Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform The new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion. The post Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform appeared first on SecurityWeek . SecurityWeek · May 27, 2026
phishing The Credential Crisis: How Stolen Credentials Defeat Modern Security As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response. The post The Credential Crisis: How Stolen Credentials Defeat… SecurityWeek · May 27, 2026 Medium
supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain
threat-intel GlassWorm Botnet Disrupted The GlassWorm botnet, a persistent threat targeting open-source software developers, has been disrupted by a coordinated effort between CrowdStrike, Google, and the Shadowserver Foundation. The botnet utilized a multi-la… SecurityWeek · May 27, 2026 High RUbotnetopen sourcedeveloper
apt LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors. The post LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers appeared first… SecurityWeek · May 27, 2026
threat-intel FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data The FBI has issued an alert regarding a new tactic employed by the Silent Ransom Group (SRG) involving physical intrusion to steal data from law firms and other organizations. SRG is impersonating IT support personnel,… SecurityWeek · May 27, 2026 High social engineeringremote accessusb drive
vulnerability CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert urging immediate patching of a zero-day vulnerability (CVE-2026-48172) in the LiteSpeed cPanel plugin. This flaw allows for privileg… SecurityWeek · May 27, 2026 Critical CVE-2026-48172UScpanelzero-dayprivilege escalation
vulnerability Anthropic Releases New Claude Sandbox, Security Guidance Plugin The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally. The post Anthropic Releases New Claude Sandbox, Security Guidance Plugin appeared fi… SecurityWeek · May 27, 2026
threat-intel AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security This article discusses AppOmni’s new Marlin AI platform, designed to autonomously investigate security issues within Software-as-a-Service (SaaS) applications. The platform leverages AI to analyze configurations across n… SecurityWeek · May 26, 2026 Medium saasaiconfiguration
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
data-breach 185,000 Likely Impacted by 7-Eleven Data Breach The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth. The post 185,000 Likely Impacted by 7-Eleven Data Breach appeared first on SecurityWeek . SecurityWeek · May 26, 2026 High
Anthropic Expands Claude’s Enterprise Security Reach With 28 New Integrations Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz. The post Anthropic Expands Claude’s Enterprise Security Reach With 28 New Integrations appe… SecurityWeek · May 26, 2026
vulnerability Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution. The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first… SecurityWeek · May 26, 2026 Critical CVE-2026-5426
Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts. The post Watch on Demand: Threat Detection & Incident Re… SecurityWeek · May 26, 2026
threat-intel Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images This article reports on the development of DockSec, an open-source tool designed to address the challenge of vulnerability detection in Docker images. The tool utilizes an LLM to correlate findings from multiple vulnerab… SecurityWeek · May 26, 2026 Medium dockervulnerabilityai
data-breach Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers. The post Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National R… SecurityWeek · May 26, 2026
Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors. The post Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands appeared fi… SecurityWeek · May 26, 2026
vulnerability Ghost CMS Vulnerability Exploited to Hack Over 700 Websites A previously disclosed SQL injection vulnerability (CVE-2026-26980) in the Ghost CMS has been actively exploited by multiple threat actors, leading to the compromise of over 700 websites. The attackers leveraged this vul… SecurityWeek · May 25, 2026 High CVE-2026-26980USGBsql injectionghost cmsvulnerability
data-breach Oncology Institute Discloses Data Breach The affected third-party vendor has not been named, but one possible candidate is TriZetto. The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek . SecurityWeek · May 25, 2026 High
data-breach 266,000 Affected by Data Breach at Radiology Associates of Richmond Threat actors stole files containing names and protected health information from the healthcare organization’s systems. The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on Secur… SecurityWeek · May 25, 2026 High