Microsoft linked more than 30 rotating domains to MacSync Stealer by correlating endpoint and network behavior across the malware’s attack chain.
Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials
Cloud Software Group has issued a critical security bulletin warning customers of two serious vulnerabilities affecting NetScaler ADC (formerly Citrix…
Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
Many teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal…
Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions
A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by…
Bluesky Hit by Second Major DDoS Attack in Months
Bluesky suffered its second major DDoS attack in months, causing hours of disruption as a threat group claimed responsibility for the outage.
CISA Adds Microsoft Internet Key Exchange RCE Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Microsoft Internet Key Exchange vulnerability, tracked as CVE-2026-33824,…
IT Security News Hourly Summary 2026-08-19 19h : 8 posts
8 posts published in the last hour 16:31Critical Snowflake GitHub Actions Flaw Exposes Projects to Command Injection 16:31Flock surveillance backlash mounts as fiendish Halloween plans circulate 16:31Microsoft Copilot Flaws Could Expose User Data With One Click 16:02Exclusive: Linux Foundation’s Akrites…
Critical Snowflake GitHub Actions Flaw Exposes Projects to Command Injection
Snowflake’s public snowflakedb/snowflake-connector-net repository has been identified as vulnerable to GitHub Actions workflow injection. This…
Flock surveillance backlash mounts as fiendish Halloween plans circulate
CEO apologizes for police misuse as activists call for vandal action against license plate cameras
Microsoft Copilot Flaws Could Expose User Data With One Click
Microsoft Copilot Personal contains three vulnerabilities that could allow an attacker to execute a malicious prompt with one click and exfiltrate data…
Exclusive: Linux Foundation’s Akrites to Go Live in September
The Linux Foundation’s Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for…
Sideloading on Android: What it is, why it’s risky, and how to do it more safely
With the new Advanced Flow for sideloading being rolled out, it’s time to discuss what sideloading is and how to do it more safely.
GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability
GitLab patched a critical GraphQL flaw as researchers observed exploitation attempts.
Android 17 QPR2 Beta 3: Google Adds Customization and New Scam Defenses
Android 17 QPR2 Beta 3 adds Pixel customization tools, call-forwarding scam protections, and experimental cellular security features.
IT Security News Hourly Summary 2026-08-19 18h : 7 posts
7 posts published in the last hour 15:31Ransomware disproportionately targets medium-sized firms, straining customer relationships 15:31MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra 15:31Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School 15:31Former Ping Identity and CyberArk Executives…
Ransomware disproportionately targets medium-sized firms, straining customer relationships
These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra
Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School
Education has overtaken every other industry to become the most targeted sector for cyberattacks worldwide, according to new research from Check Point,…
Former Ping Identity and CyberArk Executives Join AppViewX to Scale Machine and Agent Identity Security
New York, New York, August 19th, 2026, CyberNewswire New revenue leader and board member join as AppViewX’s identity security business continues its rapid…
Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON
A threat actor impersonating a senior executive at a well-known cryptocurrency media outlet attempted to infect a Huntress researcher with malware in the…
Apple Patches Dozens of WebKit Flaws in Latest Security Updates
Apple has issued a major set of security updates for macOS, iOS, and iPadOS after discovering dozens of vulnerabilities in WebKit, the browser engine that…
IT Security News Hourly Summary 2026-08-19 17h : 28 posts
28 posts published in the last hour 14:32Inside A CISO’s Playbook: What Agentic Security Looks Like In Practice 14:32ReversingLabs: Deep Analysis of the Final Build, File by File 14:32Dangerous Apple Bug Lets Images Execute Malicious Code 14:32Simple Scans for Cloud…
Inside A CISO’s Playbook: What Agentic Security Looks Like In Practice
Cyberhaven’s Office of the CISO is setting a higher standard for cybersecurity by embracing a new paradigm: autonomous, agent-driven security. Faced with…
ReversingLabs: Deep Analysis of the Final Build, File by File
Black Hat 2026 Vendor Profile — Cyber Defense Magazine By Dr. Arun Lakhotia Black Hat 2026: The Supply-Chain Trust Series — Cyber Defense Magazine. Part…