Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across…
WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities
WordPress has released version 7.1.1, a security and maintenance update that fixes 11 vulnerabilities affecting the widely used content management system.…
Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites
A widespread text-message phishing campaign is posing as T-Mobile to pressure customers into visiting fraudulent reward-redemption pages. The messages…
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
One Click in a Malicious VS Code Project Can Give Attackers Persistent Access to Your PC
A serious Visual Studio Code security issue could let attackers gain persistent access to a developer’s workstation with a single click inside a malicious…
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator…
Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile…
CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
Google says a Pixel modem zero-day was under targeted exploitation. CISA has added CVE-2026-58704 to KEV as users are urged to patch.
AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection
AI-powered malware is making a familiar security problem harder to contain. Instead of keeping the same code long enough for antivirus tools to recognize…
Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps
Researchers have identified significant security and privacy risks across 61,500 abandoned Android Internet-of-Things (IoT) companion applications. Their…
Top 10 Best Container Registry Security Tools in 2026
Quick Answer: The free floor is unusually strong here: Harbor (CNCF registry with scanning/signing) and Anchore’s Grype/Syft (scanning + SBOM) cover…
IT Security News Hourly Summary 2026-09-18 12h : 12 posts
12 posts published in the last hour 09:31Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer 09:31Europol celebrates the International Day of Police Cooperation 09:31Four AI Agent Security Risks Organisations Can’t Afford to Ignore 09:31Plugin4Shell Zero-Click RCE…
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as…
Europol celebrates the International Day of Police Cooperation
On 7 September, Europol is marking the International Day of Police Cooperation together with its partners to recognise the central role our network plays…
Four AI Agent Security Risks Organisations Can’t Afford to Ignore
AI agents are quickly moving from experimentation into everyday business operations. Unlike traditional generative AI tools that wait for a user to ask a…
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace…
Filigran, CyberASAP and Pulse Conferences Unite to Champion Cybersecurity’s Unsung Heroes
London, UK – 18th September 2026 –Eskenzi PR, the cybersecurity PR agency, are pleased to announce that Filigran, the European open-source threat…
Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication
Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik…
Android apps can now check security patches down to individual device components
New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0…
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.…
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an…
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
Arcjet brings security controls and audit trails to AI agents
Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams…
IT Security News Hourly Summary 2026-09-18 11h : 9 posts
9 posts published in the last hour 08:3112 Best CDR Solutions Compared (2026): Features & Pricing 08:31Fake parcel delivery messages steal your card and bank details 08:3112 Best SSPM Tools Compared (2026): Features & Pricing 08:31Manufacturing Accounts for 22% of…
