Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 51 min 59 sec ago

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

Tue, 07/21/2026 - 7:55am

Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.

The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.

Categories: SecurityWeek

CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG

Tue, 07/21/2026 - 7:30am

Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.

The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.

Categories: SecurityWeek

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Tue, 07/21/2026 - 7:12am

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek.

Categories: SecurityWeek

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Tue, 07/21/2026 - 6:19am

A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.

The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.

Categories: SecurityWeek

Clover Health Investments Discloses Data Breach

Tue, 07/21/2026 - 5:36am

Using social engineering, hackers compromised employee accounts with access to personal and health information.

The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.

Categories: SecurityWeek

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

Tue, 07/21/2026 - 4:41am

The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.

The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.

Categories: SecurityWeek

Zimbra Update Patches Critical Vulnerabilities

Tue, 07/21/2026 - 4:20am

The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects.

The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

Mon, 07/20/2026 - 10:54am

Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others.

The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek.

Categories: SecurityWeek

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Mon, 07/20/2026 - 10:11am

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.

The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.

Categories: SecurityWeek

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

Mon, 07/20/2026 - 8:32am

Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.

The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

New Index Tracks Material Breaches — And Refuses to Add Up the Losses

Mon, 07/20/2026 - 7:46am

Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.

The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.

Categories: SecurityWeek

Ernst & Young Data Breach Affects Personal, Financial Information

Mon, 07/20/2026 - 7:27am

Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.

The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.

Categories: SecurityWeek

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

Mon, 07/20/2026 - 6:25am

The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.

The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek.

Categories: SecurityWeek

Hugging Face Hacked in Autonomous AI Attack

Mon, 07/20/2026 - 5:36am

Targeting production infrastructure, the attack compromised internal datasets and service credentials.

The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek.

Categories: SecurityWeek

Chrome 150 Update Patches Severe Memory Safety Bugs

Mon, 07/20/2026 - 4:12am

The fresh security update resolves six critical and high-severity use-after-free vulnerabilities.

The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek.

Categories: SecurityWeek

WP2Shell WordPress Vulnerabilities Exploited in the Wild

Mon, 07/20/2026 - 1:21am

Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.

The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

Fri, 07/17/2026 - 10:27am

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.

The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek.

Categories: SecurityWeek

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

Fri, 07/17/2026 - 8:11am

(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up?

The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.

Categories: SecurityWeek

Beacon Security Raises $13 Million for Security Data Platform

Fri, 07/17/2026 - 7:43am

The startup helps organizations detect, hunt, and protect their assets across environments at machine speed.

The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek.

Categories: SecurityWeek

Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday

Fri, 07/17/2026 - 7:08am

Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI.

The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek.

Categories: SecurityWeek

Pages