Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
Tag: securityweek
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base.
Microsoft Rolls Out 22 Fresh Security Patches
Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities.
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
Hackers Target Zimbra Servers in Active Exploitation Campaign
Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.
Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it.
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.
MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
Atalanta’s Argo product is now being used to prove the resilience of Viasat’s satellite communications network.
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities.
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.
Critical GitLab Flaw Exploited Shortly After Disclosure
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built,…
US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.
Prevalent AI Raises $22 Million to Expand Data Fabric Platform
AI-powered data fabric company Prevalent AI today announced raising $22 million in growth funding from Integrity Growth Partners (IGP). Founded in 2017 by…
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
