Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 1 hour 7 min ago

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

2 hours 17 min ago

The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.

The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  appeared first on SecurityWeek.

Categories: SecurityWeek

Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)

7 hours 21 min ago

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.

The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) appeared first on SecurityWeek.

Categories: SecurityWeek

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

8 hours 57 min ago

CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield.

The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek.

Categories: SecurityWeek

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

9 hours 8 min ago

Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.

The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.

Categories: SecurityWeek

311,000 Impacted by Brown Health Medical Group-MA Data Breach

10 hours 22 min ago

Hackers stole personal information, medical records, and financial information from the organization’s server.

The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.

Categories: SecurityWeek

Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data 

10 hours 46 min ago

The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.

The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data  appeared first on SecurityWeek.

Categories: SecurityWeek

AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations

11 hours 24 min ago

In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.

The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

12 hours 12 min ago

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.

The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

13 hours 46 sec ago

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.

The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.

Categories: SecurityWeek

Water Sector Cyberattacks Reportedly Hit at Least 12 States

14 hours 32 min ago

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.

The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.

Categories: SecurityWeek

Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

Tue, 08/04/2026 - 12:49pm

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.

The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek.

Categories: SecurityWeek

Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

Tue, 08/04/2026 - 12:15pm

Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use.

The post Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer appeared first on SecurityWeek.

Categories: SecurityWeek

Oligo Raises $60 Million for Runtime Security

Tue, 08/04/2026 - 11:00am

The company will use the investment to accelerate product innovation and expand go-to-market operations.

The post Oligo Raises $60 Million for Runtime Security appeared first on SecurityWeek.

Categories: SecurityWeek

CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

Tue, 08/04/2026 - 10:30am

Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night.

The post CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout appeared first on SecurityWeek.

Categories: SecurityWeek

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Tue, 08/04/2026 - 9:54am

Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud.

The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared first on SecurityWeek.

Categories: SecurityWeek

Zenity Raises $125 Million in Series C Funding

Tue, 08/04/2026 - 9:40am

The AI security company will invest in product innovation, global expansion, and customer experience.

The post Zenity Raises $125 Million in Series C Funding appeared first on SecurityWeek.

Categories: SecurityWeek

Obsidian Security Raises $85 Million at $1.1 Billion Valuation

Tue, 08/04/2026 - 8:00am

Obsidian Security has developed a platform for governing AI agents across third-party applications.

The post Obsidian Security Raises $85 Million at $1.1 Billion Valuation appeared first on SecurityWeek.

Categories: SecurityWeek

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

Tue, 08/04/2026 - 8:00am

Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.

The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek.

Categories: SecurityWeek

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

Tue, 08/04/2026 - 6:54am

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.

The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek.

Categories: SecurityWeek

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Tue, 08/04/2026 - 5:56am

Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.

The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Pages