Nebulock Raises $25 Million for AI-Native Contextual Security The cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics. The post Nebulock Raises $25 Million for AI-Native Contextual Security appeared first on SecurityWeek . SecurityWeek · Jun 26, 2026
vulnerability Linux Foundation Unveils New Open Source Security Project Akrites It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek . SecurityWeek · Jun 26, 2026 High
$3 Million Reportedly Stolen in Polymarket Hack The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek . SecurityWeek · Jun 26, 2026
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
vulnerability First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on Securi… SecurityWeek · Jun 26, 2026 High CVE-2026-12569CVE-2026-4681
threat-intel New Enterprise-Ready MCP Specification Brings New Security Challenges The Model Context Protocol (MCP) is evolving from a single-user AI tool to an enterprise-ready platform designed for cloud-native AI usage, with a major update slated for July 28, 2026. This transition introduces new sec… SecurityWeek · Jun 26, 2026 High aistatelesssecurity
Philip Martin Joins Uber as Chief Information Security Officer Martin brings experience from Coinbase, Palantir, Amazon, and the U.S. Army to lead Uber's cybersecurity and enterprise security organization. The post Philip Martin Joins Uber as Chief Information Security Officer appea… SecurityWeek · Jun 26, 2026
Runlayer Raises $30 Million in Series A Funding The startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises. The post Runlayer Raises $30 Million in Series A Funding appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026
Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Su… SecurityWeek · Jun 25, 2026
vulnerability Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warni… SecurityWeek · Jun 25, 2026 CVE-2025-67038
vulnerability GitLab Patches Code Execution, Information Disclosure Vulnerabilities The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High CVE-2026-10086CVE-2026-10712CVE-2026-12053
vulnerability 25-Year-Old Vulnerability Patched in Curl The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High CVE-2026-8932CVE-2026-8926CVE-2026-8925
SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition The 2026 Industrial Control Systems (ICS) Cybersecurity Conference takes place October 6-8, 2026, at the W Nashville. The post SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary… SecurityWeek · Jun 25, 2026
NIST Opens Updated IoT Security Guidance to Public Review The guidance aims to establish product cybersecurity requirements for IoT devices integrated into federal agencies’ networks. The post NIST Opens Updated IoT Security Guidance to Public Review appeared first on SecurityW… SecurityWeek · Jun 25, 2026
vulnerability Chrome 149 Update Resolves 18 Severe Vulnerabilities More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution. The post Chrome 149 Update Resolves 18 Severe Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High
vulnerability Cisco SD-WAN Zero-Day Exploited Months Before Patching CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWe… SecurityWeek · Jun 25, 2026 Critical CVE-2026-20245CVE-2026-20127CVE-2026-20182
threat-intel When Information Becomes the Attack Surface – Understanding AI Agent Traps This article discusses a new security risk related to AI agents – "traps" – where malicious information can be injected into the data sources an agent uses, leading it to make incorrect decisions or take unintended actio… SecurityWeek · Jun 24, 2026 High aiagentsecurity
malware Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware appeared first… SecurityWeek · Jun 24, 2026 High
threat-intel Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk This article discusses the limitations of current vulnerability triage methods (SBOMs, VEX, and CVSS) in addressing supply chain attacks, particularly in the context of increasingly complex AI-driven systems. The author,… SecurityWeek · Jun 24, 2026 High supply chainaiautonomous robots
vulnerability macOS Weaknesses Chained to Silently Disable Endpoint Security Agents A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities. The post macOS Weaknesses Chained to Silently Disable Endpoint Security Agents ap… SecurityWeek · Jun 24, 2026 CVE-2026-39118