A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal…
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365…
IT Security News Hourly Summary 2026-08-25 15h : 3 posts
3 posts published in the last hour 12:31Encrypted instructions can fool AI assistants like Grok and Gemini 12:02Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud 12:00IT Security News Hourly Summary 2026-08-25 14h : 11 posts
Encrypted instructions can fool AI assistants like Grok and Gemini
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products,…
IT Security News Hourly Summary 2026-08-25 14h : 11 posts
11 posts published in the last hour 11:32EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next 11:32The County Prosecutors Who Became ICE Informants 11:32Australia Warns of Active Exploitation of Critical TeamCity Server Flaw 11:32First Malware Built…
EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next
EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised…
The County Prosecutors Who Became ICE Informants
Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative…
Australia Warns of Active Exploitation of Critical TeamCity Server Flaw
Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government
First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
Multiple Zscaler Client Connector Flaws Enable Remote Code Execution
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to…
Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages
Cybercriminals are using Google Sites to host fake download pages for OpenAI Codex, turning a familiar search into a malware trap. The campaign targets…
ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers
ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts linked to login credentials obtained from…
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
Black Hat State of Security Vendors
Andy Ellis has a roundup of the security vendors at Black Hat this year. Key Takeaways: We have entered into an AI world. While nearly half of booths…
Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown
A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July
IT Security News Hourly Summary 2026-08-25 13h : 17 posts
17 posts published in the last hour 10:31CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX 10:31GTA 6 leak hunt could expose data belonging to thousands of Discord users 10:31The State of AI-Enabled Malware August 2026: From Brand Abuse…
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
GTA 6 leak hunt could expose data belonging to thousands of Discord users
Take-Two is demanding IP addresses, phone numbers, device IDs, and other data as it tries to identify whoever leaked GTA 6 footage.
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply…
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday.…
Silent Patches Don’t Stop Attackers – They Blind Defenders
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…