apt Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices NetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks. The post Google, FBI Disrupt NetNut Residential Proxy Network Powered by M… SecurityWeek · Jul 3, 2026
vulnerability Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lea… SecurityWeek · Jul 3, 2026 High CVE-2026-50548CVE-2026-50549
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
threat-intel How to Conduct a Successful Audit of AI-Driven Software Development This SecurityWeek article discusses the need for a new type of audit – an ‘agentic development lifecycle’ (ADLC) audit – to address the security risks introduced by AI-driven software development, particularly large lang… SecurityWeek · Jul 2, 2026 Medium aillmsoftware security
ransomware FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ran… SecurityWeek · Jul 2, 2026 High
Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm Anthropic said Tuesday night that its AI model called Claude Fable 5 is now widely available. The post Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm appeared first on Secu… SecurityWeek · Jul 2, 2026
vulnerability Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on Securi… SecurityWeek · Jul 2, 2026 Medium CVE-2026-20230
threat-intel ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials Researchers at LayerX discovered a vulnerability dubbed ‘BioShocking’ that exploits the tendency of AI browsers to prioritize game-like objectives over security protocols. The attack leverages a puzzle-solving scenario t… SecurityWeek · Jul 2, 2026 High aibrowsercredentials
vulnerability CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659). The post CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability appeared first on Se… SecurityWeek · Jul 2, 2026 Critical CVE-2026-45659
Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings Microsoft's new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive meetings. The post Microsoft Adds New Team… SecurityWeek · Jul 1, 2026
vulnerability Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution. The post Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities appeared first on SecurityWee… SecurityWeek · Jul 1, 2026 CVE-2026-48286CVE-2026-48276CVE-2026-48277
vulnerability Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The post Citrix Patches NetScaler Vulnerabiliti… SecurityWeek · Jul 1, 2026 High CVE-2026-8451CVE-2026-8452CVE-2026-8655
threat-intel Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors This article discusses the growing hype surrounding Frontier AI and the concerns of enterprises regarding its impact on security. It highlights the need for organizations to critically evaluate vendor claims related to F… SecurityWeek · Jul 1, 2026 Medium frontier aivendor evaluationhype
vulnerability Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and S… SecurityWeek · Jul 1, 2026
Dawnguard Raises $6.3 Million for Security Architecture Automation Platform The company has publicly launched its solution to help organizations design, build, and operate secure cloud systems. The post Dawnguard Raises $6.3 Million for Security Architecture Automation Platform appeared first on… SecurityWeek · Jul 1, 2026
threat-intel Massive Password Spray Campaign Targeting Azure CLI A massive password spray campaign targeting Microsoft 365 environments, specifically the Azure CLI, was observed by Huntress. The attacks, originating from AS32167 and linked to LSHIY LLC, resulted in the compromise of o… SecurityWeek · Jul 1, 2026 High CHHOUScredential spraymfaoauth ropc
vulnerability Google Patches 382 Chrome Vulnerabilities Fifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’. The post Google Patches 382 Chrome Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jul 1, 2026 High
ransomware BlueHammer Vulnerability Exploited in Ransomware Attacks The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 Critical CVE-2026-33825
threat-intel Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks A research report by Adversa AI has identified a significant security vulnerability in several popular open-source AI coding agents, dubbed ‘GuardFall’. This flaw stems from the agents’ reliance on Bash shell tricks, spe… SecurityWeek · Jun 30, 2026 High bashai agentssupply chain
data-breach Aflac Japan Data Breach Impacts 4.38 Million Hackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 High