Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 8 min 19 sec ago

The Credential Crisis: How Stolen Credentials Defeat Modern Security

Wed, 05/27/2026 - 6:30am

As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response.

The post The Credential Crisis: How Stolen Credentials Defeat Modern Security appeared first on SecurityWeek.

Categories: SecurityWeek

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Wed, 05/27/2026 - 6:15am

Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying malicious code.

The post ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems appeared first on SecurityWeek.

Categories: SecurityWeek

GlassWorm Botnet Disrupted

Wed, 05/27/2026 - 6:10am

Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.

The post GlassWorm Botnet Disrupted appeared first on SecurityWeek.

Categories: SecurityWeek

LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers

Wed, 05/27/2026 - 5:33am

The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors.

The post LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers appeared first on SecurityWeek.

Categories: SecurityWeek

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

Wed, 05/27/2026 - 4:33am

The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms.

The post FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

Wed, 05/27/2026 - 2:55am

Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges.

The post CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day appeared first on SecurityWeek.

Categories: SecurityWeek

Anthropic Releases New Claude Sandbox, Security Guidance Plugin

Wed, 05/27/2026 - 2:43am

The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally.

The post Anthropic Releases New Claude Sandbox, Security Guidance Plugin appeared first on SecurityWeek.

Categories: SecurityWeek

AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security

Tue, 05/26/2026 - 10:00am

Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action.

The post AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security appeared first on SecurityWeek.

Categories: SecurityWeek

Iranian APT Targets Aviation, Software Companies With Updated Tools

Tue, 05/26/2026 - 9:26am

Nimbus Manticore has continued its operations during and after the US military campaign against Iran.

The post Iranian APT Targets Aviation, Software Companies With Updated Tools appeared first on SecurityWeek.

Categories: SecurityWeek

185,000 Likely Impacted by 7-Eleven Data Breach

Tue, 05/26/2026 - 7:59am

The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth.

The post 185,000 Likely Impacted by 7-Eleven Data Breach appeared first on SecurityWeek.

Categories: SecurityWeek

Anthropic Expands Claude’s Enterprise Security Governance With 28 New Integrations

Tue, 05/26/2026 - 7:44am

Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz.

The post Anthropic Expands Claude’s Enterprise Security Governance With 28 New Integrations appeared first on SecurityWeek.

Categories: SecurityWeek

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Tue, 05/26/2026 - 7:14am

Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution.

The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first on SecurityWeek.

Categories: SecurityWeek

Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available

Tue, 05/26/2026 - 7:00am

Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts.

The post Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available appeared first on SecurityWeek.

Categories: SecurityWeek

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images

Tue, 05/26/2026 - 6:45am

DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes.

The post Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images appeared first on SecurityWeek.

Categories: SecurityWeek

Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries

Tue, 05/26/2026 - 6:26am

Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers.

The post Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries appeared first on SecurityWeek.

Categories: SecurityWeek

Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands

Tue, 05/26/2026 - 5:47am

The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.

The post Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands appeared first on SecurityWeek.

Categories: SecurityWeek

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

Mon, 05/25/2026 - 9:27am

Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.

The post Ghost CMS Vulnerability Exploited to Hack Over 700 Websites appeared first on SecurityWeek.

Categories: SecurityWeek

Oncology Institute Discloses Data Breach

Mon, 05/25/2026 - 8:17am

The affected third-party vendor has not been named, but one possible candidate is TriZetto.

The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek.

Categories: SecurityWeek

266,000 Affected by Data Breach at Radiology Associates of Richmond

Mon, 05/25/2026 - 7:17am

Threat actors stole files containing names and protected health information from the healthcare organization’s systems.

The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on SecurityWeek.

Categories: SecurityWeek

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

Mon, 05/25/2026 - 6:58am

Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase. 

The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek.

Categories: SecurityWeek

Pages