JetBrains has revealed a security incident involving its Cadence cloud development service after attackers gained access through an unpatched TeamCity…
IT Security News Hourly Summary 2026-09-08 15h : 13 posts
13 posts published in the last hour 12:31Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids 12:31Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws 12:31WeedHack Malware Persists as…
Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids
Images of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say…
Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws
Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and…
WeedHack Malware Persists as Fake Minecraft Sites Survive C2 Disruption
Fake Minecraft sites continue distributing WeedHack malware through SEO poisoning and trusted hosting platforms despite disruption of its original C2…
Museum heists turn violent: new Europol report on cultural property theft tactics
The spotlight features some key findings:Increasing violence: Museum thefts are becoming more aggressive, with offenders using tools like sledgehammers,…
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These…
Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names,…
REVSTEALER Malware Disables Windows Security to Run a Crypto Miner
A new malware campaign associated with the REVSTEALER information stealing malware has been discovered using another four additional malicious programs to…
Extortion crews have their eyes on high-value AI data, Google warns
Companies ‘don’t want their IP exposed, so they’re willing to pay’
Agents of Chaos: A New $100K Agentic Security Challenge
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Agents of Chaos: A New $100K Agentic Security Challenge
Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise
Anthropic’s Claude Mythos Preview has demonstrated the ability to complete an end-to-end enterprise intrusion simulation, progressing from initial access…
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators…
IT Security News Hourly Summary 2026-09-08 14h : 17 posts
17 posts published in the last hour 11:31MikroTik Patches Critical Flaws Chained to Hack Routers 11:31THost9 Android RAT Pairs Packed Loader With ADB Worm 11:31WhatsApp Testing Guest Calls for People Without a WhatsApp Account 11:31IT help-desk vishing tricks executives into…
MikroTik Patches Critical Flaws Chained to Hack Routers
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.
THost9 Android RAT Pairs Packed Loader With ADB Worm
THost9 hides its payload and uses ADB to spread across exposed Android devices and containers
WhatsApp Testing Guest Calls for People Without a WhatsApp Account
WhatsApp is developing a guest-call feature that would let people without a WhatsApp account join encrypted calls through a web link. This capability…
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against…
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an…
IT Security News Daily Summary 2026-09-08
71 posts published today 11:02N-able Patches Critical Zero-Day in N-central 11:02The Best Firewall-as-a-Service (FWaaS) Providers, Compared and Priced (2026) 11:02Top 10 Best Extended Detection & Response (XDR) Platforms in 2026 11:02MikroTik router flaws allow takeover without a password 11:02Top 10…
N-able Patches Critical Zero-Day in N-central
Administrators are advised to check their deployments for newly created user accounts they don’t recognize.
The Best Firewall-as-a-Service (FWaaS) Providers, Compared and Priced (2026)
Firewall-as-a-service moved from experiment to default: inspection, IPS, and policy delivered from the cloud, priced per user or per site instead of per…
Top 10 Best Extended Detection & Response (XDR) Platforms in 2026
Palo Alto Cortex XDR scores highest in our 2026 evaluation, with CrowdStrike close behind on detection engineering and Microsoft Defender XDR leading on…
