vulnerability CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities The CISA has issued a warning about three actively exploited vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities – CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486 – ar… SecurityWeek · Aug 5, 2026 High CVE-2026-9198CVE-2026-18556CVE-2026-18577CHcvepatchremote code execution
supply-chain Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account an… SecurityWeek · Aug 5, 2026 High supply chainnpmgithub
threat-intel Water Sector Cyberattacks Reportedly Hit at Least 12 States A growing number of US states, including Minnesota, Michigan, and Georgia, are experiencing cyberattacks targeting water and wastewater facilities. The FBI has linked these attacks to Iran, specifically targeting interne… SecurityWeek · Aug 5, 2026 High IRicsiotcyberattack
threat-intel Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) This document summarizes key vendor announcements from the 2026 Black Hat conference, focusing on advancements in cybersecurity products and services. Several companies are leveraging AI to enhance their security offerin… SecurityWeek · Aug 4, 2026 High aivulnerability remediationthreat hunting
threat-intel Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Traditional security tools like CASB and DLP aren't sufficient for addressing the unique risks posed by AI. The core issue is that AI risk isn't about simply blocking access to AI tools; it's about analyzing the *content… SecurityWeek · Aug 4, 2026 High UNaiprompt injectiondata leakage
threat-intel Oligo Raises $60 Million for Runtime Security Oligo Security, a runtime security company, secured $60 million in a new funding round, bringing their total investment to $140 million. The company’s platform focuses on providing deep runtime visibility and real-time p… SecurityWeek · Aug 4, 2026 Medium ISruntime securityvulnerabilityai
threat-intel CISO Conversation: Russ Kirby – Passion Is the Antidote to Burnout Russ Kirby, a CISO with extensive experience at companies like Ping Identity, Creditsafe, and ForgeRock, attributes his success and longevity in cybersecurity to a deep passion for the field and a proactive approach to c… SecurityWeek · Aug 4, 2026 High cisoburnoutai
threat-intel Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Attackers are leveraging compromised email accounts and their built-in AI assistants to bypass security measures and conduct sophisticated phishing attacks against executives. By using the AI assistant to gather informat… SecurityWeek · Aug 4, 2026 High phishingaiemail
threat-intel Zenity Raises $125 Million in Series C Funding Zenity, an AI security company, secured $125 million in Series C funding to bolster its efforts in securing AI agentic frameworks and expanding its global presence. This investment reflects the growing need for specializ… SecurityWeek · Aug 4, 2026 Medium ISUSaisecurityagentic ai
threat-intel Obsidian Security Raises $85 Million at $1.1 Billion Valuation Obsidian Security, a company specializing in AI agent security governance, has raised $85 million in a Series D funding round, valuing the company at $1.1 billion. The investment will fuel their expansion into governing… SecurityWeek · Aug 4, 2026 Medium aiagentic-aigovernance
vulnerability TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Researchers at Forescout discovered 15 vulnerabilities in TP-Link’s Omada networking ecosystem’s zero-touch provisioning (ZTP) system, allowing attackers to potentially take over entire networks by chaining together thes… SecurityWeek · Aug 4, 2026 High CVE-2025-7850CVE-2025-7851ztpnetworkvulnerability
vulnerability Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering A vulnerability in Google’s Agent Development Kit (ADK) for Python allowed an attacker to manipulate low-privileged agents to gain access to high-privilege capabilities, potentially leading to pull request poisoning and… SecurityWeek · Aug 4, 2026 High agent-to-agentpull request poisoningremote code execution
vulnerability Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks A 22-year-old vulnerability in BMC management processors is exposing thousands of data centers to attack. The flaw allows attackers to retrieve password hashes and crack them offline, potentially gaining unauthorized acc… SecurityWeek · Aug 4, 2026 High CVE-2013-4786bmcipmipassword cracking
data-breach 150,000 Impacted by Madera Community Hospital Data Breach Madera Community Hospital in California experienced a data breach affecting over 150,000 individuals, exposing sensitive personal and financial information. The attackers initially demanded a ransom, which they subsequen… SecurityWeek · Aug 4, 2026 High USdata breachhealthcarecybersecurity
threat-intel Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Microsoft significantly increased its bug bounty payouts, reaching over $20 million in the past year and rewarding 562 researchers across 64 countries. The company’s programs saw a substantial rise in submissions, partly… SecurityWeek · Aug 4, 2026 Medium bug bountyvulnerabilityresearch
threat-intel New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems New York is investing $9 million to bolster cybersecurity at 153 water and wastewater systems, following a coordinated cyberattack targeting over 30 community water systems in Minnesota and subsequent incidents in at lea… SecurityWeek · Aug 4, 2026 Medium IRSOUNcyberattackindustrial control systemswater infrastructure
Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) Several cybersecurity vendors are showcasing new AI-focused security solutions at Black Hat 2026. These include tools for detecting and blocking rogue AI agents, managing AI risk across the application lifecycle, and aut… SecurityWeek · Aug 3, 2026
threat-intel Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 billion Visa is acquiring BioCatch, a behavioral biometrics firm, for $2.4 billion to bolster its fraud detection and cybersecurity capabilities. This move reflects a growing trend among major payment companies investing heavily… SecurityWeek · Aug 3, 2026 Medium biometricsfraudcybersecurity
threat-intel Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations A cyberattack compromised the Liechtenstein Register of People Behind Companies and Foundations, exposing data of approximately 31,000 individuals. The breach was discovered during a routine check and prompted a governme… SecurityWeek · Aug 3, 2026 High LIdata-breachmoney launderingfinancial crime
ransomware River Bank Says Hackers Deleted Data Stolen in Ransomware Attack River Bank & Trust suffered a ransomware attack that resulted in stolen data, which the company subsequently worked to have deleted through a possible ransom payment. The company is still investigating the full scope of… SecurityWeek · Aug 3, 2026 Medium ransomwaredata breachfinancial services