By HOC Team | Updated: September 2026 Read time: ~24 min Cybersecurity hiring in 2026 is both…
Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
A supply chain attack targeting the Admin Menu Editor Pro WordPress plugin has compromised more than 1,500 WordPress websites after threat actors breached…
Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file…
Microsoft warns of cloud storage and financial fraud campaign
Microsoft has warned customers about two sophisticated social engineering campaigns targeting corporate accounts and financial systems.
Robinhood engineers charged in $50K crypto fraud
Two engineers at Robinhood Markets face federal criminal charges for allegedly using insider information about upcoming cryptocurrency listings to profit…
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
Gyazo Data Breach Exposes 23 Million User Records
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company…
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate…
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
The feds are said to be investigating the compromise of the tankers’ networks, which in one case interfered with one of the tanker’s navigation and…
Dataminr, Crisis24 integrate AI threat detection
Dataminr has embedded its Multi-Modal Fusion AI technology into Crisis24’s Horizon platform, creating an enhanced threat detection system for enterprise…
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a…
SE Labs Launches PIVOT Testing Program
SE Labs, a UK-based security testing provider, unveiled PIVOT on September 15, a new six-month testing program designed to evaluate cybersecurity vendor…
IT Security News Hourly Summary 2026-09-18 20h : 17 posts
17 posts published in the last hour 17:31Spain gets its first taste of AI-aided cyber attack 17:31Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution 17:31UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location 17:31An Undercover Google…
Spain gets its first taste of AI-aided cyber attack
Data protection chiefs call for ‘immediate review’ of data protection models
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location
UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location andrew.gertz@t… Fri, 09/18/2026 – 16:52 Data Security Cloud Security Sebastien Pavie |…
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it…
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as…
Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files
Docker has patched two vulnerabilities in Docker Sandboxes that could allow malicious code running inside an isolated sandbox to cross its intended…
Researchers used Claude to hack OpenAI employees’ ChatGPT accounts
Agentic exploits for the win (again)
Cyber-Attacks Cost Organizations $52,000 on Average
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
North Korea’s fake job interviews infected 30,000 devices
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
Threat Intelligence Alone Won’t Close the Exploitation Gap
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real…
Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
North Korean operators built a foothold on a DevOps engineer’s Mac in a campaign whose job interview lures deliver malware via Terraform lock files.
