Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization…
100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers…
New Italian unicorn Exein rides the physical AI wave
Italian startup Exein has raised a $270 million round of funding led by Headline at a $1.7 billion valuation.
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an…
Researchers find way to listen in on headphones from afar
Eve’s dropping in on Alice and Bob
IT Security News Hourly Summary 2026-09-17 22h : 5 posts
5 posts published in the last hour 19:31Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds 19:02HBO Max’s verified Reddit account hijacked to spread malware 19:02Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk 19:02Flock cameras are…
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors,…
HBO Max’s verified Reddit account hijacked to spread malware
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk
Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast…
Flock cameras are tracking people as well as cars
Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.
IT Security News Hourly Summary 2026-09-17 21h : 7 posts
7 posts published in the last hour 18:3125 Years of Mass Surveillance Is Enough 18:02Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026) 18:02Should you care about an “AI slowdown?” 18:02From guidance to action: Security fundamentals…
25 Years of Mass Surveillance Is Enough
This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the…
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)
Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress…
Should you care about an “AI slowdown?”
In this week’s Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.
From guidance to action: Security fundamentals that materially reduce risk
AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take…
China’s Salt Typhoon backdoors Latin American orgs with new snooping malware
Beware the SparroWocky, my son! The backdoor that bites…
HKMA’s Quantum Preparedness Index: What Hong Kong Banks Should Do Next
HKMA’s Quantum Preparedness Index: What Hong Kong Banks Should Do Next josh.pearson@t… Thu, 09/17/2026 – 07:35 The Hong Kong Monetary Authority (HKMA) has…
IT Security News Hourly Summary 2026-09-17 20h : 3 posts
3 posts published in the last hour 17:31Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels 17:01Improving email security outcomes with real-world Microsoft Defender insights 17:00IT Security News Hourly Summary 2026-09-17 19h : 11 posts
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
Improving email security outcomes with real-world Microsoft Defender insights
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where…
IT Security News Hourly Summary 2026-09-17 19h : 11 posts
11 posts published in the last hour 16:31Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix 16:31FBI, Coast Guard probe suspected cyberattacks on ships entering US waters 16:31New Settra Ransomware…
Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix
Security researchers at JFrog disclosed the vulnerability on Tuesday, assigning it the identifier CVE-2026-90894 and the nickname “ParaShells.” JFrog…
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
The investigation comes at a time of heightened vigilance over U.S. port facilities and maritime security.
New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
Researchers at Huntress have detailed two ransomware incidents involving Settra, a relatively new strain first observed in June, and revealed a consistent…
