Cisco has disclosed that attackers are actively exploiting a zero-day SQL injection vulnerability in its Secure Email Gateway appliances.
Globalgig expands managed security portfolio to protect enterprise AI
Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI…
Traefik Labs launches Sovereign Trust Plane for AI governanc
Traefik Labs has unveiled the Sovereign Trust Plane (STP), a governance framework designed to bring accountability and verification to AI agent operations.
New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Phishing is arriving via trusted email systems. Instead of using obvious malicious addresses, attackers send ordinary account alerts, invoices and renewal…
OpenAI Investigates Report Linking AI Agents to RubyGems Attack
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.
Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant
Critical LiteSpeed Enterprise flaw lets one shared hosting account gain root, bypassing CageFS; patch now to 6.3.7 via forced update. cPanel warned that a…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access.
Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks
A new AI subscription service called Luciferus is being marketed on a hacking forum as an alternative to jailbreaking ChatGPT or Claude, Sophos found. The…
Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue…
1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
Attackers scanned 1.8 million Android APKs for hardcoded secrets, showing why developers need stronger credential management and production-build security.
Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking
Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site,…
IT Security News Hourly Summary 2026-09-15 15h : 9 posts
9 posts published in the last hour 12:31Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point 12:31New Italian unicorn Exein rides the physical AI wave 12:31Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed…
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization…
New Italian unicorn Exein rides the physical AI wave
Italian startup Exein has raised a $270 million round of funding led by Headline at a $1.7 billion valuation.
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an…
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload…
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors,…
240,000 Hit by Data Breach at Japan’s Digital Agency
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week
Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited & More. Welcome to this week’s edition of…
HBO Max’s verified Reddit account hijacked to spread malware
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
IT Security News Hourly Summary 2026-09-15 14h : 12 posts
12 posts published in the last hour 11:3125 Years of Mass Surveillance Is Enough 11:31Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 11:31WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites 11:31Apple Patches 200 Vulnerabilities With New iOS 27,…
25 Years of Mass Surveillance Is Enough
This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the…
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on…
