DigiCert, a global leader in intelligent trust, has announced a strategic distribution partnership with Ignition Technology to scale its presence across EMEA, accelerate market entry and expand partner-led growth. Through the partnership, Ignition will bring DigiCert ONE® to customers and partners…
1 in 4 businesses hit by cyber attacks through their supply chain in the last year
One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that…
New ClickLock Stealer locks your Mac until you hand over your password
A new macOS infostealer tricks victims into revealing their system password and installs a persistent backdoor for future access. This article has been indexed from Malwarebytes Read the original article: New ClickLock Stealer locks your Mac until you hand over…
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launches Critical Impact Awards…
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt,…
N-day is Becoming N-Hour. Patching Faster Won’t Save You.
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit,…
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is…
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls…
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering…
Don’t trust that “FBI agent” in your DMs
The FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who’ve already been scammed. This article has been indexed from Malwarebytes Read the original article: Don’t trust that “FBI agent” in your DMs
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
FBI Warns of Deepfake Videos Impersonating IC3 Leadership
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI Warns of Deepfake Videos Impersonating IC3 Leadership
MIT to Become Hotbed of AI Video Surveillance
It’s a lot: According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along…
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek. This article has…
Shufti simplifies cross-border compliance with the Glocal Platform
Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For…
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint…
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed…
Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers
Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability affects Gitea versions…
Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection
The Linux kernel project has released fixes for over 400 vulnerabilities within approximately 24 hours. These vulnerabilities span various areas, including networking, filesystems, memory management, Bluetooth, virtualization, drivers, and security components. This rapid wave of Common Vulnerabilities and Exposures (CVE)…
One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware. The exposed WebDAV server held more than 1,000 files, including phishing lures, shortcut files, droppers, testing notes, and tools used…
Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping
Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification quirk. The issue centers on FourToSixMapping, a RemoteIPType value that can cause public…
SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware
Attackers actively exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances to gain root access and deploy custom malware. In early July 2026, the cybersecurity firm Volexity was involved in investigating an intrusion related to the SonicWall…
SonicWall SMA zero-days were exploited weeks before disclosure
Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June…