Introduction AI-assisted development has crossed a threshold. The question is no longer whether your IDE communicates with an AI, it’s how deeply that AI…
IT Security News Hourly Summary 2026-09-25 22h : 14 posts
14 posts published in the last hour 19:31Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now! 19:31Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines 19:31Why would you want to turn off Apple Intelligence and Siri AI on…
Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!
ServiceNow released security updates for five AI Platform flaws, including two critical vulnerabilities that could let unauthenticated attackers access,…
Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines
Attackers are turning routine business complaints into malware traps. A message about a damaged delivery or refund request can look ordinary, yet one…
Why would you want to turn off Apple Intelligence and Siri AI on iOS 27?
The brand-new iOS 27 now runs on iPhone 11 and newer models, bringing exciting AI features, including its core feature: a smarter Siri. Understandably,…
WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments
WordPress administrators are being urged to patch a high-severity core vulnerability that can turn an anonymous comment into server-side command…
Fake Google Security Team ad says ‘no script reading’ in voice phishing – then prints the script
More mockery and memes from the Dark Web Roast
TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
TWEAKOS steals messaging accounts and turns them into items for sale. The operation pairs a Windows stealer with a Telegram bot for managing victims and…
Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
Sauron Loader has surfaced in attacks on German organizations, giving intruders a way to deliver more malware. The new tool need not be the first thing a…
Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
CARBONATO is a botnet that turns Docker servers into footholds for attackers. It places an AI agent inside compromised systems, letting operators send…
Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems
Attackers broke into a Windows system through a known flaw in Samsung’s MagicINFO software, then built a cryptocurrency miner on the compromised machine.…
International investigation identifies over 70 potential victims exploited in Indian restaurants
The coordinated action conducted on 18 September 2026 led to two arrests. Allegedly, the traffickers forced their victims to work up to 16 hours per day,…
14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers
A 14-year-old Linux kernel vulnerability can let a local attacker escalate to root privileges and, in a proof-of-concept environment, escape a Docker…
Why security belongs in the network
SPONSORED EXPLAINER: Merging security into the network makes enterprise protection more agile
OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services
Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by…
IT Security News Hourly Summary 2026-09-25 21h : 8 posts
8 posts published in the last hour 18:31ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’ 18:31Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million 18:31CAIRN framework, Muse zero-day, BigDiskBuster 18:31Critical Next.js ImageResponse Flaw Can Lead…
ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’
Data theft and extortion biz, that is
Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million
Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates.…
CAIRN framework, Muse zero-day, BigDiskBuster
Cisco releases open-source CAIRN framework Muse zero-day opens the door to account takeovers Microsoft can’t wake up from Nightmare Eclipse Get the show…
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other…
Apple Ships Desktops Pitched As Enterprise AI Alternative
Apple starts shipping new range of Mac Studio desktops priced at up to nearly $20,000, positioning them as data centre substitute
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to…
Discord Wants to Estimate Your Age Without Asking for ID
Discord is rolling out machine-learning age assurance that estimates whether users are teens or adults without requiring most accounts to submit ID.
IT Security News Hourly Summary 2026-09-25 20h : 8 posts
8 posts published in the last hour 17:31Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical 17:31Google Maps Error Causes Traffic Chaos In Rural Scotland 17:31Crooks use fake desktop apps to fool HR staff into giving them remote…
