Security Week
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.
The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.
The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek.
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.
Clover Health Investments Discloses Data Breach
Using social engineering, hackers compromised employee accounts with access to personal and health information.
The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.
Zimbra Update Patches Critical Vulnerabilities
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects.
The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek.
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others.
The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek.
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.
The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
New Index Tracks Material Breaches — And Refuses to Add Up the Losses
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.
The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
Ernst & Young Data Breach Affects Personal, Financial Information
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.
The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.
The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek.
Hugging Face Hacked in Autonomous AI Attack
Targeting production infrastructure, the attack compromised internal datasets and service credentials.
The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek.
Chrome 150 Update Patches Severe Memory Safety Bugs
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities.
The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek.
WP2Shell WordPress Vulnerabilities Exploited in the Wild
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.
The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.
The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek.
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up?
The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.
Beacon Security Raises $13 Million for Security Data Platform
The startup helps organizations detect, hunt, and protect their assets across environments at machine speed.
The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek.
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI.
The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek.
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
The company disconnected its systems on July 13 and is starting to gradually restore operations.
The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek.
