We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and…
Anthropic Researcher Resigns With Warning About the Dangers of AI Development
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology’s next evolution.
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.
IT Security News Hourly Summary 2026-09-10 17h : 41 posts
41 posts published in the last hour 14:32ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen 14:32Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell 14:32ClickFix moves into the browser:…
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
The ID checking company said the data breach included people’s full names and driver’s licenses and other government-issued identity documents.
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active…
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated…
Syrian migrant smugglers arrested in coordinated strike in Germany and Serbia
This follows several years of intensive and extensive investigations led by the German Federal Police under the direction of three Bavarian Public…
Essential AI agent security questions
AI agents are outpacing legacy IAM. Discover the 3 questions every CISO must ask to secure them.
Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation
Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT…
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities
Stealing AI Reasoning Traces
Interesting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’…
Secure AI Coding: Governing every agent, artifact, and identity
Enterprises are seeing an unprecedented surge in AI coding adoption with spend on AI coding tools projected to top $13 billion in this calendar year1,…
36K Plex servers unpatched against recent flaws
More than 36,000 Plex Media Server installations accessible from the internet have not been patched against recently disclosed security vulnerabilities,…
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware…
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought
Drug trafficking investigation leads to some of the world’s biggest underground bankers
The investigation, led by the Spanish National Police (Policía Nacional) and supported by Europol, has resulted in the arrest of 21 suspects for offences…
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365
Cyber Briefing: 2026.09.10
Internet-facing vulnerabilities, third-party compromises, and supply-chain controls remain central security concerns, while government agencies and…
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection
Attackers call employees’ personal phones to break into Microsoft 365 accounts
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into…
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed…
Lumexa Imaging breach affects 5.8M individuals
Lumexa Imaging has notified federal regulators of a massive data breach affecting 5.8 million individuals after a vendor compromise allowed unauthorized…
