Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 11 min 40 sec ago

7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand

Mon, 05/18/2026 - 7:25am

The hackers claimed to have stolen more than 600,000 Salesforce records, including personal information and corporate data. 

The post 7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand appeared first on SecurityWeek.

Categories: SecurityWeek

Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE

Mon, 05/18/2026 - 6:38am

The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug.

The post Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE appeared first on SecurityWeek.

Categories: SecurityWeek

First Shai-Hulud Worm Clones Emerge

Mon, 05/18/2026 - 5:45am

At least one threat actor has adopted the recently released malware source code in attacks against NPM developers.

The post First Shai-Hulud Worm Clones Emerge appeared first on SecurityWeek.

Categories: SecurityWeek

Grafana Confirms Breach After Hackers Claim They Stole Data

Mon, 05/18/2026 - 4:34am

Grafana appears to have been targeted by Coinbase Cartel, a cybercrime group linked to ShinyHunters, Scattered Spider, and Lapsus$.

The post Grafana Confirms Breach After Hackers Claim They Stole Data appeared first on SecurityWeek.

Categories: SecurityWeek

Exploitation of Critical NGINX Vulnerability Begins

Mon, 05/18/2026 - 3:27am

The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.

The post Exploitation of Critical NGINX Vulnerability Begins appeared first on SecurityWeek.

Categories: SecurityWeek

Hackers Earn $1.3 Million at Pwn2Own Berlin 2026 

Mon, 05/18/2026 - 12:05am

Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.

The post Hackers Earn $1.3 Million at Pwn2Own Berlin 2026  appeared first on SecurityWeek.

Categories: SecurityWeek

PoC Code Published for Critical NGINX Vulnerability

Sat, 05/16/2026 - 6:02am

Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.

The post PoC Code Published for Critical NGINX Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws

Fri, 05/15/2026 - 10:52am

Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks Canvas.

The post In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

Fri, 05/15/2026 - 8:06am

Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions.

The post Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild appeared first on SecurityWeek.

Categories: SecurityWeek

American Lending Center Data Breach Affects 123,000 Individuals

Fri, 05/15/2026 - 7:06am

The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.

The post American Lending Center Data Breach Affects 123,000 Individuals appeared first on SecurityWeek.

Categories: SecurityWeek

OpenAI Hit by TanStack Supply Chain Attack

Fri, 05/15/2026 - 6:37am

Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.

The post OpenAI Hit by TanStack Supply Chain Attack appeared first on SecurityWeek.

Categories: SecurityWeek

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code

Fri, 05/15/2026 - 5:47am

The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.

The post TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code appeared first on SecurityWeek.

Categories: SecurityWeek

Chrome 148 Update Patches Critical Vulnerabilities

Fri, 05/15/2026 - 3:25am

The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.

The post Chrome 148 Update Patches Critical Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026

Fri, 05/15/2026 - 2:28am

The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616.

The post Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 appeared first on SecurityWeek.

Categories: SecurityWeek

Enhancing Data Center Security Without Sacrificing Performance

Thu, 05/14/2026 - 10:00am

For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game.

The post Enhancing Data Center Security Without Sacrificing Performance appeared first on SecurityWeek.

Categories: SecurityWeek

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation

Thu, 05/14/2026 - 9:44am

The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.

The post New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation appeared first on SecurityWeek.

Categories: SecurityWeek

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere

Thu, 05/14/2026 - 9:00am

Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.

The post Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere appeared first on SecurityWeek.

Categories: SecurityWeek

Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million

Thu, 05/14/2026 - 8:55am

The acquisition enables Akamai to expand its Zero Trust portfolio to add protection directly into the browser.

The post Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million appeared first on SecurityWeek.

Categories: SecurityWeek

Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns

Thu, 05/14/2026 - 8:11am

Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.

The post Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns appeared first on SecurityWeek.

Categories: SecurityWeek

G7 Countries Release AI SBOM Guidance

Thu, 05/14/2026 - 7:15am

The goal of the guidance, which outlines minimum elements, is to help organizations enhance transparency in AI systems and supply chains. 

The post G7 Countries Release AI SBOM Guidance appeared first on SecurityWeek.

Categories: SecurityWeek

Pages