As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application…
Category: securityweek
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch.
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.
500,000 Active Credentials Left Exposed on GitHub
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.
Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges.
Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.
FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment.
FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment.
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.
Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.
Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.
ShinyHunters Defiant After FBI Calls on Members to Come Forward
In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
The accord opened the door to future regulation but focused on four voluntary steps for the companies to take.
OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
Altman made a slew of product announcements and updates, including the company’s new agents, called Dots.
