This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415…
Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations
Check Point has identified and blocked a large-scale email phishing campaign using fraudulent financial hardship and debt-relief offers to manipulate…
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
When Android users get a call from a non-contact, they will see more information about the caller, including their country.
Fideo Lens reveals connections across identities, accounts and devices
Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships…
Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel…
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting…
CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability
CVE-2026-72898 is a critical unauthenticated SQL injection in Metabase’s password-reset functionality. Learn more about it.
Grok fooled into stealing user chat, location data, and more
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.
Frontier AI: Vulnerability Management’s Systemic Revolution
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between…
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously…
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal…
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365…
IT Security News Hourly Summary 2026-08-25 15h : 3 posts
3 posts published in the last hour 12:31Encrypted instructions can fool AI assistants like Grok and Gemini 12:02Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud 12:00IT Security News Hourly Summary 2026-08-25 14h : 11 posts
Encrypted instructions can fool AI assistants like Grok and Gemini
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products,…
IT Security News Hourly Summary 2026-08-25 14h : 11 posts
11 posts published in the last hour 11:32EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next 11:32The County Prosecutors Who Became ICE Informants 11:32Australia Warns of Active Exploitation of Critical TeamCity Server Flaw 11:32First Malware Built…
EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next
EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised…
The County Prosecutors Who Became ICE Informants
Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative…
Australia Warns of Active Exploitation of Critical TeamCity Server Flaw
Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government
First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
Multiple Zscaler Client Connector Flaws Enable Remote Code Execution
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to…
Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages
Cybercriminals are using Google Sites to host fake download pages for OpenAI Codex, turning a familiar search into a malware trap. The campaign targets…
ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers
ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts linked to login credentials obtained from…