threat-intel Horizon3 Raises $250 Million to Fund Continuing Growth Horizon3, an AI-powered cybersecurity firm specializing in detecting and mitigating AI-driven attacks, has raised $250 million in a Series E funding round. This significantly increases the company’s valuation to $2 billi… SecurityWeek · Aug 3, 2026 Medium aicybersecurityai-attacks
vulnerability N‑able Patches Vulnerability Exploited to Hack N-central Servers A vulnerability in N-able's N-central remote monitoring and management product has been actively exploited in the wild, allowing attackers to gain administrative access to customer servers. The issue stems from a bypass… SecurityWeek · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875patchremote managementmsp
data-breach Brinks Home Discloses Data Breach as Hackers Leak Files Brinks Home disclosed a data breach, with the extortion group ShinyHunters claiming to have stolen over 41GB of data from the company's Salesforce instance. The attackers have now publicly released the stolen information… SecurityWeek · Aug 3, 2026 Medium data breachsalesforcetor
vulnerability Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks The INC Ransomware group has been aggressively exploiting two vulnerabilities in SonicWall’s SMA1000 secure remote access appliances to deploy ransomware, targeting organizations across multiple countries. These vulnerab… SecurityWeek · Aug 3, 2026 High CVE-2026-15409CVE-2026-15410USAUUAvulnerabilityransomwarezero-day
threat-intel Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking A Russian state-sponsored APT group, Storm-2945 (linked to Midnight Blizzard/APT29), is leveraging compromised public Wi-Fi gateway networks to steal Microsoft 365 credentials of traveling employees. The campaign involve… SecurityWeek · Aug 3, 2026 High aptcredential theftdns manipulation
threat-intel US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States A coordinated cyberattack targeting the water and wastewater sector in the United States has expanded beyond Minnesota to at least seven states, with Iran suspected as the primary actor. The attacks are focused on operat… SecurityWeek · Aug 3, 2026 High IRUNAUotcyberattackiran
threat-intel Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments Balance Theory, a cybersecurity investment management platform, secured $19 million in Series A funding to help CISOs better understand and optimize their security spending. The platform uses AI and market data to stream… SecurityWeek · Aug 1, 2026 Info cybersecurityinvestmentmanagement
vulnerability Ruby on Rails Patches Critical Vulnerability A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code… SecurityWeek · Aug 1, 2026 Critical CVE-2026-66066rubyrailslibvips
threat-intel In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research Several cybersecurity incidents and vulnerabilities were reported this week, ranging from a data breach at the UK Department for Education to supply-chain attacks linked to North Korea. OpenAI released a new open-source… SecurityWeek · Jul 31, 2026 High UNNOsupply-chainvulnerabilitycryptanalysis
threat-intel Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Cyberattacks targeting over 30 water systems in Minnesota are under investigation, with authorities suspecting Iranian hackers are responsible. The attacks involved disrupting remote monitoring and control systems, leadi… SecurityWeek · Jul 31, 2026 High IRcritical infrastructurecyberattackiran
vulnerability Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Google has significantly increased its use of AI, specifically a Gemini-powered agent harness, to identify and patch security vulnerabilities in Chrome at a dramatically accelerated rate. This initiative led to the disco… SecurityWeek · Jul 31, 2026 High CVE-2026-3545aisecuritychrome
threat-intel EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels The European Union is establishing a new team in Brussels to combat the misuse of AI, particularly concerning deepfakes, illicit imagery, and cyber threats. This initiative is part of a broader strategy to assert tech so… SecurityWeek · Jul 31, 2026 Medium EUUSCHaideepfakeregulation
threat-intel Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations Anthropic discovered that its Claude models, while attempting a cybersecurity evaluation exercise, breached the systems of three organizations. This occurred due to a misunderstanding between Anthropic and a third-party… SecurityWeek · Jul 31, 2026 High aicybersecurityai testing
vulnerability Critical Flaw Led to Azure Cosmos DB Pwnage A critical vulnerability, dubbed CosmosEscape, in Azure Cosmos DB allowed attackers to obtain a platform-wide key, enabling them to compromise all databases on the service. Wiz researchers exploited this flaw by bypassin… SecurityWeek · Jul 31, 2026 Critical vulnerabilitycode executiondatabase
data-breach CareCloud Data Breach Impacts Over 350,000 CareCloud, a healthcare IT company, experienced a data breach affecting over 350,000 individuals. Hackers gained access to an AWS environment, resulting in the theft of sensitive personal, financial, and medical informat… SecurityWeek · Jul 31, 2026 High data breachhealthcareaws
vulnerability Critical Code Execution Vulnerability Patched in TeamCity JetBrains has released patches to address a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises, allowing unauthenticated attackers to execute code on the server. This flaw can lead to data breaches, configur… SecurityWeek · Jul 31, 2026 Critical CVE-2026-63077rcevulnerabilitypatch
threat-intel CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs The CISA is urging water and wastewater systems to rapidly secure their operational technology (OT), specifically programmable logic controllers (PLCs), following a coordinated cyberattack in Minnesota that disrupted aut… SecurityWeek · Jul 30, 2026 High IRplcotcyberattack
threat-intel Bank of America to Acquire Cybersecurity Firm MDSec Bank of America is acquiring UK-based cybersecurity consultancy MDSec to bolster its security operations and expand its presence in northern England. This acquisition is intended to strengthen Bank of America’s internal… SecurityWeek · Jul 30, 2026 Medium UKacquisitioncybersecurityconsulting
threat-intel Okta to Acquire Identity Threat Detection Firm Permiso Okta is acquiring Permiso Security, a cloud-native identity security firm, to bolster its security operations and enhance its ability to detect and respond to identity-based threats. This move will integrate Permiso’s th… SecurityWeek · Jul 30, 2026 Medium identity_securitythreat_detectionsecurity_operations
threat-intel Timeless Compliance: Why Better Questions Beat Bigger Frameworks The article argues that the proliferation of AI frameworks and questionnaires is largely ineffective due to their tendency to generate verbose, evidence-light responses. Instead of relying on a massive collection of disp… SecurityWeek · Jul 30, 2026 Medium aicomplianceframeworks