Colombia’s largest health-promoting entity, Nueva EPS, has allegedly been hacked by an individual demanding $15 million not to leak the data. Colombia’s…
Citrix issues patch for third exploited flaw in NetScaler
The memory overflow vulnerability could lead to a denial-of-service condition under certain circumstances.
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released…
Legacy sign-on service comes back to bite school software provider Bromcom
Intruders retrieved email addresses from superseded tech kept running for an internal system
California Man Charged in Alleged $300M AI Server Smuggling Scheme to China
A California tech executive faces federal charges over an alleged $300 million scheme to route export-controlled AI servers to China through Southeast…
Google pauses open source bug bounty program after rise in AI submissions
Google has frozen its OSS VRP product vulnerability submissions to stop the flood of AI generated vulnerability reports.
Debian’s latest kernel security update has 1,313 reasons to patch
AI-assisted bug hunting adds to maintainers’ workload, while broad CVE rules help explain the sprawling tally
IT Security News Hourly Summary 2026-10-07 21h : 25 posts
25 posts published in the last hour 18:31ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes 18:31Dread Dark Web Forum Hijacked, Operators Claim Control of Domain Keys 18:31Proposed anti-Flock bills could spell trouble for license plate readers 18:31Hackers steal 8…
ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices
Dread Dark Web Forum Hijacked, Operators Claim Control of Domain Keys
Dread dark web forum appears hijacked after a pinned post claimed control of the project and domain keys, while denying plans to leak user data.
Proposed anti-Flock bills could spell trouble for license plate readers
Two sets of US lawmakers introduced bills in late September and early October to tackle the growing concerns about automated license plate readers.
Hackers steal 8 million citizens’ records from Danish government database
The Danish government said the breach of names, addresses, and state-issued ID numbers affects 8 million people, including people living abroad and the…
Denmark ’s Population Registry Breached, 8.8 Million Affected
Hackers accessed names, addresses and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access. A hacker…
Q&A With Oliver Simonnet at CultureAI: AI Security In 2026: Most Organisations Deploy AI And Hope For The Best
Over the past few years, AI has gone from something understood and used by a select few to a cornerstone of almost every organisation. As businesses race…
Secure the Grid: What Executive Order 14421 Means for Zero Trust
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Secure the Grid: What Executive Order 14421 Means for Zero Trust
Ordering violence from abroad: five suspects arrested in Spain, Morocco, and France
Five suspects linked to the organisation and recruitment of serious violence have been arrested in Spain, Morocco, and France, in the latest results of…
Company Behind Graphite Spyware Speaks for First Time about Italy Abuse and Accountability
[The following is an excerpt from a piece I recently published at Wired. See link below to read the full story.] Spyware maker Paragon Solutions has long…
Harvest Now, Decrypt Later: The Attack You Defend Against by Doing Nothing
Somewhere, an attacker is recording your encrypted traffic. Not breaking it. Recording it. The bet is patient and simple: store ciphertext today, wait for…
Citrix NetScaler Targeted Via New Zero Day
The memory buffer vulnerability can result in denial of service to customers, with CISA warning it poses “significant risks” to the federal government
FBI, French authorities seize deepfake CSAM-for-sale websites
Some of the material appeared to be recorded or stolen video of girls through interactions on social media sites like Snapchat, TikTok, Instagram and…
AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
Strands Box is the latest open source AI control tool from the cloud giant; like its predecessors, it promises tighter reins on autonomous agents
3 lessons from frontier AI vulnerability research
Read how How Microsoft Security’s FORGE Lab is scaling vulnerability research from Windows to the Linux kernel.
CIA officer admits to creating fake top secret government program to steal over $190M, including gold bars
CIA officer David Rush, who worked on highly sensitive intelligence programs, reached a plea deal with U.S. prosecutors after he was caught siphoning…
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access…
