A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local…
Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets
A new Shai-Hulud supply-chain attack dubbed Trinitite has compromised the npm package @7nohe/openapi-react-query-codegen, a TanStack Query code-generation…
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic…
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers,…
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final…
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.
AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S. retailer could be exploited to enable remote code…
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has…
Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming “Microsoft Defender…
IT Security News Hourly Summary 2026-08-31 12h : 6 posts
6 posts published in the last hour 09:31Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks 09:31Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ 09:31Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data…
Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks
Android 17 introduces a new set of network security controls to reduce cellular downgrade attacks, protect local networks, and limit metadata exposure…
Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’
The ruling is part of Anthropic’s legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year.
Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
A Magecart campaign dubbed HexMage has compromised more than 40 e-commerce storefronts across at least 15 countries, using Ethereum smart contracts as a…
Berlin Won’t Pay Extortion Group Claiming Data Theft
The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried…
IT Security News Hourly Summary 2026-08-31 11h : 12 posts
12 posts published in the last hour 08:31Hackers Use Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks 08:31Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files 08:31Debian developers rejected an LLM ban and left disclosure voluntary…
Hackers Use Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks
Hackers are using a fake Cloudflare CAPTCHA to turn a routine web check into a doorway into corporate networks. The campaign, called TerminalFix, begins…
Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files
A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised package to alter…
Debian developers rejected an LLM ban and left disclosure voluntary
A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through…
Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure
A malware investigation has exposed the tools and infrastructure used by suspected operators behind a Blind Eagle-linked campaign targeting Colombia and…
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker…
Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks
A router configuration change is gaining attention as a way to add defense against phishing and malware. Cybersecurity commentator Luis Catacora urged…
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical…
Critical Microsoft Flaw Lets Hackers Remotely Control Android Devices Without a Login
A critical vulnerability in Microsoft’s open-source UFO automation framework, tracked as CVE-2026-73296 with a CVSS score of 9.4, could allow remote…