Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
Tag: securityweek
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.
CISA Warns of Exploited Oracle WebLogic Vulnerability
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard.
Hired for One Job, Judged on Another: The CISO’s Real Problem
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job.
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation.
91 Vulnerabilities Patched in Spring Application Framework
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.
Venezuelan Gets Record Federal Prison Term for ATM Jackpotting
Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses.
Personal Information Exposed in Apollo Global Data Breach
The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.
Rethinking Application Security for the AI Era
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company,…
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the…
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
Former NSA Director Paul Nakasone Launches National Security Advisory Firm
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity,…
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST…
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution…
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions…
Microsoft Patches Exploited Entra ID Vulnerability
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
Critical Isolated-vm Vulnerability Leads to RCE on Host
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
