A newly disclosed Docker vulnerability, tracked as CVE-2026-17106 and nicknamed “CopyEscape,” allows malicious containers to overwrite files on the host…
The inconvenient truth about AI pentesting: someone has to check all the work
AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has…
Zenity Raises $125 Million Series C to Strengthen AI Agent Security and Governance
AI security and governance platform Zenity has announced a $125 million Series C funding round led by Norwest. The investment signals escalating…
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
The security defects could be exploited for arbitrary code execution and denial-of-service.
ISA VDA 6.0.3 – The Data Protection sheet explained
The Data Protection catalog is the shortest of the three in ISA 6.0.3 and the one most often underestimated. Twelve control questions across eight…
Valve warns Steam hardware buyers: Expect fake delivery scams
The warning affects recent buyers of Steam hardware, including the hugely popular Steam Deck.
IT Security News Hourly Summary 2026-08-11 19h : 11 posts
11 posts were published in the last hour 16:31 : Social media platforms crack down on drone factory recruiting game 16:31 : DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi 16:31 : Q&A: Ransomware is now…
Social media platforms crack down on drone factory recruiting game
Researchers found that games and major US social media platforms were used to lure young people into jobs in Russia’s drone industry.
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
This is why we can’t have nice things, people
Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while…
AWS successfully completed its 2025-26 NHS DSPT assessment
Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment…
Uncover Security Risks in Your Agent Skills Before Deploying
This tutorial explains how to catch a dangerous agent skill before an agent ever runs it: review it automatically, block it in CI if it fails, and only…
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
Two wars and a World Cup lead to epic DDoS attacks on publishers
Ukraine, Iran, and football inspire geopolitically motivated DDoS attacks, while 1 Tbps traffic jams up 519 percent
AI Genie in the Wild
When I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked…
Delta investigating after someone set up fake Wi-Fi network mid-flight
The Delta flight crew switched off the aircraft’s legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.
IT Security News Hourly Summary 2026-08-11 18h : 13 posts
13 posts were published in the last hour 15:31 : Secure development can help turn the tables as AI alters cyber landscape 15:31 : Six npm Packages Read C2 Addresses From Ethereum Wallet 15:31 : AI Helps Researchers Uncover Zoom…
Secure development can help turn the tables as AI alters cyber landscape
A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages queried an Ethereum wallet to locate C2 infrastructure
AI Helps Researchers Uncover Zoom Zero-Click RCE in Less Than a Day
Researchers used public AI models to uncover ZOOMSDAY, a critical Zoom zero-click RCE exploit chain, in less than 24 hours.
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability-coordination project has had a rocky few years, but a key leader says it will “flourish and improve.”
Alert Fatigue Is Hitting US SOCs Hard: How to Cut Through the Noise
US SOC teams are dealing with a growing volume of alerts, while analyst time and security budgets remain limited. Too much of that time is spent checking…