WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has…
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,…
Hackers stole millions of US military personnel records during months-long data breach
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long…
Huawei Smartphone Chip Narrows Performance Gap
Latest flagship Kirin 9050 Pro chip uses architectural changes to boost performance despite manufacturing constraints, says Bernstein
Certainties in life: Death, taxes, and critical Citrix vulns under attack
Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage
Another Microsoft SharePoint flaw now exploited Details and doubts emerge regarding OpenAI hack of Australian Health portal Kiteworks urges customers to…
IT Security News Hourly Summary 2026-09-30 22h : 11 posts
11 posts published in the last hour 19:02Medela – 423,947 breached accounts 19:02PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries 19:02When Productivity Extensions Become Attack Platforms 19:02AI Coding Agents Leak 13,000+ Internal Screenshots From…
Medela – 423,947 breached accounts
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters “pay or leak” extortion campaign . The data allegedly obtained in…
PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries
PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single…
When Productivity Extensions Become Attack Platforms
Our research uncovered a campaign of 32 malicious browser extensions that uses remote configs to spy on 9,800+ users and hijack browsing activity.
AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub
AI coding agents exposed more than 13,000 internal screenshots from over 300 organizations by publishing them in publicly accessible GitHub repositories,…
The Silent Container Death: A TCP Dial That Never Times Out
A pod goes into CrashLoopBackOff . You pull the logs expecting a stack trace, a panic, an error string – anything that points you somewhere. Instead, you…
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The…
Local Residents Protest Massive North Devon Data Centre
Hundreds turn out to protest Xlinks plan to convert 850 acres of farmland in North Devon into AI data centre and energy storage campus
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and…
OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought
Amid allegations that agents may have gone off the rails thousands of times, China set up some kind of agentic incident hotline
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary…
IT Security News Hourly Summary 2026-09-30 21h : 10 posts
10 posts published in the last hour 18:31Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster 18:31Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux 18:31Google Warns of Hackers Actively Exploiting Citrix 0-Day…
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern…
Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux
Google released a Chrome Stable update fixing 32 security vulnerabilities across Windows, macOS, and Linux, including one critical and multiple…
Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells
Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy…
Ping Command Options & Syntax: Network Admin Guide
By HOC Team | Updated: September 2026 Read time: ~15 min The ping command is the undisputed…
Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations. The campaign…
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
It’s 2 am. Do you know what your teen is doing?
