Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents.
Bots with good manners are better at fooling people on social media
Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The…
CISA Upgrades Vulnerability Reporting Platform with More Automation
The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT
Europol and European Labour Authority strengthen cooperation against labour exploitation
The Working Arrangement formalises cooperation that has already demonstrated its value through joint involvement in EMPACT activities. It provides a…
Top 10 Best Cloud Compliance Tools in 2026
Quick Answer: Cloud compliance splits into two jobs: technical posture against benchmarks where free Prowler and CNAPP compliance (Wiz, Prisma Cloud,…
Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell
Linux administrators are being urged to patch four newly disclosed local privilege escalation (LPE) vulnerabilities, collectively known as DirtyAH6,…
Top 10 Best Cloud Encryption Solutions in 2026
Quick Answer: Native KMS AWS KMS, Azure Key Vault, Google Cloud KMS is the usage-based default for single-cloud estates. Dedicated platforms earn their…
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
More than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could…
Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2
Movie torrents are being used to deliver a new Windows malware framework called MovieReaper. Attackers have poisoned torrent downloads for popular films,…
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across…
WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities
WordPress has released version 7.1.1, a security and maintenance update that fixes 11 vulnerabilities affecting the widely used content management system.…
Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites
A widespread text-message phishing campaign is posing as T-Mobile to pressure customers into visiting fraudulent reward-redemption pages. The messages…
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
One Click in a Malicious VS Code Project Can Give Attackers Persistent Access to Your PC
A serious Visual Studio Code security issue could let attackers gain persistent access to a developer’s workstation with a single click inside a malicious…
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator…
Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile…
CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
Google says a Pixel modem zero-day was under targeted exploitation. CISA has added CVE-2026-58704 to KEV as users are urged to patch.
AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection
AI-powered malware is making a familiar security problem harder to contain. Instead of keeping the same code long enough for antivirus tools to recognize…
Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps
Researchers have identified significant security and privacy risks across 61,500 abandoned Android Internet-of-Things (IoT) companion applications. Their…
Top 10 Best Container Registry Security Tools in 2026
Quick Answer: The free floor is unusually strong here: Harbor (CNCF registry with scanning/signing) and Anchore’s Grype/Syft (scanning + SBOM) cover…
IT Security News Hourly Summary 2026-09-18 12h : 12 posts
12 posts published in the last hour 09:31Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer 09:31Europol celebrates the International Day of Police Cooperation 09:31Four AI Agent Security Risks Organisations Can’t Afford to Ignore 09:31Plugin4Shell Zero-Click RCE…
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as…
Europol celebrates the International Day of Police Cooperation
On 7 September, Europol is marking the International Day of Police Cooperation together with its partners to recognise the central role our network plays…
Four AI Agent Security Risks Organisations Can’t Afford to Ignore
AI agents are quickly moving from experimentation into everyday business operations. Unlike traditional generative AI tools that wait for a user to ask a…
