Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
Category: securityweek
NightmareStresser DDoS Service Disrupted in International Operation
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
MIND Secures $72 Million for AI-Powered DLP
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.
Comp AI Raises $34 Million for AI-Native Compliance and Security
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure.
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by…
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.
CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
CISA Releases Guidance on Deploying Cyber Decoys
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.
First Agentic AI Data Breach Reported to Spanish Regulator
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for…
Virtual Event Today: Attack Surface Management Summit
Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding…
