BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize…
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.
IT Security News Hourly Summary 2026-09-01 12h : 11 posts
11 posts published in the last hour 09:31Hackers Use Malicious Website Themes to Steal Crypto Wallet Seeds From iPhones 09:31Berlin refuses to be blackmailed after network breach 09:319.5 Million Impacted by Aesto Health Data Breach 09:31U.S. CISA adds PaperCut NG/MF…
Hackers Use Malicious Website Themes to Steal Crypto Wallet Seeds From iPhones
Hackers are using booby-trapped website themes to turn visits from iPhone users into a route for spyware and cryptocurrency theft. The campaign hides…
Berlin refuses to be blackmailed after network breach
Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner…
9.5 Million Impacted by Aesto Health Data Breach
Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S.…
Popular npm Package With 150K Weekly Downloads Compromised in Mini Shai-Hulud Supply-Chain Attack
A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with…
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI
Hackers Compromise Cisco Routers to Spy on Networks and Reach Critical Infrastructure
Fire Ant has moved beyond attacking individual systems and is now compromising network infrastructure that organizations trust to move traffic and manage…
WatchGuard Patches Critical Vulnerabilities
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.
Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials
Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan…
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that’s been put to use by a Russia-aligned threat actor known as UAC-0099…
IT Security News Hourly Summary 2026-09-01 11h : 6 posts
6 posts published in the last hour 08:31SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications 08:31Healthcare Giant McKesson Investigates Data Breach Incident 08:31WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited 08:01Fake…
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections.…
Healthcare Giant McKesson Investigates Data Breach Incident
ShinyHunters claims to have stolen 284 million records from McKesson
WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited
The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across…
Fake Claude Opus 5 App Deploys RevStealer to Steal Passwords, Crypto Wallets and Sessions
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized…
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in…
IT Security News Hourly Summary 2026-09-01 10h : 7 posts
7 posts published in the last hour 07:31Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages 07:31Claude sessions hijacked, AI jolts global finance, agents get too many keys 07:31Mirage Kitten targeting aviation and FinTech sectors…
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a…
Claude sessions hijacked, AI jolts global finance, agents get too many keys
Claude sessions get hijacked Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into…
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in…
Questel – 1,226,209 breached accounts
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters “pay or leak” extortion campaign .…
