News Archive
1929 stories · page 28 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Intezer Introduces Native Automation for Security Response Workflows
Intezer has launched Workflows, a new feature allowing security teams to build and customize automated response actions directly within its platform. This integration aims to streamline incident response by eliminating the need for a separate SOAR system, enabling faster post-investigation actions where alerts are already being triaged and analyzed.

Oracle Critical Patch Update, August 2026 Security Update Review
Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle

Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a major cyberattack that exposed data belonging to over 1.2 million citizens and 200,000 entities. The breach, which involved payment receipt data dating back to 2008, has led to calls for resignations from senior officials, including the CSDD chief. The incident has raised national security concerns and prompted investigations by cybersecurity authorities and state police.

Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek.

Comcast gives its Wi-Fi motion detector a security makeover
Rebranded feature promises household alerts without video, but mind the small print

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a

US charges Iranians for sprawling hacking campaign on government agencies, universities
The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.

Prevalent AI Raises $22 Million to Expand Data Fabric Platform
The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek.

Rapid7 and Licencias OnLine Partner for Latin American Cybersecurity
Rapid7 has announced a new strategic distribution partnership with Licencias OnLine (LOL) to enhance cybersecurity maturity for organizations across Latin America. This collaboration aims to help businesses manage the complexities introduced by cloud, AI, and digital transformation by providing unified security operations, continuous exposure management, and threat detection capabilities. The partnership leverages LOL's established presence and expertise in the region to support partners in delivering greater value and strengthening cyber resilience.

OpenAI Tightens AI Safeguards Following Hugging Face Incident
OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers have detailed a campaign, dubbed Operation CameraSwarm, that compromised over 14,500 Dahua devices between June and July 2026. The attackers utilized credential stuffing, two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique to gain access. The compromised devices were primarily located in Ukraine and Russia, and users are advised to update firmware and disable P2P services where unnecessary.

US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek.

Phishing 3.0: The Fight Moves to Agent Versus Agent
The cybersecurity landscape is evolving with the advent of "Phishing 3.0," where attackers are increasingly using AI-powered agents to conduct sophisticated, multi-channel attacks. These agents automate reconnaissance and personalize lures, moving beyond simple malicious content to exploit trust through social engineering, deepfakes, and impersonation across email, voice, and video. Traditional defenses are struggling to keep pace, necessitating a shift towards proactive, agent-assisted security measures for defenders.

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

Microsoft fixes known issue causing Windows Defender crashes
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appeared first on SecurityWeek.

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

Scammers are using fake crypto AML checkers to drain your wallet
We found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers.

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter

ICE Collecting DNA Samples
ICE collected nearly a million DNA samples last year.

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.

Critical Chrome Update Fixes Two Buffer Overflow Vulnerabilities
Google has released an update for Chrome's desktop versions, addressing 15 security flaws. Two of these are critical buffer overflow vulnerabilities, one in WebGL (CVE-2026-76034) and another in the Dawn library used for WebGPU (CVE-2026-76036). These issues could allow remote attackers to execute arbitrary code. Users are urged to update to version 151.0.7922.169/.170 to protect themselves.

Medusa ransomware gang has hit over 500 organizations, CISA warns
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026. “Medusa developers and affiliates have impacted over 500 victims from a va

Critical RCE flaw in Windows IKE Extension now actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]