CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
Category: securityweek
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
When Android users get a call from a non-contact, they will see more information about the caller, including their country.
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.
First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
Silent Patches Don’t Stop Attackers – They Blind Defenders
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.
CISA Warns of Exploited Oracle WebLogic Vulnerability
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard.
Hired for One Job, Judged on Another: The CISO’s Real Problem
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job.
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation.
91 Vulnerabilities Patched in Spring Application Framework
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.
Venezuelan Gets Record Federal Prison Term for ATM Jackpotting
Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses.
Personal Information Exposed in Apollo Global Data Breach
The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.
Rethinking Application Security for the AI Era
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company,…
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the…
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
Former NSA Director Paul Nakasone Launches National Security Advisory Firm
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity,…
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST…
