Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.

Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.

More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.

Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

The announcement comes after Trump hosted top executives of AI companies at the White House last week.

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority.

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws.

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account.

Cybersecurity bill passes Cybersecurity bill passes

More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.

Hacker arrested Hacker arrested

Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.

Citrix vulnerability Citrix vulnerability

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

Top Cybersecurity Headlines

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

Upcoming Cybersecurity Events

ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

SecurityWeek’s 2026 Zero Trust Summit will deep-dive into the world of digital identity management and the role of zero-trust principles and associated technologies
[October 14, 2026 | Virtual]

Read More
CISO Forum Virtual Summit 2026

The 2026 Virtual CISO Forum brings together CISOs, senior cybersecurity executives, practitioners, industry experts, and other security leaders to share practical experience and examine the issues shaping enterprise cybersecurity strategy.
[November 11, 2026]

Read More

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[Originally August 19, 2026]

Learn More

Vulnerabilities

Cybercrime

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.

Cloud Security

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.