A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the…
Chinese Hackers Exploit ZyXEL Switch Flaw to Steal Data From Nearly 1,000 Devices
A Chinese threat actor has been using the recently discovered vulnerability in ZyXEL GS1900 switches to steal crucial information from the devices around…
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in…
Fake Claude Max giveaway hides a Google account phishing trap
A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel’s AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said…
Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the…
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes…
IT Security News Hourly Summary 2026-09-23 15h : 16 posts
16 posts published in the last hour 12:31Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare 12:31ShinyHunters claims FBI breach was revenge for “false” report 12:31Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites 12:03How to Secure AI Models:…
Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.
ShinyHunters claims FBI breach was revenge for “false” report
The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.
Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites
A new Malware-as-a-Service platform, Exvicy, is actively abusing compromised WordPress websites to deliver ClickFix lures disguised as Cloudflare…
How to Secure AI Models: Model Security and Adversarial Attacks (2026)
By HOC Team | Updated: October 2026 | Read time: ~22 min In October 2024, researchers at Anthropic…
Enabling Car Play and Android Auto for free on VW and Audi MMI 2026
2026 Free CarPlay and Android Auto activation on Audi MMI. Covers compatibility across Audi models, firmware decoding. No dealer visit required.
Ransomware Attacks Reach Record High for 2026
A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data
Ofcom takes a hard look at Pornhub’s Apple-powered age checks
Regulator wants to know whether parent Aylo did its homework before reopening the door to UK iPhone users
SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code
SolarWinds has released SolarWinds Observability Self-Hosted version 2026.2.3 to address two critical remote code execution (RCE) vulnerabilities. These…
NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information
NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities that could let attackers access…
Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.
The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves
Fake verification pages are steering people toward malware, but the web addresses behind the lures keep changing. Over five months, investigators tracked…
HPE Networking Analytics Engine Flaws Let Attackers Gain Root Access
Hewlett Packard Enterprise (HPE) has announced security updates for its Networking Analytics and Location Engine (ALE), addressing 10 vulnerabilities that…
The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine
EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an…
Cybercriminals Abandon Domains but Keep the Hosting Networks Behind Malware Campaigns
Cybercriminals are rapidly rotating lure domains, cloud storage buckets and command-and-control channels, but one infrastructure component is proving far…
The Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack Paths
Malware has moved into tools developers use to build and manage cloud infrastructure. A campaign linked to Graphalgo planted a remote access program in…
IT Security News Hourly Summary 2026-09-23 14h : 13 posts
13 posts published in the last hour 11:31Drug trafficking investigation leads to some of the world’s biggest underground bankers 11:31EvilTokens made phishing-as-a-service look easy. Then it got taken down 11:31Research on Models Engaging in Genie-Like Behavior 11:31AI-Powered Phishing Platform EvilTokens…
