Security Week
Critical Flaw Led to Azure Cosmos DB Pwnage
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.
The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek.
CareCloud Data Breach Impacts Over 350,000
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.
The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek.
Critical Code Execution Vulnerability Patched in TeamCity
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.
The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek.
Bank of America to Acquire Cybersecurity Firm MDSec
The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom.
The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek.
Okta to Acquire Identity Threat Detection Firm Permiso
The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response.
The post Okta to Acquire Identity Threat Detection Firm Permiso appeared first on SecurityWeek.
Timeless Compliance: Why Better Questions Beat Bigger Frameworks
The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change.
The post Timeless Compliance: Why Better Questions Beat Bigger Frameworks appeared first on SecurityWeek.
DataBahn Raises $40 Million for Agentic Data Pipeline Management
The company will accelerate investments in R&D and product innovation to expand its agentic data control plane.
The post DataBahn Raises $40 Million for Agentic Data Pipeline Management appeared first on SecurityWeek.
Discern Security Raises $13 Million in Series A Funding
The company will invest in accelerating the development and adoption of its agentic platform.
The post Discern Security Raises $13 Million in Series A Funding appeared first on SecurityWeek.
Cantina Emerges From Stealth With $8 Million in Funding
The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities.
The post Cantina Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek.
Onyx Security Raises $113 Million to Control AI Agents in the Enterprise
The Series B funding round brings the total raised by Onyx Security to $153 million.
The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared first on SecurityWeek.
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains.
The post ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale appeared first on SecurityWeek.
Semiconductor Firm Analog Devices Discloses Data Breach
Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.
The post Semiconductor Firm Analog Devices Discloses Data Breach appeared first on SecurityWeek.
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.
The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms appeared first on SecurityWeek.
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities.
The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers appeared first on SecurityWeek.
US and Allies Update SBOM Guidance
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.
The post US and Allies Update SBOM Guidance appeared first on SecurityWeek.
Chrome 151 Patches 370 Vulnerabilities
The major browser update resolves roughly 80 critical- and high-severity security defects.
The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek.
Cisco Secure FMC Zero-Day Exploited in the Wild
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.
The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek.
US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
The agency said imports of advanced robots pose cybersecurity and other national security risks.
The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek.
Mate Security Raises $35 Million for Agentic SOC
The startup will use the investment to expand its customer support, sales, and R&D teams.
The post Mate Security Raises $35 Million for Agentic SOC appeared first on SecurityWeek.
