FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
A new macOS infostealer tricks victims into revealing their system password and installs a persistent backdoor for future access.
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.
Researchers demonstrated that chain, plus six o...
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.
Sandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume.
Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CL...
Every patch is a confession.
The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is N-day exploitation...
The FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed.
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.
The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.
Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware Arctic Wolf Labs linked multiple June 2026 intrusions to active exploitation of CVE-2026-0257, an authentication bypass flaw in Palo Alto Networks’ GlobalProtect portal and gateway, with attackers using it as an initial access point t...
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.
That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026,...
From smart doorbells and singing toys to deepfakes and forensic digital twins, Forensics Europe Expo 2026 showed just how quickly digital evidence is evolving; read our full recap for key insights from this year’s event.
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.
The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek.
It’s a lot:
According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will supp...
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]
Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For...
Anubis menace Coca-Cola après une cyberattaque revendiquée contre Fairlife et fixe un ultimatum au 27 juillet.
Coinbase Cartel menace Caterpillar, expose une stratégie d’extorsion cyber publique et alerte sur des pirates qui usurpent le groupe pirate !
Several security issues were fixed in the Linux kernel.
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose se...
Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22, 2026,...