Managed detection and response provider Huntress has issued a threat advisory warning of an active and rapidly growing credential stuffing campaign…
Critical VMware vCenter Flaws Let Remote Attackers Bypass Authentication and Execute Code
Broadcom has released important security updates addressing critical vulnerabilities in VMware that could allow remote attackers to bypass vCenter…
CREST Launches AI-Enabled Pentesting Accreditation
CREST has introduced an optional AI-Enabled Penetration Testing accreditation module designed to verify responsible AI usage among cybersecurity service…
Tengu botnet reboots Linux devices to survive removal
A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another…
Critical Ruflo MCP Bridge Flaw Allows Full AI Agent Platform Takeover
A critical vulnerability in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to achieve full remote…
US, Australia Release OT Isolation Guidance
The United States and Australia have published joint guidance to help critical infrastructure organizations isolate their operational technology systems…
Stairwell launches Backstory, pioneering agentic investigation for malware blast radius
Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces…
IBM: Average Data Breach Cost Hits $5M
The global average cost of a data breach has climbed to $4.99 million, marking a 12% increase over the previous year and setting a new record, according…
IT Security News Hourly Summary 2026-07-29 15h : 18 posts
18 posts were published in the last hour 13:2 : Mate Security Raises $35 Million for Agentic SOC 13:2 : macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets 13:2 : Houston City College Data…
Mate Security Raises $35 Million for Agentic SOC
The startup will use the investment to expand its customer support, sales, and R&D teams.
macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets
macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS…
Houston City College Data Breach Exposes 832k Unique Student Email Addresses
Houston City College has experienced a serious data breach that exposed sensitive personal information of approximately 832,000 unique students and alums.…
120 fake Walmart stores stealing credit cards
A network of more than 120 fraudulent websites impersonating Walmart is actively stealing credit card information from online shoppers.
Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism, Issues Arrest Warrant
Russia’s Federal Security Service (FSB) has formally charged Telegram founder and CEO Pavel Durov with aiding terrorism and issued a warrant for his…
CISA adds Arista and Fortinet flaws to KEV catalog
The U.S.
Fake Recruiters Target Web3 Developers Through Trusted Bitbucket and npm Workflows
A new wave of job scams is hitting Web3 developers who are simply looking for their next role. Attackers pose as recruiters, start friendly chats about…
ThreatLocker Raises $190 Million in Series F Funding
The company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation.
Securing What Matters: Why Cyber Resilience Needs Prioritisation
Recent government data shows the scale of cyber threats facing security teams. According to the Cyber Security Breaches Survey 2025/2026, it’s estimated…
JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox
Artificial intelligence models have now demonstrated how quickly a security test can become a real infrastructure risk. In an isolated evaluation, OpenAI…
Mythos Asks the Right Question. It Doesn’t Answer It.
AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve…
Android Malware Scanners Are Flagging Legitimate Apps and Missing Threats Without Context
Android malware scanners are increasingly misaligning with real-world risk by over-flagging legitimate, high-permission applications while quietly missing…
Managing cyber-physical risk in smart buildings
Smart buildings promise greater efficiency, improved sustainability and enhanced operational oversight. However, as building management systems, security…
20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of…
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.…