PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers…
Cyber Briefing: 2026.09.04
Attackers are combining critical software vulnerabilities, AI-driven automation, and third-party access to increase the potential impact of cyber…
Brazilian Government Site Compromised to Redirect Users to Betting Pages
An organization known as Gambling Goblin, which is a Chinese-speaking cybercrime group, has compromised Apache web servers owned by Brazilian government…
The Oracle of Delphi Will Steal Your Credentials
Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced…
Season 4 of The Europol Podcast available now
The Europol Podcast is the official podcast of the EU’s agency for law enforcement cooperation. This season, we spoke to our Europol experts on the…
Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks
Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such…
Politicians target Flock AI surveillance cameras
Bipartisan political opposition is mounting against Flock Safety’s automated license plate reader network, with candidates in at least six states…
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
The financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT…
Russian National Indicted for Malware Distribution
Federal prosecutors in San Francisco have secured an indictment against Russian national Searzhudin Tamirlanovich Aktulaev on multiple cybercrime charges,…
Europol-led action against nihilistic violent extremist network “The Com”
An estimated 4 340 URLs related to nihilistic violent extremism were referred during the initiative organised by Europol’s EU Internet Referral Unit – EU…
North Dakota Supreme Court hit by third-party vendor breach
The North Dakota Court System has confirmed that data associated with the state’s Supreme Court was compromised through a security breach at C-Track, a…
Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains
Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from…
OpenAI launches Astra model, claims AGI milestone
OpenAI launched its GPT-6 model, named Astra, on September 3, with company president Greg Brockman declaring it represents artificial general intelligence…
Migrant smuggling network using rental cars dismantled across the Balkans
Led by the Greek authorities and supported by Europol, the investigation targeted a criminal network composed mainly of Syrian and Egyptian nationals…
Chinese Hackers Deploy AI Agents in Multi-Country Campaign
Threat intelligence firm Hunt.io has documented a sophisticated Chinese-speaking cyberespionage campaign that integrated commercial AI models into live…
IT Security News Hourly Summary 2026-09-04 16h : 12 posts
12 posts published in the last hour 13:31Sangoma Switchvox Vulnerabilities Exploited in the Wild 13:31KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival 13:31OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques 13:31Compliance…
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution.
KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival
KnowBe4 is set to explore the growing challenge of determining what organisations can trust in the age of AI at an exclusive cybersecurity briefing during…
OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques
Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to…
Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up
The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published…
US military disabled ad tracking on troops’ devices following reports of targeted attacks
A senator’s letter confirms the U.S. military moved to prevent the tracking after foreign adversaries used location data to target troops.
Protecting Against Zero-Click Attacks
By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around…
Europol supports operation against amphetamine producers
As part of an extensive investigation led by the German Krefeld Public Prosecutor’s Office and Mönchengladbach Police, officers from the North…
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000…
