SecurityWeek

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Security Week - Mon, 09/28/2026 - 5:44am

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Security Week - Mon, 09/28/2026 - 3:29am

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Security Week - Sun, 09/27/2026 - 5:23am

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

Security Week - Sat, 09/26/2026 - 2:09pm

The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.

The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek.

Categories: SecurityWeek

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Security Week - Sat, 09/26/2026 - 8:00am

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.

The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.

Categories: SecurityWeek

OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

Security Week - Sat, 09/26/2026 - 6:15am

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Security Week - Fri, 09/25/2026 - 11:07am

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.

The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek.

Categories: SecurityWeek

North Korea Suspected in $351 Million Bitget Crypto Heist

Security Week - Fri, 09/25/2026 - 10:16am

Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen.

The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

Security Week - Fri, 09/25/2026 - 8:39am

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. 

The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Security Week - Fri, 09/25/2026 - 8:16am

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.

The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek.

Categories: SecurityWeek

Windows, Linux, Android File Notification Systems Leak User Activity

Security Week - Fri, 09/25/2026 - 6:53am

Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.

The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek.

Categories: SecurityWeek

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Security Week - Fri, 09/25/2026 - 5:27am

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek.

Categories: SecurityWeek

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Security Week - Fri, 09/25/2026 - 2:57am

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

Categories: SecurityWeek

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

Security Week - Thu, 09/24/2026 - 4:35pm

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden.

The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek.

Categories: SecurityWeek

Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

Security Week - Thu, 09/24/2026 - 11:52am

The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions.

The post Kontext Security Emerges With $4 Million for AI Agent Runtime Controls appeared first on SecurityWeek.

Categories: SecurityWeek

OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

Security Week - Thu, 09/24/2026 - 10:43am

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.

The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek.

Categories: SecurityWeek

AI-Powered Campaign Targets Hundreds of Online Retailers

Security Week - Thu, 09/24/2026 - 8:48am

A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.

The post AI-Powered Campaign Targets Hundreds of Online Retailers appeared first on SecurityWeek.

Categories: SecurityWeek

Island Raises $400 Million at $6.4 Billion Valuation

Security Week - Thu, 09/24/2026 - 7:39am

The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round. 

The post Island Raises $400 Million at $6.4 Billion Valuation appeared first on SecurityWeek.

Categories: SecurityWeek

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

Security Week - Thu, 09/24/2026 - 7:05am

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek.

Categories: SecurityWeek

Begin at the End: How to Enable Agentic Remediation

Security Week - Thu, 09/24/2026 - 7:00am

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.

The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek.

Categories: SecurityWeek

Pages