U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S.…
Popular npm Package With 150K Weekly Downloads Compromised in Mini Shai-Hulud Supply-Chain Attack
A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with…
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI
Hackers Compromise Cisco Routers to Spy on Networks and Reach Critical Infrastructure
Fire Ant has moved beyond attacking individual systems and is now compromising network infrastructure that organizations trust to move traffic and manage…
WatchGuard Patches Critical Vulnerabilities
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.
Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials
Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan…
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that’s been put to use by a Russia-aligned threat actor known as UAC-0099…
IT Security News Hourly Summary 2026-09-01 11h : 6 posts
6 posts published in the last hour 08:31SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications 08:31Healthcare Giant McKesson Investigates Data Breach Incident 08:31WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited 08:01Fake…
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections.…
Healthcare Giant McKesson Investigates Data Breach Incident
ShinyHunters claims to have stolen 284 million records from McKesson
WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited
The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across…
Fake Claude Opus 5 App Deploys RevStealer to Steal Passwords, Crypto Wallets and Sessions
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized…
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in…
IT Security News Hourly Summary 2026-09-01 10h : 7 posts
7 posts published in the last hour 07:31Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages 07:31Claude sessions hijacked, AI jolts global finance, agents get too many keys 07:31Mirage Kitten targeting aviation and FinTech sectors…
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a…
Claude sessions hijacked, AI jolts global finance, agents get too many keys
Claude sessions get hijacked Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into…
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in…
Questel – 1,226,209 breached accounts
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters “pay or leak” extortion campaign .…
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco…
Hackers Target AWS Root Accounts at 150+ Organizations in Password-Spraying Campaign
Datadog Security Research observed a password-spraying campaign targeting AWS root accounts at more than 150 organizations between July 24 and August 23,…
IT Security News Hourly Summary 2026-09-01 09h : 7 posts
7 posts published in the last hour 06:31PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain 06:31Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations 06:3113 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet…
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain
A public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange…
Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations
Research has discovered a password-spraying campaign targeting AWS root user accounts across more than 150 organizations. This highlights ongoing efforts…
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
13 malicious Composer theme packages on Packagist that turn Vietnamese movie and comic streaming websites into delivery points for iPhone spyware,…