SecurityWeek

Corma Raises $60 Million for Defensive Cybersecurity AI Model

Security Week - Tue, 08/11/2026 - 8:01am

Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue.

The post Corma Raises $60 Million for Defensive Cybersecurity AI Model appeared first on SecurityWeek.

Categories: SecurityWeek

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

Security Week - Tue, 08/11/2026 - 7:15am

The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.

The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek.

Categories: SecurityWeek

Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption

Security Week - Tue, 08/11/2026 - 6:00am

Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did.

The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek.

Categories: SecurityWeek

OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber

Security Week - Tue, 08/11/2026 - 5:45am

OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.

The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared first on SecurityWeek.

Categories: SecurityWeek

Mozilla Issues New Firefox GPG Key Following Exposure

Security Week - Tue, 08/11/2026 - 2:16am

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.

The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.

Categories: SecurityWeek

OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

Security Week - Mon, 08/10/2026 - 10:33am

The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. 

The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek.

Categories: SecurityWeek

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

Security Week - Mon, 08/10/2026 - 10:19am

The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure.

The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Security Week - Mon, 08/10/2026 - 10:07am

Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.

The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek.

Categories: SecurityWeek

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

Security Week - Mon, 08/10/2026 - 8:59am

An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.

The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek.

Categories: SecurityWeek

New Jersey, Alabama Join States Targeted in Water Cyberattacks

Security Week - Mon, 08/10/2026 - 7:44am

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.

The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek.

Categories: SecurityWeek

Metabase Patches Vulnerability Exploited as Zero-Day

Security Week - Mon, 08/10/2026 - 7:03am

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.

The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

Categories: SecurityWeek

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

Security Week - Mon, 08/10/2026 - 6:01am

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.

The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

Security Week - Mon, 08/10/2026 - 5:31am

The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.

The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Corporate Data Stolen in Levi Strauss Cyberattack

Security Week - Mon, 08/10/2026 - 4:55am

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.

The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.

Categories: SecurityWeek

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

Security Week - Mon, 08/10/2026 - 12:44am

The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies.

The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.

Categories: SecurityWeek

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

Security Week - Sat, 08/08/2026 - 7:30am

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.

The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Security Week - Fri, 08/07/2026 - 10:26am

Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.

The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek.

Categories: SecurityWeek

Vishing Extortion Group UNC6671 Rebrands After Making Millions

Security Week - Fri, 08/07/2026 - 7:06am

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.

Categories: SecurityWeek

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

Security Week - Fri, 08/07/2026 - 6:00am

NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.

The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.

Categories: SecurityWeek

Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)

Security Week - Fri, 08/07/2026 - 5:24am

Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.

The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek.

Categories: SecurityWeek

Pages