Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote…
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models
Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment
Proactive AI-native security vendor Horizon3 has announced a major $20 million investment into its global partner ecosystem. The funding reinforces the…
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July…
Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems
Security researchers have discovered 23 vulnerabilities in Copeland’s XWEB Pro commercial refrigeration controllers, with 21 rated as high severity. These…
New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines
A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings,…
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and…
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous…
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data…
Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the…
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that…
IT Security News Hourly Summary 2026-08-11 13h : 18 posts
18 posts were published in the last hour 10:31 : Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection 10:31 : US Court Gives Go-Ahead To Thousands Of Social Media Cases 10:31 : Hacker Conversations:…
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate…
US Court Gives Go-Ahead To Thousands Of Social Media Cases
Thousands of addiction lawsuits against social media giants to proceed in California federal court after legal challenge dismissed
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did.
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and…
Levi Strauss & Co. Confirms Hackers Stole Corporate Data in Cyberattack
Levi Strauss & Co. (Levi’s) has announced a cybersecurity incident involving an unauthorized third party who used social engineering to access the…
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
GhostJacking Attacks Let Hackers Hijack AI Agents and Steal Cloud Credentials
Security researchers have disclosed “GhostJacking,” a new class of attacks that exploits trusted observability and security platforms to manipulate AI…
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open…
Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access…