Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 10 min 16 sec ago

Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants

Fri, 05/08/2026 - 7:46am

The hackers gained the ability to modify equipment operational parameters, creating a direct risk to the public water supply.

The post Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants appeared first on SecurityWeek.

Categories: SecurityWeek

AI Firm Braintrust Prompts API Key Rotation After Data Breach

Fri, 05/08/2026 - 7:14am

Hackers accessed one of the company’s AWS accounts and compromised AI provider secrets stored in Braintrust.

The post AI Firm Braintrust Prompts API Key Rotation After Data Breach appeared first on SecurityWeek.

Categories: SecurityWeek

Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom

Fri, 05/08/2026 - 6:43am

A system that thousands of schools and universities use went offline due to a cyberattack, creating chaos as students tried to study for finals.

The post Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom appeared first on SecurityWeek.

Categories: SecurityWeek

‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials

Fri, 05/08/2026 - 4:32am

The malware framework targets web applications and cloud environments, including AWS, Docker, Kubernetes, and more.

The post ‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials appeared first on SecurityWeek.

Categories: SecurityWeek

Ransomware Group Takes Credit for Trellix Hack

Fri, 05/08/2026 - 3:58am

RansomHouse has published several screenshots to demonstrate access to internal Trellix services.

The post Ransomware Group Takes Credit for Trellix Hack appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover

Fri, 05/08/2026 - 2:53am

Lax extension permissions and improper trust implementation allow attackers to inject prompts in the Claude Chrome extension.

The post Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover appeared first on SecurityWeek.

Categories: SecurityWeek

Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks

Fri, 05/08/2026 - 1:41am

CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.

The post Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Pages