Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to…
SAP Commerce Cloud CVE-2026-58231 Under Active Exploitation
SAP Commerce Cloud is facing active exploitation of a critical security vulnerability that carries the maximum severity rating.
Akamai Valkey Managed Database: Real-Time Memory for Enterprise AI
Introducing Akamai Valkey Managed Database: a low-latency, in-memory data layer to optimize AI inference costs, accelerate RAG, and power real-time AI…
Google’s Zero-Trust AI Agent Framework
Google has published an open-source autonomous customer support agent that showcases how zero-trust security principles can be applied to AI systems with…
Critical MLflow SSRF Flaw Exploited in the Wild
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours…
Google Docs Misconfiguration Exposes Staging Credentials
A contractor working for QR generation service Pageloot inadvertently exposed login credentials for the company’s staging environment after storing them…
The Mistake That Exposed a Global Cyber Crime Operation
Most cyber crime investigations reveal the aftermath of an attack. Few reveal the attackers themselves. That’s what makes Check Point Research‘s latest…
Gaps in Credential Security Programs and Continuous Defense
Cybersecurity professionals widely acknowledge credential compromise as a major threat, but most organizations lack continuous monitoring and automated…
AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland’s EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI)…
ETSI Proposes 17 Cybersecurity Standards for EU CRA
The European Telecommunications Standards Institute (ETSI) has initiated the approval process for 17 cybersecurity standards that will govern product…
FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight
Federal court records show how far the FBI’s Pegasus review progressed — and why new US spyware reporting will still leave major gaps in government…
China-Nexus APT Exploits VMware vCenter CVE-2026-59310
Cybersecurity researchers have identified active exploitation of a critical VMware vCenter Server vulnerability by a suspected Chinese state-sponsored…
OpenAI Warns Organizations to Automate Cybersecurity as AI-Powered Attacks Accelerate
OpenAI has issued a warning that organizations need to quickly automate core cybersecurity functions as increasingly advanced AI systems make it easier…
International Cyber Expo Unveils New Talks for its Global Cyber Summit 2026
International Cyber Expo has announced a new line-up of speakers and sessions for its Global Cyber Summit, with discussions set to tackle some of the…
Copilot tricked into telling reseachers how to hack itself
How to social engineer an AI’s reasoning engine
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely…
IT Security News Hourly Summary 2026-08-18 15h : 14 posts
14 posts published in the last hour 12:31Download: 2026 Credential Risk Report 12:31Fortinet Acquires AI Security Company Virtue AI 12:31Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting 12:31French Tax Authority Cyberattack Exposes Tax Data of…
Download: 2026 Credential Risk Report
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and…
Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems.
Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting
A cryptocurrency fraud operation has been found using AI coding tools to turn huge phone lists into a sharper victim-targeting system. The campaign…
French Tax Authority Cyberattack Exposes Tax Data of 678,000 Individuals and Businesses
France’s Directorate General of Public Finances (DGFiP) has reported a cyberattack that resulted in unauthorized access to and extraction of tax and…
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog after confirming…
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations…
Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim’s Mouse
Shadow hVNC is a remote access tool built to operate where victims cannot see it. Instead of taking over the visible desktop, it can create a separate…