China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco…
Hackers Target AWS Root Accounts at 150+ Organizations in Password-Spraying Campaign
Datadog Security Research observed a password-spraying campaign targeting AWS root accounts at more than 150 organizations between July 24 and August 23,…
IT Security News Hourly Summary 2026-09-01 09h : 7 posts
7 posts published in the last hour 06:31PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain 06:31Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations 06:3113 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet…
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain
A public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange…
Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations
Research has discovered a password-spraying campaign targeting AWS root user accounts across more than 150 organizations. This highlights ongoing efforts…
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
13 malicious Composer theme packages on Packagist that turn Vietnamese movie and comic streaming websites into delivery points for iPhone spyware,…
Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers
Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted…
Museum heists turn violent: new Europol report on cultural property theft tactics
The spotlight features some key findings:Increasing violence: Museum thefts are becoming more aggressive, with offenders using tools like sledgehammers,…
LastPass enhancements improve visibility, governance, and control
LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the…
IT Security News Hourly Summary 2026-09-01 08h : 10 posts
10 posts published in the last hour 05:31Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes 05:31This month in security with Tony Anscombe – August 2026 edition 05:31BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers 05:31PaperCut Exploitation…
Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes
Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests,…
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month’s cybersecurity news
BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers
A BGP hijacking incident targeting Softaculous infrastructure redirected traffic for Virtualizor update services to attacker-controlled systems, allowing…
PaperCut Exploitation Escalates to Active Intrusions
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.
NIS2 compliance: Fixing IAM and access control before the 2026 audit
The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability.…
Broadcom Unveils VMware AI Factory With Secure Sandboxes for Enterprise AI Workloads
Broadcom has announced the VMware AI Factory, a software-defined private AI platform designed to accelerate the transition from bare-metal servers to…
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited…
BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update
Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a…
What your vendor says about PQC tells you if they are ready
In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The…
Anthropic Hardens Claude Security After AI Models Gain Unauthorized Access to Real Systems
Anthropic has hardened security around its Claude models after several incidents in which the systems gained unauthorized access to real computers during…
Cybersecurity jobs available right now: September 1, 2026
Security Engineer, PSO Google | USA | On-site – View job details As a Security Engineer, you will provide technical guidance to customers adopting Google…
ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076,…
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Introduction
Agents of Chaos: A New $100K Agentic Security Challenge
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Agents of Chaos: A New $100K Agentic Security Challenge