the opening move of a serious intrusion. A newly documented chain uses a fake fix…
WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud
A newly identified Android malware family, tracked as WindRelay, is being used alongside the SpyNote remote-access trojan to convert victims’ phones into…
Top 10 Best Network Access Control (NAC) Solutions in 2026
Modern network access control solutions decide which devices get onto your network, what they can reach once connected, and what happens when an unmanaged…
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks…
Top 10 Best Business VPN Solutions in 2026
The best business VPN solutions in 2026 are increasingly the ones that aren’t traditional VPNs at all. Twingate and Tailscale lead for modern…
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.…
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Sandworm has turned the routine job interview into a route for compromising IT workers. The campaign uses convincing recruiter conversations, live video…
IT Security News Hourly Summary 2026-08-12 12h : 16 posts
16 posts were published in the last hour 9:31 : ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch 9:31 : ConnectSecure helps MSPs automate Microsoft 365 security remediation 9:31 : Letting Agents Hit By AI-Generated Complaints 9:31 : LiteLLM Supply…
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code…
ConnectSecure helps MSPs automate Microsoft 365 security remediation
ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The…
Letting Agents Hit By AI-Generated Complaints
Most tenants’ complaints now lengthy, legally complex, at times citing legislation inaccurately, say letting agents
LiteLLM Supply Chain Breach: How a 40-Minute Hack Exposed 2,500+ Companies
The 2026 LiteLLM Supply Chain Breach Explained: How a 40-Minute Hack Exposed 2,500+ Companies. A research report by…
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on…
CBTS brings continuous penetration testing to enterprise security
CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations…
AI Token Prices Fall To Annual Low
Average token prices for AI inference fall to low for the year to date, amid release of low-cost Chinese models, increased US efficiency focus
Microsoft Fixes 400 Flaws on August Patch Tuesday
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys,…