Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch.
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from…
IT Security News Hourly Summary 2026-09-16 16h : 14 posts
14 posts published in the last hour 13:31Scattered Spider Social Engineering Attacks on UK Retailers 13:31Pixel Modem Zero-Day Exploited in Targeted Attacks 13:31Top 30 Cybersecurity Interview Questions And Answers For 2026 13:31VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows…
Scattered Spider Social Engineering Attacks on UK Retailers
A wave of cyberattacks against major UK retailers in April 2025 has highlighted the continuing effectiveness of social engineering tactics employed by the…
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
Top 30 Cybersecurity Interview Questions And Answers For 2026
By HOC Team | Updated: September 2026 Read time: ~24 min Cybersecurity hiring in 2026 is both…
VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a…
Microsoft warns of cloud storage and financial fraud campaign
Microsoft has warned customers about two sophisticated social engineering campaigns targeting corporate accounts and financial systems.
PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
A phishing campaign using a fake tax-audit notice is deploying VenomRAT through a signed copy of Notepad++. The operation, tracked as PAPERMILL, uses an…
Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
A supply chain attack targeting the Admin Menu Editor Pro WordPress plugin has compromised more than 1,500 WordPress websites after threat actors breached…
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate…
SE Labs Launches PIVOT Testing Program
SE Labs, a UK-based security testing provider, unveiled PIVOT on September 15, a new six-month testing program designed to evaluate cybersecurity vendor…
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root…
Robinhood engineers charged in $50K crypto fraud
Two engineers at Robinhood Markets face federal criminal charges for allegedly using insider information about upcoming cryptocurrency listings to profit…
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass…
Dataminr, Crisis24 integrate AI threat detection
Dataminr has embedded its Multi-Modal Fusion AI technology into Crisis24’s Horizon platform, creating an enhanced threat detection system for enterprise…
IT Security News Hourly Summary 2026-09-16 15h : 15 posts
15 posts published in the last hour 12:31Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes 12:31Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems 12:31US, UK, Dutch Agencies Expose Iranian…
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to…
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time…
Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Ordinary-looking casino websites are being used to conceal infrastructure for cyberespionage. The sites imitate low-grade gambling portals, but some…
Spain gets its first taste of AI-aided cyber attack
Data protection chiefs call for ‘immediate review’ of data protection models
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
