threat-intel The MFA Identity Trap: When Authentication Creates a False Sense of Security Multi-factor authentication (MFA) is increasingly relied upon, but organizations are mistakenly assuming that successful MFA automatically verifies a user’s identity. Attackers are exploiting vulnerabilities in the proce… SecurityWeek · 4d ago High mfaidentity-proofingauthentication
vulnerability Chrome 152 Patches Over 300 Vulnerabilities Google released Chrome 152, addressing over 300 vulnerabilities, a significant portion of which were identified using internal AI. This update represents a substantial increase in patching activity for Chrome this year,… SecurityWeek · 4d ago High CVE-2026-79282chromevulnerabilitypatch
data-breach Sensitive Information Exposed in Nutex Health Data Breach Nutex Health, a healthcare management company, experienced a data breach resulting in the potential exposure of sensitive information, including patient data, employee details, and business records. The company is curren… SecurityWeek · 4d ago Medium data breachhealthcarepatient data
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa
threat-intel Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation The Linux Foundation will manage TRACE, a new open standard for verifying the behavior of AI agents and confidential workloads. Developed collaboratively by AMD, Intel, Microsoft, and the Technology Innovation Institute,… SecurityWeek · 4d ago Medium aiconfidential computingtrust
threat-intel Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails Alice, a cybersecurity firm specializing in AI safety, has raised $140 million to bolster its defenses against vulnerabilities and attacks targeting generative AI models. The company uses a decade-long database of harmfu… SecurityWeek · 5d ago Medium ISUNaicybersecurityprompt injection
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
threat-intel WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update WhatsApp has significantly boosted its account security by introducing multi-passkey support, upgrading two-step verification to stronger passwords, and providing caller information to combat scams. These changes aim to… SecurityWeek · 5d ago Medium passkeystwo-factorsecurity
threat-intel Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference SecurityWeek and MTSI are offering a hands-on training course, Cyber Attack Methods (CAM), as part of the 25th Anniversary Industrial Control Systems (ICS) Cybersecurity Conference. The course teaches participants to thi… SecurityWeek · 5d ago Medium cyber-physicalicscybersecurity
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel Silent Patches Don’t Stop Attackers—They Blind Defenders Broadcom’s new program offering early access to CVE-only patches for Spring Framework users is exacerbating the problem of silent patching. While Broadcom continues to issue CVEs, the program effectively provides pre-ale… SecurityWeek · 5d ago High silent patchingvulnerability disclosureai-driven vulnerability
supply-chain Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff Nine individuals, including employees from Nvidia and Super Micro, have been charged in Taiwan for illegally exporting high-end AI servers to China. These servers, containing banned ‘B300’ GPUs, were part of a scheme to… SecurityWeek · 5d ago High CHTAJAexport controlschinaai
vulnerability CISA Warns of Exploited Oracle WebLogic Vulnerability The CISA has issued a critical warning to federal agencies about a widely exploited vulnerability in Oracle WebLogic servers (CVE-2026-21962). This flaw allows attackers to execute code remotely without authentication, a… SecurityWeek · 5d ago Critical CVE-2026-21962CNoracleweblogicvulnerability
threat-intel ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited ReliaQuest was targeted by the ShinyHunters group through a sophisticated phishing campaign mimicking security employees to gain access to an Okta dashboard. While the attackers gained temporary view-only access, they we… SecurityWeek · 5d ago Medium phishingsocial engineeringokta
threat-intel Hired for One Job, Judged on Another: The CISO’s Real Problem CISOs often struggle to demonstrate their value to a board of directors, who tend to prioritize cost, growth, and customer trust over technical security achievements. Instead of focusing on preventing breaches (which is… SecurityWeek · 6d ago Medium cisosecurity-strategybusiness-alignment
data-breach Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts Dutch regulators have fined Uber nearly $1 billion for using automated software to suspend driver accounts without human review, violating EU data privacy regulations. This is the fourth time the authority has penalized… SecurityWeek · 6d ago Medium dataprivacygdprautomation
vulnerability 91 Vulnerabilities Patched in Spring Application Framework Broadcom released a massive update addressing 91 vulnerabilities within the Spring application framework. Many of these flaws, including a critical Remote Code Execution (RCE) vulnerability, could be exploited for variou… SecurityWeek · 6d ago High CVE-2026-59270CVE-2026-59285CVE-2026-59318springvulnerabilityrce
threat-intel Venezuelan Gets Record Federal Prison Term for ATM Jackpotting A Venezuelan national has been sentenced to a record 96 months in prison for his involvement in a sophisticated ATM jackpotting scheme, linked to the Venezuelan terrorist organization Tren de Aragua. The scheme resulted… SecurityWeek · 6d ago High VEatmjackpottingcybercrime
threat-intel Personal Information Exposed in Apollo Global Data Breach Apollo Global Management suffered a data breach due to a social engineering attack, exposing sensitive personal information like names, contact details, and Social Security numbers. The attack was attributed to the UNC66… SecurityWeek · 6d ago High vishingsocial engineeringdata breach
threat-intel Rethinking Application Security for the AI Era The speed at which attackers can now exploit vulnerabilities – thanks to advancements in AI – is dramatically increasing, shrinking the window from vulnerability disclosure to exploit from months to hours. This necessita… SecurityWeek · 6d ago High aivulnerabilitypatching