Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and…
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are…
Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach
Valve has confirmed that a cyberattack on CEVA Logistics, its European shipping partner for Steam hardware such as the Steam Deck, Steam Machine, and…
IT Security News Hourly Summary 2026-08-10 15h : 15 posts
15 posts were published in the last hour 12:31 : Levi Strauss Hit by Cyberattack 12:31 : New CSS Attacks Expose Webmail Users to Passord and Token Theft 12:31 : Anthropic enables auto mode for Claude Code by default 12:31…
Levi Strauss Hit by Cyberattack
Levi Strauss & Co.
New CSS Attacks Expose Webmail Users to Passord and Token Theft
In new research, CSS-based attacks have been discovered that can bypass security protections in webmail services, allowing attackers to steal passwords,…
Anthropic enables auto mode for Claude Code by default
Anthropic announced it will activate auto mode as the default setting for Claude Code sessions on Pro, Max, and Team subscription plans beginning August…
OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns
OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s…
Health Information Privacy Reform Act Advanced
The Health Information Privacy Reform Act has cleared a significant legislative hurdle after the Senate HELP Committee advanced the bill by a unanimous…
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
No, no nasties to see here, guv…
Ghostjacking: AI Agents Bypass Firewalls
A new attack technique called Ghostjacking exploits AI coding agents to bypass firewall defenses at major corporations, according to research presented at…
ICE Can Now Buy Your Credit Card Information
Every time you apply for a credit card or update your account details, you may be sharing your data with ICE. A research by 404 Media said that personal…
Cloudflare launches AI-powered Radar Researcher
Cloudflare has released a beta version of Radar Researcher, an artificial intelligence tool that translates natural language questions into queries…
Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks
Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose…
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The…
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular…
Interlock Turns the Tools Incident Responders Use Into Weapons for Stealing Windows Passwords
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft. The group has turned memory analysis software into a…
IT Security News Hourly Summary 2026-08-10 14h : 10 posts
10 posts were published in the last hour 11:31 : Metabase Patches Vulnerability Exploited as Zero-Day 11:31 : Framework loses customer data in Metabase zero-day attack 11:31 : MITRE ATT&CK Framework Explained: How to Use It for Threat Detection (2026)…
Metabase Patches Vulnerability Exploited as Zero-Day
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
Framework loses customer data in Metabase zero-day attack
Repairable hardware is little comfort when personal details escape
MITRE ATT&CK Framework Explained: How to Use It for Threat Detection (2026)
By HOC Team | Last updated: July 2026 | Read time: ~22 min In the months following the…
Python Now Has a Post-Quantum Encryption Library
This is good : Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we…
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems,…