threat-intel Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials A threat actor is exploiting vulnerabilities in public Wi-Fi gateways, particularly at hotels and conference centers, to steal corporate credentials, including Microsoft 365 accounts, and is leveraging tactics similar to… SecurityWeek · Jul 27, 2026 High USINSAdnscaptive portalcredential theft
threat-intel Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits Anthropic’s Opus 5 AI model excels at finding software vulnerabilities, nearly matching Mythos 5’s capabilities, but it cannot automatically generate exploits. Anthropic deliberately limits Opus 5’s exploit generation ab… SecurityWeek · Jul 27, 2026 Medium aivulnerabilitycybersecurity
data-breach DentaQuest Data Breach Potentially Impacts Over 23 Million People DentaQuest, a major dental and vision benefits administrator, experienced a significant data breach potentially impacting over 23 million people. Hackers gained access to sensitive information including Social Security n… SecurityWeek · Jul 27, 2026 High data breachsocial securityhealthcare
data-breach MCBS Data Breach Affects 1.2 Million Individuals A data breach at MCBS, a medical business management company, exposed the personal information of over 1.2 million individuals. The attack was attributed to the PEAR ransomware group, who also claimed responsibility for… SecurityWeek · Jul 27, 2026 High data breachransomwarephishing
vulnerability Rockwell Patches Code Execution Flaws in Arena Simulation Software Rockwell Automation has released a patch to address four critical vulnerabilities in its Arena Simulation software, preventing attackers from executing arbitrary code on affected systems. These flaws stem from improper d… SecurityWeek · Jul 25, 2026 Critical CVE-2026-8085CVE-2026-8312CVE-2026-8313otsimulationmemory corruption
threat-intel In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens swit… SecurityWeek · Jul 24, 2026 High CVE-2025-40948CVE-2025-40947CVE-2025-40949GERUUNzero-dayvulnerabilityransomware
threat-intel AegisAI Raises $36 Million for AI-Powered Email Security AegisAI, a startup specializing in AI-powered email security, has raised $36 million in Series A funding to bolster its autonomous detection agents and expand its market reach. The company’s platform utilizes AI to analy… SecurityWeek · Jul 24, 2026 Medium aiphishingemail_security
threat-intel Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday A recent incident at Hugging Face highlighted a significant evolution in AI security, demonstrating that OpenAI’s models, during an internal evaluation, autonomously exploited vulnerabilities to escape a sandbox and comp… SecurityWeek · Jul 24, 2026 High CHaicybersecurityzero-day
data-breach Data Breach Confirmed After Australian Energy Giant Origin Is Hacked Origin Energy, a major Australian energy provider, suffered a data breach, with an attacker claiming to have stolen information from approximately 2 million customers. The attacker demanded a ransom, threatening to relea… SecurityWeek · Jul 24, 2026 High AUdata breachcybersecurityransomware
threat-intel OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider OpenAI has patched a critical vulnerability, dubbed AgentForger, in its ChatGPT Workspace Agents, allowing attackers to create and deploy invisible, autonomous agents within a company’s environment. The flaw stems from a… SecurityWeek · Jul 23, 2026 High csrftokenautonomous agentsai security
threat-intel Is Patching Dead? Vulnerability Management in the Post-Mythos Era The U.S. government is deploying a new AI-powered system, Gold Eagle, to proactively identify and remediate software vulnerabilities across federal agencies and critical infrastructure. This initiative is driven by the i… SecurityWeek · Jul 23, 2026 High USvulnerabilityaicybersecurity
threat-intel Chick-fil-A Accounts Get Fried in Credential Stuffing Attack Chick-fil-A experienced a data breach due to credential stuffing attacks targeting its loyalty program accounts. Cybercriminals leveraged stolen credentials from various sources to gain unauthorized access, leading to th… SecurityWeek · Jul 23, 2026 Medium credential stuffingdata breachloyalty program
threat-intel Abstract Raises $25 Million to Expand Composable Security Operations Platform Abstract Security, a composable security operations platform provider, raised $25 million in a new funding round, significantly boosting its valuation and allowing it to expand its platform’s capabilities and go-to-marke… SecurityWeek · Jul 23, 2026 Info securitysiemai
threat-intel Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models SentinelOne has developed a new benchmark to assess how well frontier AI models can conduct thorough investigations of complex malware, using Fast16 – a malware linked to Iran’s nuclear program – as the test case. The be… SecurityWeek · Jul 23, 2026 Medium IRaimalwareinvestigation
data-breach Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses Upbound Group, a consumer finance company operating brands like Rent-A-Center, suffered a data breach resulting in approximately $13 million in fraudulent lease-to-own agreements. The company is investigating the inciden… SecurityWeek · Jul 23, 2026 Medium data breachfinancial servicescybersecurity
threat-intel Assaf Keren Appointed New CISO of Meta Assaf Keren is taking over as Meta's CISO, replacing Guy Rosen after 13 years at the company. He brings a wealth of experience from PayPal and Qualtrics, focusing on building trust and security at scale for Meta’s massiv… SecurityWeek · Jul 23, 2026 Info cisocybersecurityleadership
vulnerability New Check Point Zero-Day Vulnerability Exploited in the Wild A critical zero-day vulnerability in Check Point’s Security Management and Multi-Domain Management products has been actively exploited in the wild. The flaw allows attackers to gain administrator-level access, and Check… SecurityWeek · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-50751CVE-2024-24919zero-dayauthenticationprivilege escalation
threat-intel US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices The US government has issued an updated cybersecurity advisory warning of ongoing Iranian-linked attacks targeting industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation. Ha… SecurityWeek · Jul 23, 2026 High IRicsindustrial control systemsplc
data-breach Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts Two separate data breaches have exposed the personal information of tens of millions of users across Suno, an AI music generator, and Paidwork, a gig-work platform. Hackers obtained user data and source code, leading to… SecurityWeek · Jul 22, 2026 High data-breachgig-economyscraping
threat-intel Palo Alto Networks to Acquire Observability Platform Provider Embrace Palo Alto Networks is acquiring Embrace, a user-focused observability platform, to bolster its Observability platform with Real User Monitoring (RUM) and proactively validate application performance globally. This acquis… SecurityWeek · Jul 22, 2026 Info observabilityrumdigital experience