SecurityWeek
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek.
Malicious B-tree NPM Package Accumulates Millions of Downloads
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.
The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign.
The post Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme appeared first on SecurityWeek.
US Proposes AI Incident Alert System in Talks With China, Bessent Says
Trump has resisted calls to slow down AI development, saying that would help China catch up to U.S. companies.
The post US Proposes AI Incident Alert System in Talks With China, Bessent Says appeared first on SecurityWeek.
Google Hit With $463 Million Fine for EU Location Data Rule Breach
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data.
The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek.
Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek.
CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be.
The post CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast appeared first on SecurityWeek.
Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal
The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push.
The post Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal appeared first on SecurityWeek.
RatHat Android Trojan Uses AI for Automation
The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion.
The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek.
Rust Team Members and Popular Crate Owners Targeted via Video Calls
It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea.
The post Rust Team Members and Popular Crate Owners Targeted via Video Calls appeared first on SecurityWeek.
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek.
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
The post Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems appeared first on SecurityWeek.
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek.
Google Confirms Gemini AI Breached Three Firms
Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies.
The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek.
TigerByte Cyber Emerges From Stealth With $3 Million in Funding
The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA.
The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.
23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
