Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where…
Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data.
IT Security News Hourly Summary 2026-08-18 09h : 8 posts
8 posts published in the last hour 06:31How QR-code phishing can slip past corporate security measures 06:31Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases 06:31Shadow hVNC Malware Kit Gives Hackers Hidden Windows Desktop for…
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases
A new threat intelligence report from Gambit Security has documented one of the clearest real-world examples yet of artificial intelligence being…
Shadow hVNC Malware Kit Gives Hackers Hidden Windows Desktop for Covert Remote Control
A newly advertised malware-as-a-service toolkit named Shadow hVNC combines browser credential theft, hidden virtual desktop control, reverse proxying, and…
Google’s open-source HEIR lets AI work with data it can’t see
Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler…
Public Exploit Code Released for Microsoft SCCM Remote Code Execution Vulnerability
Public proof-of-concept exploit code is now available for CVE-2026-47301, a critical remote code execution vulnerability affecting Microsoft Configuration…
VMware vCenter RCE Gives Attackers a Path From One Appliance to Entire Virtual Infrastructure
A critical VMware vCenter vulnerability is being actively exploited in a fast-moving campaign that turns a single exposed management appliance into a…
Multi-Factor Authentication (MFA) Explained: Types, Bypass Attacks and Best Practices (2026)
By HOC Team | Last updated: August 2026 | Read time: ~22 min In September 2022, Uber suffered…
IT Security News Hourly Summary 2026-08-18 08h : 5 posts
5 posts published in the last hour 05:31PoC Exploit Released for Microsoft SCCM Vulnerability Enabling SYSTEM-Level Code Execution 05:31A hollowed out data layer is making CISOs fly blind into AI attacks 05:31Pokémon Center Data Breach Exposes Customers’ Personal and Order…
PoC Exploit Released for Microsoft SCCM Vulnerability Enabling SYSTEM-Level Code Execution
A recently disclosed proof-of-concept (PoC) exploit for Microsoft Configuration Manager, previously known as System Center Configuration Manager (SCCM),…
A hollowed out data layer is making CISOs fly blind into AI attacks
The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However,…
Pokémon Center Data Breach Exposes Customers’ Personal and Order Data
Pokémon Center has begun notifying customers in the United Kingdom and Germany that personal information from their online orders was exposed following a…
Attackers turn to AI for help identifying files worth stealing
AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable…
GitLab Released GraphQL Vulnerability (CVE-2026-19478) Emergency Patch
GitLab released an emergency, out-of-band security update to address a critical access control flaw affecting self-managed instances of…
Cybersecurity jobs available right now: August 18, 2026
CISO ADI Global Distribution | USA | Hybrid – View job details As a CISO, you will develop and lead ADI’s global security strategy to protect information…
Pokémon Center Confirms Data Breach – Hackers Stole Customers’ Personal Data
Pokémon Center has begun notifying customers in the United Kingdom and Germany that their personal information was exposed in a third-party data breach,…
ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056,…
IT Security News Hourly Summary 2026-08-18 00h : 6 posts
6 posts published in the last hour 21:55IT Security News Daily Summary 2026-08-17 21:31Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects 21:02SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers 21:01‘MessiahGPT’ AI Service Promises…
IT Security News Daily Summary 2026-08-17
163 posts published today 21:31Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects 21:02SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers 21:01‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware 21:01Philips and GE Investigate…
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that,…
SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers
SafePal says a security flaw exposed personal and order information for nearly 40,000 customers, increasing the risk of targeted phishing attacks.
‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware
Trellix says MessiahGPT is marketed to cybercriminals as an uncensored AI service for ransomware, phishing kits, malware, and breach exploitation.