SecurityWeek
Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
Anthropic has been conducting tests to identify issues in how AI agents interact with each other.
The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek.
40,000 Impacted by SafePal Data Breach
Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.
The post 40,000 Impacted by SafePal Data Breach appeared first on SecurityWeek.
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.
The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.
In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption.
The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities appeared first on SecurityWeek.
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028.
The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.
1.6 Million Likely Impacted by RingCentral Data Breach
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.
The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek.
Over 1,000 Charities Hit by Beacon CRM Data Breach
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.
The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek.
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.
The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek.
Hackers Exploiting Unpatched GeoServer Zero-Day
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek.
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm.
The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek.
Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.
The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek.
Venture Firm Team8 Secures Additional $365 Million
The Israeli company has nearly $2 billion in total assets under management since 2014.
The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek.
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.
The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements.
The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek.
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
