The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried…
IT Security News Hourly Summary 2026-08-31 11h : 12 posts
12 posts published in the last hour 08:31Hackers Use Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks 08:31Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files 08:31Debian developers rejected an LLM ban and left disclosure voluntary…
Hackers Use Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks
Hackers are using a fake Cloudflare CAPTCHA to turn a routine web check into a doorway into corporate networks. The campaign, called TerminalFix, begins…
Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files
A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised package to alter…
Debian developers rejected an LLM ban and left disclosure voluntary
A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through…
Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure
A malware investigation has exposed the tools and infrastructure used by suspected operators behind a Blind Eagle-linked campaign targeting Colombia and…
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker…
Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks
A router configuration change is gaining attention as a way to add defense against phishing and malware. Cybersecurity commentator Luis Catacora urged…
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical…
Critical Microsoft Flaw Lets Hackers Remotely Control Android Devices Without a Login
A critical vulnerability in Microsoft’s open-source UFO automation framework, tracked as CVE-2026-73296 with a CVSS score of 9.4, could allow remote…
New Gryxa Toolkit Uses AI-Built Persistence to Fight Back Against Security Teams
A financially motivated threat actor using a new Windows toolkit named Gryxa that combines remote monitoring and management abuse, AI-assisted…
Praetorian – Offensive Security Tools Built Around Portable Go Workflows
Praetorian’s Go security tools consolidate established offensive workflows, with portable binaries, direct pipelines and a partial shared SDK.
Small businesses and cyberattacks: why phishing is still the threat to watch
Small businesses and cyberattacks are often discussed as if they belong to separate worlds. E3nterprise organizations are seen as high-value targets,…
IT Security News Hourly Summary 2026-08-31 10h : 8 posts
8 posts published in the last hour 07:31A week in security (August 24 – August 30) 07:31The OpenClaw 2.0 release moves your sessions into SQLite 07:31ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach 07:31ChatGPT Conversations Are Being Used as Court…
A week in security (August 24 – August 30)
A list of topics we covered in the week of August 24 to August 30 of 2026
The OpenClaw 2.0 release moves your sessions into SQLite
OpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor…
ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach
ServiceNow warns of three maximum severity security vulnerabilities PaperCut zero-day exploited in attacks Healthcare giant McKesson discloses breach Get…
ChatGPT Conversations Are Being Used as Court Evidence With No Legal Privilege Protecting Them
It has become more and more common for people to have private conversations with AI chatbots such as ChatGPT, and such conversations do not benefit from…
TerminalFix: Fake Cloudflare CAPTCHA Campaign Deploys Reverse-Tunnel Backdoor
Security researchers at Microsoft have uncovered a sophisticated social engineering campaign called TerminalFix. A new type of ClickFix…
More Details Emerge on Exploited PaperCut Vulnerabilities
PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578.
Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files
Composer users are urged to update their software following the disclosure of a path-traversal vulnerability. This flaw could allow a malicious or…
IT Security News Hourly Summary 2026-08-31 09h : 5 posts
5 posts published in the last hour 06:31Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication 06:31What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 06:31TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to…
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
A critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via…