DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last…
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.
The devil is still in the email – but wears a new mask
When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack
Jailbreaking AI: What It Is and Why It Matters for Security
By HOC Team | Updated: October 2026 Read time: ~20 min In March 2023, a researcher posted…
Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks
ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake…
Timeshare exit scams: From fake buyers to recovery fraud
Con artists are targeting timeshare owners who want out – and some victims are hit twice
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise
Oracle launches Fusion Claw AI agentic runtime
Oracle has introduced Fusion Claw, a governed agentic execution runtime designed to automate complex business processes for Oracle Fusion Applications…
Quantum teleportation breakthrough: Scientists crack a 25-year entanglement challenge
Scientists have developed and experimentally demonstrated a long-sought method for identifying W states, an important form of multi-photon quantum…
RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked…
IT Security News Hourly Summary 2026-09-30 16h : 14 posts
14 posts published in the last hour 13:31Signal adds encrypted backups, cross-platform restore 13:31AI Coding Agents Leak 13K Internal Images on GitHub 13:31EU CRA requirements for containers and Kubernetes 13:31WatchGuard Patches Critical Fireware OS Code Injection Vulnerability 13:31US CSuite Phishing…
Signal adds encrypted backups, cross-platform restore
Signal has finished rolling out cross-platform encrypted backup capabilities with iOS version 8.30, enabling users to transfer their complete message…
AI Coding Agents Leak 13K Internal Images on GitHub
Security firm Glow has uncovered a widespread data exposure incident involving AI coding assistants that inadvertently published thousands of sensitive…
EU CRA requirements for containers and Kubernetes
The European Union’s Cyber Resilience Act (CRA), formally designated as regulation EU 2024/2847, entered its initial phase on December 10, 2024,…
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.
US CSuite Phishing Campaign Steals M365 Sessions
Security researchers at ANY.RUN have identified an active phishing campaign targeting C-suite executives at U.S.
PaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
A large-scale scraping cluster dubbed PaperPhone, exposing how one operator can manufacture the appearance of tens of thousands of legitimate mobile users…
Know Your Enemy: Browser-Based Attack Techniques in 2026
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a…
CyberASAP Celebrates 10th Anniversary with Special Event Exploring Future of UK Cyber Security Innovation
In 2026, the Cyber Security Academic Startup Accelerator Programme (CyberASAP), which is funded by the UK Government’s Department for Digital, Culture,…
Trump, Six AI Giants Sign ‘Super Intelligence’ Safety Accord
Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight
Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.
Don’t Make It Easy For Them: Cybersecurity Awareness Month 2026
Don’t Make It Easy For Them: Cybersecurity Awareness Month 2026 lee.potok@thal… Wed, 09/30/2026 – 08:29 Cybersecurity Awareness Month 2026 highlights…
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the…
Docker CopyEscape CVE-2026-17106 Lets Malicious Containers Overwrite Host Files
A critical Docker vulnerability tracked as CVE-2026-17106, also known as CopyEscape, could allow a malicious container to overwrite files on the host…
