SecurityWeek
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.
Mindgard Raises $30 Million to Protect AI Systems
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.
The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek.
WhatsApp Unveils New Scam Alert Feature
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system.
The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek.
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.
The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek.
Ceva Logistics Operations Disrupted by Cyberattack
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.
The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek.
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution.
The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared first on SecurityWeek.
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek.
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.
The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek.
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek.
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
CISA has also published several advisories describing vulnerabilities in ICS and other OT products.
The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek.
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.
The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek.
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.
The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek.
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.
The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek.
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
The security defects could be exploited for arbitrary code execution and denial-of-service.
The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek.
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek.
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.
The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It appeared first on SecurityWeek.
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.
The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek.
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.
The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek.
