Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 12 min ago

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

26 min 35 sec ago

The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.

The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek.

Categories: SecurityWeek

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

58 min ago

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek.

Categories: SecurityWeek

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

4 hours 48 min ago

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek.

Categories: SecurityWeek

Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

Mon, 09/14/2026 - 10:28am

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.

The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.

Categories: SecurityWeek

New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

Mon, 09/14/2026 - 9:31am

Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims.

The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.

Categories: SecurityWeek

Personal, Financial Info Exposed in Revolut Data Breach

Mon, 09/14/2026 - 9:03am

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.

Categories: SecurityWeek

The Race to Control AI and Protect What Makes Us Human

Mon, 09/14/2026 - 9:00am

As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity.

The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.

Categories: SecurityWeek

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Mon, 09/14/2026 - 7:51am

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.

Categories: SecurityWeek

CISOs Race to Control AI Agents Without Destroying Their Value

Mon, 09/14/2026 - 6:30am

Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm.

The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.

Categories: SecurityWeek

Telus Warns Customers of Account Breaches

Mon, 09/14/2026 - 5:56am

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.

Categories: SecurityWeek

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Mon, 09/14/2026 - 5:27am

The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.

The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek.

Categories: SecurityWeek

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

Mon, 09/14/2026 - 4:25am

The flaw allows attackers to send files and execute them without authorization through an active remote session.

The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Sun, 09/13/2026 - 9:27am

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet.

The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.

Categories: SecurityWeek

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Sat, 09/12/2026 - 7:10am

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.

Categories: SecurityWeek

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Fri, 09/11/2026 - 9:50pm

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.

The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.

Categories: SecurityWeek

Phishing Research Challenges Conventional Security Awareness Testing

Fri, 09/11/2026 - 1:23pm

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.

The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.

Categories: SecurityWeek

GitLab Vulnerability Exploited One Day After Disclosure

Fri, 09/11/2026 - 12:11pm

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Fri, 09/11/2026 - 10:19am

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.

Categories: SecurityWeek

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Fri, 09/11/2026 - 8:48am

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.

Categories: SecurityWeek

Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

Fri, 09/11/2026 - 7:29am

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek.

Categories: SecurityWeek

Pages