Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden.

The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions.

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.

A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.

The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round. 

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.

The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

IonQ’s new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction.

The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts.

Rogue AI attacks Rogue AI attacks

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.

WordPress vulnerability exploited WordPress vulnerability exploited

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

AI security OT AI security OT

Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.

Top Cybersecurity Headlines

Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons.

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

SecurityWeek’s 2026 Zero Trust Summit will deep-dive into the world of digital identity management and the role of zero-trust principles and associated technologies
[October 14, 2026 | Virtual]

Read More

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[Originally September 16, 2026]

Read More

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[Originally August 19, 2026]

Learn More

Vulnerabilities

Cybercrime

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.

Cloud Security

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.