Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.
Category: securityweek
Ceva Logistics Operations Disrupted by Cyberattack
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution.
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
CISA has also published several advisories describing vulnerabilities in ICS and other OT products.
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
The security defects could be exploited for arbitrary code execution and denial-of-service.
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.
Corma Raises $60 Million for Defensive Cybersecurity AI Model
Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue.
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did.
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.
Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.