Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 14 min 33 sec ago

Cisco SD-WAN Zero-Day Exploited Months Before Patching

18 min 29 sec ago

CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching.

The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek.

Categories: SecurityWeek

When Information Becomes the Attack Surface – Understanding AI Agent Traps

Wed, 06/24/2026 - 1:37pm

From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI.

The post When Information Becomes the Attack Surface – Understanding AI Agent Traps appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware

Wed, 06/24/2026 - 11:02am

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

The post Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware appeared first on SecurityWeek.

Categories: SecurityWeek

Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk

Wed, 06/24/2026 - 10:30am

The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environments.

The post Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk appeared first on SecurityWeek.

Categories: SecurityWeek

macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

Wed, 06/24/2026 - 9:50am

A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities.

The post macOS Weaknesses Chained to Silently Disable Endpoint Security Agents appeared first on SecurityWeek.

Categories: SecurityWeek

Third DraftKings Hacker Sentenced to 18 Months in Prison

Wed, 06/24/2026 - 8:52am

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

The post Third DraftKings Hacker Sentenced to 18 Months in Prison appeared first on SecurityWeek.

Categories: SecurityWeek

Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs

Wed, 06/24/2026 - 8:32am

The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands.

The post Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs appeared first on SecurityWeek.

Categories: SecurityWeek

Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed

Wed, 06/24/2026 - 8:00am

Context is the central plank of AI in general, and agentic AI in particular. If an AI system doesn’t have the correct context, it cannot make the correct decisions.

The post Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed appeared first on SecurityWeek.

Categories: SecurityWeek

New ‘Mistic’ RAT Opens Door to Several Ransomware Families

Wed, 06/24/2026 - 7:42am

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

The post New ‘Mistic’ RAT Opens Door to Several Ransomware Families appeared first on SecurityWeek.

Categories: SecurityWeek

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking

Wed, 06/24/2026 - 6:55am

The security defects allow unauthenticated users to take control of the open source software supply chain.

The post Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking appeared first on SecurityWeek.

Categories: SecurityWeek

BeyondTrust, LastPass Impacted by Klue-Salesforce Incident

Wed, 06/24/2026 - 6:03am

Over a dozen Klue customers have confirmed that hackers stole data from their Salesforce instances.

The post BeyondTrust, LastPass Impacted by Klue-Salesforce Incident appeared first on SecurityWeek.

Categories: SecurityWeek

Webinar Today: Modern Exposure Validation in the AI Era

Wed, 06/24/2026 - 4:04am

The exploit timeline collapsed. Make sure your validation didn't.

The post Webinar Today: Modern Exposure Validation in the AI Era appeared first on SecurityWeek.

Categories: SecurityWeek

Hackers Exploiting Cisco Unified CM Vulnerability

Wed, 06/24/2026 - 1:44am

Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June.

The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says

Tue, 06/23/2026 - 11:29pm

Come vulnerabilities were found within hours, but that does not mean the model was able to exploit them within that time, the official said.

The post Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says appeared first on SecurityWeek.

Categories: SecurityWeek

Dragos Unveils AI for OT Security 

Tue, 06/23/2026 - 1:26pm

Named EmberAI, the new capability is built on Dragos’ massive operational technology cybersecurity dataset.

The post Dragos Unveils AI for OT Security  appeared first on SecurityWeek.

Categories: SecurityWeek

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Tue, 06/23/2026 - 11:36am

Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs.

The post Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps appeared first on SecurityWeek.

Categories: SecurityWeek

Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

Tue, 06/23/2026 - 9:00am

The high-severity use-after-free vulnerability in Samsung's KNOX security framework affected Android-powered Galaxy devices from the S9 through S25.

The post Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct

Tue, 06/23/2026 - 8:50am

Carl Froggett combines CISO and CIO. He currently occupies both positions at Deep Instinct. Before then, he was CISO at Citi for almost 17 years.

The post CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct appeared first on SecurityWeek.

Categories: SecurityWeek

Algerian Man Extradited to US for Running Cybercrime Marketplaces

Tue, 06/23/2026 - 8:06am

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

The post Algerian Man Extradited to US for Running Cybercrime Marketplaces appeared first on SecurityWeek.

Categories: SecurityWeek

FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances

Tue, 06/23/2026 - 7:48am

Attackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library.

The post FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances appeared first on SecurityWeek.

Categories: SecurityWeek

Pages