Security teams must treat autonomous agents as highly privileged identities.
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the…
OpenClaw 2.0 Released With Enhanced AI Agent Security and Credential Protection
OpenClaw has launched version 2.0, offering a major overhaul of its AI-agent platform. This update emphasizes streamlined deployment, a rebuilt browser…
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant…
Anthropic Warns Claude Users of Infostealer Malware Infections
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new…
ShinyHunters claims it stole 284 million patient records from McKesson
Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S.…
Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. “The…
IT Security News Hourly Summary 2026-08-31 14h : 8 posts
8 posts published in the last hour 11:31Hackers Use Ethereum Blockchain to Steal Credit Card Data From Online Shoppers 11:31Microsoft Confirms False “Defender Antivirus Turned Off” Alerts Spreading Across Windows Devices 11:31Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs 11:31New…
Hackers Use Ethereum Blockchain to Steal Credit Card Data From Online Shoppers
Online shoppers can have their card details stolen without ever leaving a legitimate store. A tracked Magecart campaign plants malicious checkout code on…
Microsoft Confirms False “Defender Antivirus Turned Off” Alerts Spreading Across Windows Devices
Microsoft has confirmed that a wave of alarming Windows Security pop-ups telling users their antivirus protection is disabled is nothing more than a…
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.
New AI-Built Malware Watches How Security Teams Remove It and Fights Back
A new Windows malware toolkit is showing how artificial intelligence can change the economics of cybercrime. Known as Gryxa, it gives a criminal operator…
Hiding Prompt Injection in Legal Filing
Someone hid AI instructions into a legal filing. Alternate link .
OpenClaw 2.0 Released With Major Security Upgrades for AI Agents, Plugins and Credentials
OpenClaw has released version 2026.8.1, also called OpenClaw 2.0, in what the open-source AI agent platform described as its largest update to date. The…
Boston Scientific Still Recovering From Cyberattack
The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.
IT Security News Hourly Summary 2026-08-31 13h : 12 posts
12 posts published in the last hour 10:31Dashlane vs 1Password: Features & Pricing Compared 10:31Extortion Group Claims Manchester Airports Group Data Breach 10:31ATM Flaws Reveal Key Weaknesses in the Software Supply Chain 10:31Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm…
Dashlane vs 1Password: Features & Pricing Compared
Compare Dashlane and 1Password and explore their features, pricing, and overall value to make the best choice for your needs.
Extortion Group Claims Manchester Airports Group Data Breach
FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local…
Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets
A new Shai-Hulud supply-chain attack dubbed Trinitite has compromised the npm package @7nohe/openapi-react-query-codegen, a TanStack Query code-generation…
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic…
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers,…
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final…
