12 posts published in the last hour 12:31QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes 12:31HiddenLayer Raises $100 Million for AI Runtime Security 12:02New StreamRAT Android Trojan Gives Hackers Full Remote Control Through VNC and…
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images…
HiddenLayer Raises $100 Million for AI Runtime Security
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents.
New StreamRAT Android Trojan Gives Hackers Full Remote Control Through VNC and Accessibility
StreamRAT is a new Android banking trojan that gives criminals broad control of an infected phone. It pairs streaming offers with screen viewing, remote…
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.
Microsoft Teams, Outlook Crashes Following August 2026 Updates on ARM-Based Devices
Microsoft has confirmed a known issue causing Microsoft Teams and the new Outlook for Windows to crash or fail to launch on ARM-based PCs after installing…
US and Canadian Court Records Breached Following Thomson Reuters Incident
Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US
Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host
Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of…
New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds
Researchers have developed SweepLED, a smartphone-based hidden-camera detection system that uses a low-cost LED accessory and computer vision to identify…
Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks
A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems,…
Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026.…
Hackers Turn Trusted Node.js Runtime Into Malware Launcher in Ransomware-Linked Attacks
Cybercriminals are increasingly hijacking Node.js, the widely used JavaScript runtime, to slip malicious code past security defenses, according to new…
IT Security News Hourly Summary 2026-09-03 14h : 12 posts
12 posts published in the last hour 11:31Attackers Exploit CVE-2026-82329 to Forge JFrog Artifactory Admin Tokens 11:31I’ve been deepfaked: What do I do? 11:31HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning 11:31Attackers Turn Trusted Node.js Runtime Into Malware…
Attackers Exploit CVE-2026-82329 to Forge JFrog Artifactory Admin Tokens
Cybersecurity researchers have observed attackers exploiting a critical JFrog Artifactory vulnerability shortly after its public disclosure. The flaw…
I’ve been deepfaked: What do I do?
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning
QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from…
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new…
Researching Employment Scams
Researchers built a fake company to study fake employee scams .
Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This…
Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations…
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
153 Million Driver License Images Offered on Dark Web
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
Russian man indicted for spreading malware to 80,000 freelancers
A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by…
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and…
