Security Week
Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.
The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.
Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
Hackers recently obtained non-sensitive customer information and other documents from the company.
The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.
Assaf Keren Appointed New CISO of Meta
He replaces Guy Rosen, who announced his retirement from the company after 13 years.
The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.
New Check Point Zero-Day Vulnerability Exploited in the Wild
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.
The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers.
The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek.
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms.
The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek.
Palo Alto Networks to Acquire Observability Platform Provider Embrace
Acquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability.
The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek.
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.
The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek.
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge.
The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek.
StrongestLayer Raises $4.1 Million in Seed Funding Extension
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform.
The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek.
Vibe-Coded Apps Riddled With Exploitable Security Flaws
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues.
The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.
The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.
Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement.
The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek.
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.
The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.
The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek.
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
The admission comes days after Hugging Face disclosed an attack powered by autonomous AI agents.
The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek.
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks.
The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first on SecurityWeek.
Cisco Launches Low-Cost AI Models for Source Code Security
The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.
The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.
Empirical Security Raises $25 Million in Series A Funding
The startup will use the investment to accelerate the development of its threat prediction and discovery products.
The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek.
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville
The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity appeared first on SecurityWeek.
