Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.
IT Security News Hourly Summary 2026-10-01 15h : 14 posts
14 posts published in the last hour 12:31New PS5 Relapse Exploit Breaks Into the Kernel Across Years of Firmware Releases 12:31MetaMask Security Incident Affecting Parts of Infrastructure 12:31How Financial Services Companies Can Modernize Their Software Supply Chain 12:31Researchers Use New…
New PS5 Relapse Exploit Breaks Into the Kernel Across Years of Firmware Releases
Researchers have released a new PlayStation 5 jailbreak, Relapse, that public reports say reaches firmware 7.00 through 13.60 on both the standard PS5 and…
MetaMask Security Incident Affecting Parts of Infrastructure
MetaMask has disclosed an ongoing security incident affecting part of its infrastructure, prompting the cryptocurrency wallet provider to begin…
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities.…
Researchers Use New CPU Attack to Steal Linux Root Password Hash From Memory
Branch Target Reuse (BTR) is a newly disclosed variant of the Spectre-v2 attack that leverages stale CPU branch-prediction data to leak sensitive…
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a…
ModSecurity Vulnerabilities Let Attackers Bypass Web Application Firewall Protections
Multiple newly disclosed vulnerabilities in OWASP ModSecurity could let attackers bypass web application firewall protections by exploiting parsing…
Pentagon breach exposes personal data of more than 3 million people
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data. The breach affects…
Hackers Exploit Zimbra Mail Servers With Crafted Emails to Gain Remote Access
Hackers are exploiting a serious flaw in internet-facing Zimbra mail servers with specially crafted emails. The weakness lets an outsider run commands on…
England’s schools are getting better at mopping up cyber incidents
Two-thirds report immediate recovery, although teachers remain divided over whose job security is
This month in security with Tony Anscombe – September 2026 edition
Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year’s worth of security patches in one go – here’s how to keep pace
Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks
Axios maintainers have disclosed several high-severity security vulnerabilities that could allow attackers to bypass proxy and DNS controls in server-side…
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch.
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows…
IT Security News Hourly Summary 2026-10-01 14h : 16 posts
16 posts published in the last hour 11:31OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates 11:31September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs 11:31CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords…
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from…
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight
A new macOS backdoor, tracked as CloudSyncD, that masquerades as a Zoom installer and uses invisible Unicode characters to conceal a victim’s phished…
Connected Cars Are a Surveillance Platform
Researchers at Northeastern University, in collaboration with Consumer Reports , evaluated how much modern cars spy in their drivers: To determine this,…
Cannabis smuggling from North America and Thailand into Europe: Europol highlights growing threat
Cannabis smuggling from North America and Thailand in Europe has seen a sharp rise, driven by oversupply in legal markets and the adaptability of…
Armadin raises $255.5 million to expand AI offensive security platform
Armadin has raised $255.5 million in Series B funding co-led by Andreessen Horowitz (a16z) and Accel that brings the company’s valuation to over $2.5…
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN…
Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation
TeamViewer has issued security bulletin TV-2026-1010 to address five high-severity vulnerabilities found in the TeamViewer Full Client, Host, and related…
