Apple introduced a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature allows supported apps to request a…
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts…
Government contractor exposed path to immigration records
IT took a shortcut when the boss was away, and it led to danger!
GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany…
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister…
Claude.ai is about 3x faster after 3,000+ changes
Anthropic engineers made claude.ai and the Claude desktop app roughly three times faster during a two-week sprint in August, with Claude finding the…
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is…
Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
An Integrated Security Operations Center (ISOC) in Microsoft Defender, unifying security information and event management (SIEM) and threat-protection…
IT Security News Hourly Summary 2026-09-24 10h : 6 posts
6 posts published in the last hour 07:31RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials 07:31Critical WordPress Vulnerability Exploited Immediately After Disclosure 07:31ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon’s cyber appetite grows…
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East,…
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon’s cyber appetite grows
ShinyHunters peeks at FBI assignments WordPress flaw wastes no time Pentagon’s cyber appetite grows Get the show notes here:…
Protecting citizens, preserving rights
How can law enforcement make effective use of data and technology while ensuring that fundamental rights and the rule of law remain protected? This…
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation. This flaw could…
IT Security News Hourly Summary 2026-09-24 09h : 7 posts
7 posts published in the last hour 06:31One URL, Three Different Tricks, (Thu, Sep 24th) 06:31New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group 06:31OpenAI Releases Lower-Cost Sol, Luna Models 06:31CLOSEDQUORUM, the malware that asks four AI models…
One URL, Three Different Tricks, (Thu, Sep 24th)
Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted…
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
A newly identified ransomware operation tracked as Galago has emerged with apparent operational links to the Panzer ransomware group, raising concerns of…
OpenAI Releases Lower-Cost Sol, Luna Models
After GPT-6 Astra, start-up releases GPT-6 Sol and Luna, cutting costs for programming, high-volume clerical tasks
CLOSEDQUORUM, the malware that asks four AI models what to do next
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found…
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs
A long-lived GitLab incoming email token embedded in project email addresses for the “Email work item” feature can be exploited to push…
Apache Tomcat 11.0.26 Fixes 12 Security Flaws Enabling WebSocket Bypass and DoS Attacks
Apache Tomcat 11.0.26 has been released with fixes for 12 security vulnerabilities, including a significant flaw that could allow attackers to bypass…
IT Security News Hourly Summary 2026-09-24 08h : 5 posts
5 posts published in the last hour 05:31Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First 05:31What to do first when you get 90 days to secure AI agent data 05:02Your security program knows about the firewall, but does…
Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First
A malicious Firefox extension masquerading as a PDF identity-verification utility has been found targeting Google accounts through session-cookie theft…
What to do first when you get 90 days to secure AI agent data
In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to…
