The 7th SIRIUS Single Point of Contact (SPoC) Network Meeting, organised by Europol’s EU Internet Referral Unit (EU IRU) together with the German Federal…
More CVEs than ever. The same old ones keep getting exploited.
Vulnerability volume is climbing fast. The exploited ones are old and already patchable.
Top 10 Best Single Sign-On (SSO) Solutions in 2026
Quick Answer: Microsoft Entra ID is the bundled default for M365 estates; Okta leads neutral catalog breadth; Ping Identity owns complex enterprise;…
Revolut Customers Targeted with New Wave of Phishing Attacks
Following a major data breach, Revolut customers are being sent convincing phishing messages
North Korean WaterPlum Hackers Infect 30,000 PCs via Fake Job Interviews, Steal $10.7M Crypto
North Korean-linked WaterPlum operators have turned job hunting into a route for theft. By posing as recruiters, they persuaded software developers to run…
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into…
New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN
A newly identified Android banking Trojan called RatHat uses phone features for account theft. The malware can guide itself through an infected device,…
Security’s 30-year habit: layering around the problem
The nurse isn’t careless. Every safe path is slower than Outlook.
Top 10 Best Identity Governance & Administration (IGA) Tools in 2026
Quick Answer: SailPoint remains the IGA benchmark with AI-driven certifications; Saviynt leads cloud-native converged governance; Microsoft Entra ID…
The Target Is No Longer the Model. It’s the Agent.
AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI…
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized…
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has…
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached…
IT Security News Hourly Summary 2026-09-21 11h : 5 posts
5 posts published in the last hour 08:31HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise 08:02Month-Old UK Start-Up Achieves Nearly $4bn Valuation 08:02Your bank is calling, but is it really your bank? How impersonation…
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote…
Month-Old UK Start-Up Achieves Nearly $4bn Valuation
‘World model’ start-up Emulate, founded by former Google DeepMind researchers, reportedly raising $700m at $3.7bn valuation
Your bank is calling, but is it really your bank? How impersonation scams work
Receiving a call or email that appears to come from your bank can be unsettling. The message may warn that someone accessed your account, a…
UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns
A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has…
IT Security News Hourly Summary 2026-09-21 10h : 8 posts
8 posts published in the last hour 07:31New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets 07:31India’s Second-Phase Semiconductor Push Attracts $12bn 07:31Google Confirms Gemini AI Breached Three Firms 07:31A week in security (September 14 –…
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI…
India’s Second-Phase Semiconductor Push Attracts $12bn
Indian government’s second-phase programme to set up a chip supply chain in the country attracts $11bn to $12bn in investment interest
Google Confirms Gemini AI Breached Three Firms
Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies.
A week in security (September 14 – September 20)
A list of topics we covered in the week of September 14 to September 20 of 2026
OpenAI Codex sandbox escape, President proposes AI Force, Cyber Command suicides
Researchers escape OpenAI Codex sandbox to run commands on host AI Force proposed to monitor technology Congress eyes new support for Cyber Command after…
