Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to…
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which…
Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator…
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents…
Chrome 152 Patches Over 300 Vulnerabilities
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.
Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best…
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password
Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The…
IT Security News Hourly Summary 2026-08-26 12h : 15 posts
15 posts published in the last hour 09:32NVIDIA NemoClaw Flaw Lets Attackers Hijack AI Agents With One Website Visit 09:31The Planting Seeds philosophy. Selling into schools takes years, not quarters 09:31Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor…
NVIDIA NemoClaw Flaw Lets Attackers Hijack AI Agents With One Website Visit
A critical vulnerability in NVIDIA NemoClaw that could let attackers hijack an AI agent after a victim visits a malicious website. The issue, tracked as…
The Planting Seeds philosophy. Selling into schools takes years, not quarters
It’s tempting for MSPs to write off event sponsorship in education as a waste of money. You sponsor an event, hand out flyers, follow up with an email,…
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno…
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States…
Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code…
Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities
Google has released Chrome 152 for Windows, macOS, and Linux, delivering 327 security fixes and improvements. The update addresses 10 critical…
DDoS Attack Hits Norwegian Government Services
A coordinated DDoS campaign has caused disruption among Norwegian government services
28,000 Exposed Git Repositories Reveal API Keys, Bank Details and Employee Disciplinary Files
A routine development mistake has exposed thousands of software repositories. Researchers found 28,000 publicly reachable .git repositories containing…
88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report…
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a…
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.…
WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has…
IT Security News Hourly Summary 2026-08-26 11h : 9 posts
9 posts published in the last hour 08:31Beware of fake Indeed interview apps used to install spyware 08:31G DATA XDR: The most important questions from practice 08:3128,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials 08:02Linux Turns…
Beware of fake Indeed interview apps used to install spyware
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.