Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers…
IT Security News Hourly Summary 2026-08-24 11h : 11 posts
11 posts published in the last hour 08:31AliExpress Ran Silent Browser Audio to Fingerprint and Track Devices, Researchers Find 08:31Researchers Uncover Thousands of Leaked AWS Keys 08:02Post-DEF CON phishing campaign delivered AMOS and NetSupport malware 08:02Windows 11 Update Triggers Game…
AliExpress Ran Silent Browser Audio to Fingerprint and Track Devices, Researchers Find
AliExpress has been found to run silent audio processes in the browser to fingerprint and track devices. Thank you for being a Ghacks reader.
Researchers Uncover Thousands of Leaked AWS Keys
Truffle Security says it found over 9000 publicly accessible and active AWS key pairs
Post-DEF CON phishing campaign delivered AMOS and NetSupport malware
A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware…
Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers
Microsoft is currently investigating a compatibility issue with Windows 11, in which certain games crash, freeze, or cause unexpected system restarts on…
Report Finds Over 700 Fake VPN Extensions on the Chrome Web Store With 75,000 Installs
Cybersecurity firm Socket has identified over 700 fake VPN extensions on the Chrome Web Store. Thank you for being a Ghacks reader.
TikTok Settles U.S. Child Privacy Case for $400 Million
TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of…
A reverse image search platform exposed more than 9 million facial images
A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults,…
New macOS Malware Clones Your Logged-In Browser and Gives Hackers Remote Control.
AmnesiaStealer, a multi-stage macOS infostealer written in Rust that moves beyond conventional credential theft by giving attackers covert, interactive…
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security…
AI agents taking unsanctioned action during cyber testing
The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and…
IT Security News Hourly Summary 2026-08-24 10h : 14 posts
14 posts published in the last hour 07:32Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund 07:32Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution 07:31Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain…
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.
Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution
A critical security flaw in the popular Node.js sandboxing library isolated-vm could allow untrusted JavaScript to escape its V8 sandbox and potentially…
Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete…
Museum heists turn violent: new Europol report on cultural property theft tactics
The spotlight features some key findings:Increasing violence: Museum thefts are becoming more aggressive, with offenders using tools like sledgehammers,…
DOUBLECUP’s PNG Payload, (Mon, Aug 24th)
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#;x26;#;39;t…
China Firms Optimise Inference To Slash AI Compute Needs
Chinese companies turn to novel approach that splits single AI task among domestic, Nvidia GPUs to reduce compute requirements
UK power plant hack, AI zero click, children’s hospital breach
UK power plant disabled for four days by Iran-linked hackers Zero-click Grok and Gemini chat history theft possible through cryptographic context…
A week in security (August 17 – August 23)
A list of topics we covered in the week of August 17 to August 23 of 2026
Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks
Malicious npm packages are being used to place a Linux backdoor inside calendar and streak-calculation tools. The packages deliver legitimate date…
AWS Network Firewall Adds Rule Hit Counts to Identify Unused Security Rules
AWS has introduced a new capability for AWS Network Firewall that tracks rule hit counts, providing security teams with direct visibility into how often…
Cybermes – AI Red Teaming Agent for Automated Penetration Testing
A new open-source project called Cybermes has entered the crowded field of AI-powered offensive security tooling, positioning itself as an…