Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source…
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.
Goals Are Not Enough: Securing AI Agents with NVIDIA OpenShell
In this article An agent’s goal rarely says how the agent may reach it, and capable agents are good at finding routes nobody planned for. →NVIDIA Open…
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs…
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting…
IT Security News Hourly Summary 2026-09-28 15h : 9 posts
9 posts published in the last hour 12:31Beyond Account-Level Risk: An Evidence-to-Action Pipeline for Detecting Fraud Rings 12:31OpenAI Agent Swarm Bypassed Sandbox Limits and Left 80,000 Attack Payloads Behind 12:31NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI…
Beyond Account-Level Risk: An Evidence-to-Action Pipeline for Detecting Fraud Rings
Linkage analysis connects accounts, devices and infrastructure to detect coordinated fraud rings that traditional account-level risk controls may fail to…
OpenAI Agent Swarm Bypassed Sandbox Limits and Left 80,000 Attack Payloads Behind
About 700 OpenAI agents allegedly escaped evaluation sandboxes, compromised parts of Hugging Face infrastructure, and generated over 80,000 attack…
NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI Agents
NVIDIA has launched its Open Agent Safety Platform, a security architecture designed for out-of-band monitoring, runtime policy enforcement, and…
Other users can watch your browsing and time your keystrokes through OS file notifications
Researchers at Graz University of Technology have used the file-notification systems in Windows, Linux, and macOS to spy on activity in other accounts. On…
NVIDIA wants AI agent safety enforced in silicon, not left to the agent
NVIDIA has introduced an open software platform and a hardware-based reference design intended to keep AI agents within the limits set by the…
OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government
Sam Altman says the company “have not been as fast as we would have liked” at dealing with security breaches, after news of further incidents over the…
Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
The ShinyHunters-linked threat cluster tracked as UNC6240 has renewed mass exploitation of Oracle PeopleSoft servers vulnerable to CVE-2026-35273.…
“Drunk” AI is terrible at keeping secrets
AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW…
IT Security News Hourly Summary 2026-09-28 14h : 13 posts
13 posts published in the last hour 11:31DC Health Agency Exposes 400,000 Beneficiary Records 11:31New Attack Against RSA 11:31Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities 11:02Top 10 Best Authentication-as-a-Service (AaaS) Providers in 2026 [Ranked & Scored] 11:02New Mexico Jury…
DC Health Agency Exposes 400,000 Beneficiary Records
The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.
New Attack Against RSA
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007 .…
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys.…
Top 10 Best Authentication-as-a-Service (AaaS) Providers in 2026 [Ranked & Scored]
Nobody gets promoted for building login, but plenty get breached maintaining it. Authentication-as-a-Service moved from convenience to best practice:…
New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections
A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform.
Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers
A Python-based malware builder can turn a single stealer into Windows programs for different operators. The tool packages a payload designed to take saved…
The Goal Tells an Agent What to Do. Security Has to Govern How.
In this article An agent’s goal rarely says how the agent may reach it, and capable agents are good at finding routes nobody planned for. →NVIDIA Open…
Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages
Hackers broke into business networks, stole customer records and used those details to send convincing fake bills. The campaign, called Operation Master,…
James Moore, Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind
AI adoption is moving faster than most organisations can govern it. It is a familiar line by now, repeated often enough to sound routine, and that is part…
