SecurityWeek
341 articles in the TruthFoundry index. Each links out to the original.
- Rockwell Automation Patches Dozen Vulnerabilities in Industrial Products · Rockwell Automation released patches for over a dozen vulnerabilities across its industrial automation product line.
- Cleo Harmony Vulnerability Patched After Exploit Released · Security researchers urge immediate patching of Cleo Harmony after an authentication bypass exploit was released.
- Anthropic Details Security Breaches, Unveils Enterprise Safeguards · Anthropic addresses unauthorized access incidents and launches new enterprise privacy and monitoring tools.
- Softaculous Suffers BGP Hijack Leading to Malicious Update Delivery · Softaculous users received malicious Virtualizor updates after a BGP hijack diverted traffic to attacker servers.
- OpenAI's Astra Model Crosses Critical Cybersecurity Threshold · OpenAI's new Astra model is the first to reach the 'Critical' cybersecurity capability level, requiring additional safeguards before release.
- Chrome and Firefox Patch Dozens of Critical and High-Severity Vulnerabilities · Google and Mozilla released updates for Chrome and Firefox to fix dozens of security flaws.
- 23-Year-Old Sality P2P Botnet Disrupted by International Law Enforcement · International law enforcement and CrowdStrike disrupted the 23-year-old Sality P2P botnet.
- SonicWall Warns of Two Exploited Zero-Days in SMA1000 Appliances · SonicWall urges patching of two zero-day vulnerabilities exploited in attacks on SMA1000 appliances.
- Palo Alto Networks Acquires AI Agent Platform Console · Palo Alto Networks acquires AI agent platform Console and reports 34% revenue growth in Q4 fiscal 2026.
- Sevii Deploys AI Defense Module to Counter AI-Driven Cyber Attacks · Sevii launches an AI security module to autonomously detect and remediate AI-driven cyber attacks in real-time.
- US Coast Guard Establishes Office of Maritime Cybersecurity Policy · The US Coast Guard created a new office to centralize maritime cybersecurity policy and compliance.
- Researchers Use AI to Port PLC Exploit, Risking Device Bricking · Forescout researchers used Anthropic's Claude to port a PLC exploit, costing hundreds of dollars and risking hardware damage.
- Hackers Exploit Critical Langflow RCE Vulnerability for Reconnaissance · Threat actors are actively exploiting a critical remote code execution flaw in the AI platform Langflow.
- Five Venezuelans Plead Guilty to ATM Jackpotting Attempts in Kansas · Five Venezuelan nationals pleaded guilty to ATM jackpotting charges in Kansas after failed malware attempts.
- Ransomware Gang Claims Data Breach at Healthcare Firm Nutex Health · The Gentlemen ransomware group claims responsibility for a data breach at Nutex Health, threatening to leak stolen data.
- Critical JFrog Artifactory Vulnerability Exploited in the Wild · Security firm WatchTowr reports active exploitation of a critical JFrog Artifactory authentication bypass vulnerability.
- Aesto Health Data Breach Exposes 9.5 Million Patients · Aesto Health reports a breach affecting over 9.5 million individuals via stolen PII and PHI.
- WatchGuard Patches Critical RCE Vulnerabilities in Fireware OS and Dimension · WatchGuard released patches for five critical vulnerabilities enabling remote code execution and account takeover.
- PaperCut Print Management Vulnerabilities Escalate to Active Intrusions · Threat actors are actively exploiting two PaperCut NG/MF vulnerabilities to gain remote code execution.
- Nightmare Eclipse Releases HardBreacher Exploit for Kaspersky Endpoint Security · Security researcher Nightmare Eclipse released a proof-of-concept exploit targeting Kaspersky Endpoint Security.
- ServiceNow Patches Critical AI Platform Code Injection Flaws · ServiceNow releases patches for four vulnerabilities, including three critical code injection flaws in its AI platform.
- McKesson Confirms Data Breach as ShinyHunters Deadline Looms · McKesson Corporation confirmed a data breach affecting oncology and medical-surgical units as extortion group ShinyHunters threatens to release stolen data.
- AI Agents Breached Hugging Face in 4 Days; Security Gaps Identified · AI agents breached Hugging Face's production environment, taking 17,600 actions in four days, exposing identity, response, and escalation gaps.
- Anthropic Warns Users of Infostealer Malware Hijacking Claude Sessions · Anthropic detected infostealer malware hijacking user sessions and refunded unauthorized charges.
- Hackers Exploit Critical Ruby on Rails RCE Vulnerability CVE-2026-66066 · VulnCheck warns that hackers are actively exploiting critical Ruby on Rails vulnerability CVE-2026-66066, leading to remote code execution.
- Boston Scientific Recovers Partially After Disruptive Cyberattack · Boston Scientific continues recovery efforts following a cyberattack that disrupted global manufacturing and shipping operations.
- Extortion Group FulcrumSec Claims Responsibility for MAG Data Breach · FulcrumSec extortion group claims responsibility for a data breach at Manchester Airports Group affecting millions of customers.
- Berlin Refuses to Pay Ransom for Massive Data Breach · Berlin authorities confirmed they will not pay the ransom demanded by the Rhysida ransomware group following a major data theft.
- PaperCut Releases Second Patch for Exploited Zero-Day Vulnerabilities · PaperCut issues emergency patch for two zero-day flaws exploited in remote code execution attacks.
- Hasbro Data Breach Exposes Employee Personal Information · Hasbro notifies employees that names, addresses, and financial data may have been exposed in a security incident.