8 posts published in the last hour 15:31AI Agent Hacks Gym Booking System 15:31OpenAI Says Reward Hacking Fueled AI Agents’ Hugging Face Cyberattack 15:31Russian-Speaking Hackers Used Cursor AI in Attacks on Seven Companies, Report Says 15:31Critical Avada WordPress Vulnerability Allows…
AI Agent Hacks Gym Booking System
An AI agent designed to help with everyday tasks has ended up exposing a serious security flaw in a gym booking system. According to a report cited by…
OpenAI Says Reward Hacking Fueled AI Agents’ Hugging Face Cyberattack
OpenAI has disclosed that reward hacking played a central role in an AI-driven cyberattack targeting Hugging Face, revealing that signs of misaligned…
Russian-Speaking Hackers Used Cursor AI in Attacks on Seven Companies, Report Says
Russian-speaking hackers used Cursor AI during attacks on corporate networks, reportedly speeding reconnaissance, VPN access and exploitation attempts.
Critical Avada WordPress Vulnerability Allows Unauthenticated PHP Code Execution
A critical vulnerability chain in the popular Avada theme for WordPress could allow an unauthenticated attacker to execute arbitrary PHP code on the…
Making User-Generated Sites Embeddable: X-Frame-Options vs CSP Frame-Ancestors
If you let users publish something, such as a page, prototype, or dashboard, sooner or later you want an “embed this” button so they can drop it into a…
Flock Sought to Expand Surveillance Through Uber and Lyft Drivers
By using rideshare and delivery vehicles as mobile surveillance platforms, Flock Safety may be able to extend its automated license plate reader network…
US government snitch-finder pleads guilty to leaking state secrets to foreign spies
The IT specialist began contacting a foreign government within days of being assigned to the DIA’s Insider Threat Division
IT Security News Hourly Summary 2026-08-28 17h : 10 posts
10 posts published in the last hour 14:31Cyber Briefing: 2026.08.28 14:31Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix 14:02Secure Agent Harness Execution: Preventing Escape 14:02Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against…
Cyber Briefing: 2026.08.28
Espionage campaigns, actively exploited vulnerabilities, large-scale data exposure, infrastructure targeting, and expanding AI-driven risks underscore the…
Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix
A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an…
Secure Agent Harness Execution: Preventing Escape
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Secure Agent Harness Execution: Preventing Escape
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent…
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited…
Russian APT BlueDelta Uses HOOKEDGE Against European Government
Recorded Future’s Insikt Group has documented a sustained espionage campaign by BlueDelta, a Russian GRU-linked threat group overlapping with APT28,…
ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
Protect your WhatsApp account with new passkey and 2FA upgrades
WhatsApp has introduced three security upgrades. Here’s what to turn on to better protect your account.
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415…
IT Security News Hourly Summary 2026-08-28 16h : 16 posts
16 posts published in the last hour 13:32Key Reasons Why Identity Fabric Matters in 2026 13:32Zero-Day Dominance: How Akamai Defends Before the Industry Discloses 13:31Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign 13:31PaperCut Emergency Patch for Zero-Day 13:31Manchester Airports Group…
Key Reasons Why Identity Fabric Matters in 2026
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and…
Zero-Day Dominance: How Akamai Defends Before the Industry Discloses
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Zero-Day Dominance: How Akamai Defends Before the Industry Discloses
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious…
PaperCut Emergency Patch for Zero-Day
PaperCut has issued an emergency security update to address a zero-day vulnerability in its NG and MF print management products that is being actively…
Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers
Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising…
