Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its…
Norfolk Council Hacked During Election Count
Borough council of King’s Lynn and West Norfolk detects hack of IT systems on day staff were counting votes for PCC by-election
North Korean Hackers Are Hiding Malware Servers Inside Empty Crypto Transfers
North Korean-linked attackers are using a new way to hide the servers that control malware. The method places a command server address inside an empty…
Google Disables Earth AI Imagery Over Disinformation Risk
Google suspends AI image-generation feature in Google Earth over fears fake satellite images could be used for disinformation
31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data…
Snapchat Removes AI Videos From Spotlight Feed
Social media platform becomes latest to downplay AI-generated content, after moves by LinkedIn, YouTube and Substack
OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments
The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities…
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known…
Apache NiFi Flaw Enable Security Bypass and Memory Corruption
Apache NiFi has issued security advisories for four vulnerabilities affecting its web API. These include an authorization bypass that could allow…
Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on…
License plate readers as stalking tools, ExfilSquad dumps UK police data, the ever-shrinking patch window
When license plate readers become stalking tools ExfilSquad dumps UK police contact data China-linked hackers shrink the patch window Get the show notes…
Hackers Breach Police Legal Database, Steal Contact Details
Cyber-criminals breach Police National Legal Database and steal contact information for cops, members of public, after DfE hack
IT Security News Hourly Summary 2026-08-04 09h : 6 posts
6 posts were published in the last hour 7:2 : cPanel Database Privilege Escalation Flaw Enables Full Administrative Access 7:2 : Check Point Authentication Bypass Flaw Enables Full Compromise of Security Management System 7:2 : EU begins enforcing AI Act,…
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an…
Check Point Authentication Bypass Flaw Enables Full Compromise of Security Management System
Check Point has released security updates for a high-severity authentication-bypass vulnerability (CVE-2026-18574) that could allow attackers to…
EU begins enforcing AI Act, putting AI models under the microscope
Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities…
WhatsApp account takeover scam asks you to “vote for my friend”
Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.
Digital executive protection is a strategic imperative for CEOs
In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the…
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions,…
NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking…
OWASP’s subtractive security project measures the attack paths you erased
An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an…
Apple Removes Telegram From App Store Worldwide
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging…
Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.
Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This…