Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users
Your data doesn’t die when you do (Lock and Code S07E17)
This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.
IT Security News Hourly Summary 2026-08-24 17h : 7 posts
7 posts published in the last hour 14:31Hired for One Job, Judged on Another: The CISO’s Real Problem 14:31AliExpress caught using silent audio to fingerprint visitors’ browsers 14:02A tiny “rainbow on a chip” could help supercharge 6G networks 14:02ToxicPanda 2.0…
Hired for One Job, Judged on Another: The CISO’s Real Problem
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job.
AliExpress caught using silent audio to fingerprint visitors’ browsers
Silent audio processing on the AliExpress website was found helping to fingerprint visitors’ browsers without relying on cookies.
A tiny “rainbow on a chip” could help supercharge 6G networks
Researchers have created a tiny chip that produces a stable “rainbow” of light capable of generating multiple high-frequency signals at once, potentially…
ToxicPanda 2.0 can take over your Android phone and banking apps
A new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services.
Suspected Iran-linked attack knocked UK power plant offline for days
News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid…
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely…
IT Security News Hourly Summary 2026-08-24 16h : 11 posts
11 posts published in the last hour 13:31How to Secure Fintech REST APIs Against BOLA Vulnerabilities 13:31Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages 13:31Doubloon Dredger Abuses Notion to Harvest Authentication Tokens 13:31North Korean Hackers Hide…
How to Secure Fintech REST APIs Against BOLA Vulnerabilities
Broken Object Level Authorization (BOLA) occurs when a REST API exposes an object identifier—such as an account, transaction, or loan ID — without…
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to…
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
North Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk,…
AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs
AmnesiaStealer is a newly identified macOS information stealer that does more than copy saved passwords. It can give criminals quiet control of a browser…
AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev’s headphones
Sawtooth waves you can’t hear still mess with your Bluetooth. Firefox and Brave say they’ve got you covered
9 Proofpoint alternatives. Pros & cons of the leading options
Proofpoint catches malicious traffic and blocks data exfiltration well, with solid coverage for business email compromise, phishing, and malware. But it’s…
Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords
Microsoft Teams phishing is again being used as a doorway to deliver a malware family called SynkLoader. The campaign relies on a familiar…
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation.
Microsoft August 2026 Windows Updates Trigger Issues on Devices Using RGB Lighting Features
Microsoft is investigating a Windows 11 issue in which the August 2026 security updates can cause certain games to freeze, crash, display access-violation…
IT Security News Hourly Summary 2026-08-24 15h : 10 posts
10 posts published in the last hour 12:32The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk 12:32Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor 12:32Hackers Impersonate Security Staff to Steal Credentials in ReliaQuest Social…
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for…
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go…
Hackers Impersonate Security Staff to Steal Credentials in ReliaQuest Social Engineering Attack
ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and…