CrowdStrike is investigating FalconFlank, a privilege-escalation PoC that can reach SYSTEM access. Here’s what defenders should disable and monitor.
IT Security News Hourly Summary 2026-09-07 17h : 6 posts
6 posts published in the last hour 14:31LG TV flaws could let attackers listen in, even in standby mode 14:31NCSC Warns Shadow AI Creates New Security Risks 14:31Attackers use rogue ScreenConnect clients to spread malware 14:31Chaotic Eclipse Released A PoC…
LG TV flaws could let attackers listen in, even in standby mode
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
NCSC Warns Shadow AI Creates New Security Risks
NCSC warns unapproved AI tools can expose corporate data and create new security risks
Attackers use rogue ScreenConnect clients to spread malware
A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A…
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known…
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska,…
IT Security News Hourly Summary 2026-09-07 16h : 8 posts
8 posts published in the last hour 13:31PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells 13:31Hackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guys 13:31NoName057(16) Renews #OpJapan 13:02Telerik UI Padding-Oracle Bug Chained to…
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
A sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with…
Hackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guys
Self-described white hats promise to return ‘most’ of the 4,000 BTC once the vulnerability is fixed
NoName057(16) Renews #OpJapan
On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform,…
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against…
Your Cloud Security Checklist Doesn’t Work the Way You Think It Does
If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder…
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script…
IT Security News Hourly Summary 2026-09-07 15h : 19 posts
19 posts published in the last hour 12:31North Korean Hackers Deploy New Linux Espionage Toolkit 12:31ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions 12:31OpenAI Agents Hijack Another Victim Website 12:31Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity…
North Korean Hackers Deploy New Linux Espionage Toolkit
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance.
ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue…
OpenAI Agents Hijack Another Victim Website
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face…
Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data
Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current…
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure
OpenAI has announced a $1 billion global commitment to expanding access to its Daybreak AI cybersecurity platform for frontline defenders who protect…
The UK’s Cyber Community Comes North as CyberFest returns for 2026
The North East’s biggest cyber security festival returns this October. Now in its ninth year, CyberFest has grown into a major national platform for…
DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms
South Korean automotive and media organizations have been hit by a quiet Linux intrusion toolkit built for long-term access. The malware hides inside…
