SecurityWeek

Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities

Security Week - Tue, 06/02/2026 - 10:36am

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.

The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Anthropic Expanding Mythos Access to 150 New Organizations

Security Week - Tue, 06/02/2026 - 9:58am

Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.

The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first on SecurityWeek.

Categories: SecurityWeek

The Zero-Knowledge Threat Actor and the End of Responsible Disclosure

Security Week - Tue, 06/02/2026 - 8:30am

AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code.

The post The Zero-Knowledge Threat Actor and the End of Responsible Disclosure appeared first on SecurityWeek.

Categories: SecurityWeek

Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

Security Week - Tue, 06/02/2026 - 8:25am

A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device.

The post Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches appeared first on SecurityWeek.

Categories: SecurityWeek

Oracle WebLogic Vulnerability Exploited in the Wild

Security Week - Tue, 06/02/2026 - 7:39am

The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers.

The post Oracle WebLogic Vulnerability Exploited in the Wild appeared first on SecurityWeek.

Categories: SecurityWeek

Meta AI Hands Over High-Profile Instagram Accounts to Hackers

Security Week - Tue, 06/02/2026 - 6:48am

Exploiting a confused deputy weakness, the hackers simply asked the chatbot to link the account to a new email address.

The post Meta AI Hands Over High-Profile Instagram Accounts to Hackers appeared first on SecurityWeek.

Categories: SecurityWeek

Supply Chain Attack Hits 32 Red Hat NPM Packages

Security Week - Tue, 06/02/2026 - 5:51am

Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.

The post Supply Chain Attack Hits 32 Red Hat NPM Packages appeared first on SecurityWeek.

Categories: SecurityWeek

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Security Week - Tue, 06/02/2026 - 4:07am

Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts.

The post Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads appeared first on SecurityWeek.

Categories: SecurityWeek

Oracle’s First Monthly Patches Resolve 77 Vulnerabilities

Security Week - Tue, 06/02/2026 - 3:20am

Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster.

The post Oracle’s First Monthly Patches Resolve 77 Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites

Security Week - Mon, 06/01/2026 - 2:19pm

The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations.

The post WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites appeared first on SecurityWeek.

Categories: SecurityWeek

Dutch Police Dismantle Massive 17-Million-Device Botnet

Security Week - Mon, 06/01/2026 - 1:55pm

Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.

The post Dutch Police Dismantle Massive 17-Million-Device Botnet appeared first on SecurityWeek.

Categories: SecurityWeek

Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs

Security Week - Mon, 06/01/2026 - 11:02am

Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation.

The post Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

Categories: SecurityWeek

Dragos Acquires xIoT Security Firm Phosphorus

Security Week - Mon, 06/01/2026 - 8:46am

Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow.

The post Dragos Acquires xIoT Security Firm Phosphorus appeared first on SecurityWeek.

Categories: SecurityWeek

As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution

Security Week - Mon, 06/01/2026 - 7:48am

AI’s use in the military is part of the administration’s larger push to grow the capability it sees as a unique American advantage.

The post As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution appeared first on SecurityWeek.

Categories: SecurityWeek

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access

Security Week - Mon, 06/01/2026 - 7:19am

proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems.

The post 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access appeared first on SecurityWeek.

Categories: SecurityWeek

Recent Palo Alto Networks Vulnerability Exploited for Weeks

Security Week - Mon, 06/01/2026 - 6:00am

Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure.

The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on SecurityWeek.

Categories: SecurityWeek

Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say

Security Week - Sat, 05/30/2026 - 12:00pm

Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key infrastructure.

The post Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say appeared first on SecurityWeek.

Categories: SecurityWeek

Exploit Code Published for Critical Flowise RCE Vulnerability

Security Week - Sat, 05/30/2026 - 11:55am

The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow.

The post Exploit Code Published for Critical Flowise RCE Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks

Security Week - Fri, 05/29/2026 - 12:20pm

Noteworthy stories that might have slipped under the radar: Trump Mobile exposes customer data, phishers target the 2026 FIFA World Cup, CISA responds to recent supply chain attacks.

The post In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Charter Communications Data Breach Could Impact Nearly 5 Million

Security Week - Fri, 05/29/2026 - 10:49am

The notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April.

The post Charter Communications Data Breach Could Impact Nearly 5 Million appeared first on SecurityWeek.

Categories: SecurityWeek

Pages