threat-intel Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software Neo, a cybersecurity startup led by former SentinelOne executives, has raised $100 million to provide enterprises with a control layer for AI software, addressing the growing concern of AI agents embedded in various appl… SecurityWeek · Jul 20, 2026 Medium aiagenticcybersecurity
threat-intel SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch SonicWall appliances were targeted by threat actors exploiting two unpatched zero-days for weeks before a fix was released. The attackers, tracked as UTA0533, deployed custom malware – KnuckleBall, OrangeTail, and Suo5 –… SecurityWeek · Jul 20, 2026 High CVE-2026-15409CVE-2026-15410zero-dayexploitmalware
vulnerability OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability A denial-of-service vulnerability, dubbed ‘HollowByte,’ in OpenSSL allows attackers to exhaust server memory by crafting a small payload that triggers excessive buffer allocations. This can lead to complete system lockup… SecurityWeek · Jul 20, 2026 High denial-of-servicebuffer overflowmemory exhaustion
threat-intel New Index Tracks Material Breaches — And Refuses to Add Up the Losses Richard Bird, a former cybersecurity executive, has launched The Hacker in a Hoodie (HIH) Index, a project tracking disclosed material cyber incidents. The index compiles data from SEC filings and news reports, grading t… SecurityWeek · Jul 20, 2026 Medium cybersecuritydata breachloss reporting
data-breach Ernst & Young Data Breach Affects Personal, Financial Information Ernst & Young (EY) experienced a data breach affecting the personal and financial information of its clients due to a vulnerability in a third-party service management platform. The breach, discovered in April, exposed s… SecurityWeek · Jul 20, 2026 High data breachtaxsocial security
threat-intel Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool Capital One has released its internally developed AI-powered security tool, ‘VulnHunter,’ as open source to address the issue of overwhelming vulnerability scans and improve software supply chain security. The tool proac… SecurityWeek · Jul 20, 2026 Medium vulnerabilityaiopen source
threat-intel Hugging Face Hacked in Autonomous AI Attack Hugging Face, a popular AI collaboration platform, suffered a data breach orchestrated by an autonomous AI agent. The attackers exploited vulnerabilities within their data processing pipeline to gain unauthorized access… SecurityWeek · Jul 20, 2026 High aiautonomousattack
vulnerability Chrome 150 Update Patches Severe Memory Safety Bugs Google released Chrome 150 to address seven memory safety vulnerabilities, including critical use-after-free flaws within components like CameraCapture and GPU. While no exploits have been reported, Google urges users to… SecurityWeek · Jul 20, 2026 High memory-safetyvulnerabilitychrome
threat-intel WP2Shell WordPress Vulnerabilities Exploited in the Wild Two recently patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. Attackers are leveraging these flaws to gain remote code execution on WordPress site… SecurityWeek · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
threat-intel In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,… SecurityWeek · Jul 17, 2026 High NEBEGEcyberattackransomwaredata breach
threat-intel Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive This SecurityWeek podcast explores the evolving challenges of cybersecurity governance, particularly highlighting the increasing role of AI agents in incident response. The discussion centers around a new open-source AI… SecurityWeek · Jul 17, 2026 Medium aicybersecurityincident response
threat-intel Beacon Security Raises $13 Million for Security Data Platform Beacon Security, a cybersecurity startup founded by IDF veterans, has secured $13 million in seed funding to bolster its security data platform. The platform aims to provide context and visibility for AI-powered security… SecurityWeek · Jul 17, 2026 Info aisecuritydata
threat-intel Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday The Department of War has temporarily paused the mandatory third-party assessment requirement for CMMC Phase 2, citing concerns about the capacity of the assessor ecosystem and the potential for CMMC to price small and m… SecurityWeek · Jul 17, 2026 High cmmccybersecuritycompliance
threat-intel Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei A cyberattack disrupted operations at Nichirei, a major Japanese frozen food producer, impacting its logistics, warehousing, and shipping services. The company disconnected systems as a precaution, and is investigating a… SecurityWeek · Jul 17, 2026 Medium JPcyberattackdata-breachransomware
supply-chain Risk Ledger Raises $32 Million in Series B Funding Risk Ledger, a UK-based supply chain security firm, secured $32.3 million in Series B funding to expand its network and enhance its AI-powered risk intelligence platform. This investment will allow them to grow their use… SecurityWeek · Jul 17, 2026 Info GBsupply chaincybersecurityrisk management
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
threat-intel Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack Coca-Cola has temporarily halted Fairlife production in the US due to a ransomware attack that compromised production systems. The company is investigating the scope of the incident and working with cybersecurity experts… SecurityWeek · Jul 17, 2026 Medium ransomwarecyberattackproduction
threat-intel Legacy Systems, Real-World Impacts: The Reality of OT Security This article highlights the unique challenges of securing Operational Technology (OT) systems compared to traditional IT environments. Unlike IT, OT vulnerabilities often lead to devastating real-world consequences – lik… SecurityWeek · Jul 16, 2026 High otcybersecurityvulnerability
threat-intel Two Scattered Spider Hackers Sentenced to Jail in UK Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, were sentenced to prison in the UK for their role in a 2024 attack on Transport for London, resulting in significant financial losses.… SecurityWeek · Jul 16, 2026 High UKUSEScybercrimeukscattered spider
threat-intel AI Data Centers Are Being Built Faster Than They Can Be Secured A Lava Labs report highlights significant security risks associated with the rapid growth of AI data centers, arguing that these new facilities are being built without adequately addressing the unique vulnerabilities ste… SecurityWeek · Jul 16, 2026 High aidata centersecurity