The security defect allows remote attackers to bypass authentication through argument bearer manipulation.
Tag: securityweek
Malicious Virtualizor Update Served via BGP Hijacking
Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards
Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse.
OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
Chrome and Firefox Updates Patch Dozens of Vulnerabilities
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.
23-Year-Old Sality P2P Botnet Disrupted
The shutdown operation involved peer list manipulation and Sality payload URL takedown.
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.
Palo Alto Networks Acquires AI Agent Platform Console
The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation…
Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense
Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes.
Coast Guard Establishes Office of Maritime Cybersecurity Policy
The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities.
Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.
Hackers Start Exploiting Critical Langflow Vulnerability
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.
Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.
Ransomware Gang Claims Nutex Health Data Breach
The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.
9.5 Million Impacted by Aesto Health Data Breach
Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.
WatchGuard Patches Critical Vulnerabilities
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.
PaperCut Exploitation Escalates to Active Intrusions
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.
Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.
ServiceNow Patches 3 Critical Code Injection Vulnerabilities
Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.
