DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a…
CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
OpenAI Model Gained Unauthorized Access to Australian Government Systems
OpenAI has disclosed that an experimental internal AI model accessed several Australian government systems without authorization during training and…
OperTraitors: How Kubernetes Operators Betray Your Security Posture
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities.
Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
WatchGuard has announced the discovery of three high-impact vulnerabilities in its wireless access point platform. Two of these critical issues allow…
Palo Alto Networks and NVIDIA want tighter control over AI agents
Palo Alto Networks is expanding its work with NVIDIA to help companies control what AI agents can access and do. The collaboration covers agent activity,…
wolfSSL 5.9.4 Patches 11 Security Flaws Affecting TLS and Certificate Validation
wolfSSL has released version 5.9.4, which addresses 11 security vulnerabilities related to TLS and DTLS handshakes, X.509 certificate validation,…
SilverFox Built Fake Software Sites That Know When Researchers Are Watching
SilverFox-linked operators are evolving beyond counterfeit software portals and signed-binary abuse by using visitor-aware delivery infrastructure that…
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. “It is true that this…
Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core…
Japanese Railway Operators Hit with Weekend Cyber Attacks
Tokyo Metro and Keio have revealed separate cyber-attacks
Protego Ventures closes debut $125 million fund for Israeli defense tech
Protego Ventures, the first and largest dedicated defense tech VC in Israel, just completed its final $125 million closing, TechCrunch learned exclusively.
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
Humans are reviewing Copilot users’ bizarre and abusive image-editing requests
Copilot users asked for upskirt images and sexualized edits of people in uploaded photos. Human contractors were asked to judge the results.
Securing the keys to the kingdom: Announcing Executive Threat Detection
This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most…
Kiteworks Urges Customers to Restart Systems After Shutdown Notice
Kiteworks has lifted a temporary shutdown recommendation which was issued on the back of federal intelligence
IT Security News Hourly Summary 2026-09-29 12h : 9 posts
9 posts published in the last hour 09:32Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack 09:31Critical Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks 09:31Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first 09:31Critical WatchGuard API Vulnerabilities Enables…
Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack
Storm-3168 used compromised cloud identities to carry out a destructive attack against an Azure environment in minutes. The operation shows how a stolen…
Critical Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to fix a critical zero-day vulnerability that it says may have been exploited in an extremely…
Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first
Cloudflare released EmDash 1.0, a free, open source content management system that locks each sandboxed plugin in its own isolated runtime. A plugin…
Critical WatchGuard API Vulnerabilities Enables Command Execution Attacks
WatchGuard has disclosed three security vulnerabilities affecting WatchGuard AP devices, including two critical flaws that could allow attackers to gain…
Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Hackers stole patient data from Qbusoft, a Polish medical software maker, weeks after a breach at another provider exposed records of nearly 19 million…
BotHelper RAT Uses Encrypted Payloads and Live Screen Surveillance to Spy on Windows Users
A newly documented Windows remote access trojan, dubbed BotHelper RAT, gives attackers a quiet way to watch an infected user’s screen and control the…
CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
