SecurityWeek
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.
In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion.
The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates.
The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek.
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility.
The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared first on SecurityWeek.
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution.
The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.
The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek.
Catch Raises $5 Million for AI Executive Assistant With Guardrails
Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access.
The post Catch Raises $5 Million for AI Executive Assistant With Guardrails appeared first on SecurityWeek.
VMware Workstation and Fusion Updates Patch Critical Vulnerability
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWeek.
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine.
The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek.
Nvidia Is Buying AI Platform Hugging Face for $13 Billion
The deal highlights Nvidia’s push to champion increasingly popular open-source AI models.
The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek.
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys.
The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.
The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.
HiddenLayer Raises $100 Million for AI Runtime Security
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents.
The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek.
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.
The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
153 Million Driver License Images Offered on Dark Web
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.
The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on SecurityWeek.
OpenLeash Adds a Human Check to Risky AI Agent Actions
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.
The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.
The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek.
