Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges.

The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.

An FTC spokesperson confirmed the investigation but declined further comment.

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.

Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.

The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

Gemini Gemini

The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.

Citrix vulnerability Citrix vulnerability

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

AI code of conduct AI code of conduct

Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.

Top Cybersecurity Headlines

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take.

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

Upcoming Cybersecurity Events

ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

SecurityWeek’s 2026 Zero Trust Summit will deep-dive into the world of digital identity management and the role of zero-trust principles and associated technologies
[October 14, 2026 | Virtual]

Read More
CISO Forum Virtual Summit 2026

The 2026 Virtual CISO Forum brings together CISOs, senior cybersecurity executives, practitioners, industry experts, and other security leaders to share practical experience and examine the issues shaping enterprise cybersecurity strategy.
[November 11, 2026]

Read More

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[Originally August 19, 2026]

Learn More

Vulnerabilities

Cybercrime

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.

Cloud Security

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.