For you Ai Security Dev Cloud Hardware Startups Releases General

From SecurityWeek · 40 stories

5 sources 9 reports 66d ago

Coca-Cola's Fairlife Hits U.S. Production Halt Due to Anubis Ransomware Attack

A ransomware attack by the Anubis group has forced Coca-Cola's Fairlife to suspend U.S. production. Hackers claim they extracted 1 TB of data, threatening to release it unless a ransom is paid. The incident raises concerns about cybersecurity in the food and beverage sector.

security coca-cola fairlife ransomware food industry
5 sources 6 reports 71d ago

Hacker Reveals AI Music Generator Suno Breached, Exposing Data Practices

A hacker breached AI music generator Suno, revealing it had scraped millions of songs from platforms like YouTube and Deezer for its training datasets. Exposed user data from over 55 million accounts highlights serious privacy and copyright violation concerns. This incident raises questions about the legality of Suno's dataset usage amidst ongoing lawsuits.

security ai music data breach copyright
5 sources 5 reports 85d ago

Critical KVM/x86 Vulnerability Allows VM Escape to Host on Intel and AMD

Januscape, a 16-year-old use-after-free vulnerability (CVE-2026-53359) in Linux's KVM hypervisor, allows guest VMs to execute arbitrary code on host systems, compromising host security in multi-tenant environments. Discovered by Hyunwoo Kim, this first-known architecture-independent exploit has been demonstrated in Google's kvmCTF. Cloud providers like Google Cloud and AWS may be particularly vulnerable, posing risks of data breaches.

security kvm vulnerabilities cloud linux
5 sources 6 reports 86d ago

19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks

Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.

security cybercrime hacking law enforcement scattered spider
3 sources 18 reports 2d ago

Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security

Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.

security chrome vulnerabilities google browser
4 sources 5 reports 5d ago

US Proposes AI Incident Alert System to China Ahead of Trump-Xi Talks

The U.S. proposed a notification mechanism for AI incidents with national security implications during discussions with China. This initiative aims to increase transparency between the two leading AI powers and sets a precedent for international cooperation on AI risks.

ai policy international relations us-china national security
4 sources 19 reports 6d ago

Critical RCE Flaw in Forminator WordPress Plugin Affects 600,000+ Sites

A critical security vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, leading to remote code execution and site compromise. The flaw, rated 9.8 on CVSS, affects over 600,000 active installations and requires specific form configurations for exploitation, but has been patched in version 1.56.2.

security wordpress vulnerability rce elementor
1 source 1 report 19h ago Updated 19h ago

Zero Trust Creator Affirms Model's Effectiveness Against AI-Assisted Attacks in New Book

John Kindervag, creator of the Zero Trust model, released a new book asserting that Zero Trust principles remain effective against AI-assisted cyber threats. The book, co-authored with various experts, concludes that AI threats are fundamentally similar to past threats, only faster and more sophisticated, and Zero Trust can mitigate them if correctly implemented.

security zero trust ai cybersecurity
4 sources 4 reports 9d ago

Microsoft and Partners Dismantle EvilTokens AI Cybercrime Platform, Two Arrested

Microsoft, in collaboration with partners including Health-ISAC, Cloudflare, and OpenAI, has taken down EvilTokens, an AI-powered cybercrime platform. The platform, which offered AI tools for account compromise and financial fraud, led to the arrest of two men, aged 32 and 38, in the UK by the Metropolitan Police Service.

security ai cybercrime law enforcement phishing
4 sources 4 reports 14d ago

Microsoft sets new Patch Tuesday record with over 650 security fixes for Windows

Microsoft released over 650 security fixes for Windows in its September Patch Tuesday, setting a new record. This increase in patched vulnerabilities is attributed to new AI models, like Anthropic's Mythos and OpenAI's cybersecurity model, which are discovering software flaws at a rapid pace.

security microsoft patch tuesday ai vulnerabilities
4 sources 5 reports 14d ago

Revolut confirms customer data breach via fraudulent government agency requests

Revolut disclosed that an unauthorized third party obtained sensitive customer data by submitting fraudulent requests from a legitimate government agency email domain. The exposed information includes identity details, contact information, and potentially verification selfies, account statements, and transaction histories for a limited number of customers. This incident highlights vulnerabilities in data access protocols, even when dealing with seemingly legitimate government communications.

security data breach fintech revolut cybersecurity
4 sources 6 reports 20d ago

Trezor Discloses ShipMonk Breach Exposed Data of 67,000 U.S. Customers

Hardware wallet manufacturer Trezor announced that 67,000 U.S. customers had their personal data exposed due to a breach at its shipping provider, ShipMonk. This incident is significant because it adds to previously disclosed exposures and highlights the risks associated with third-party data handling, even after assurances of data deletion.

security data breach cryptocurrency privacy supply chain security
4 sources 11 reports 21d ago

PaperCut warns of active exploitation of zero-day vulnerability in NG and MF software

PaperCut issued an urgent security advisory regarding a zero-day vulnerability in all versions of its PaperCut NG and PaperCut MF print management software, which is actively being exploited in attacks. The company released emergency patches and advised organizations to restrict access to web interfaces of Internet-exposed servers, as this vulnerability poses a significant risk to affected systems.

security vulnerability zeroday papercut patch
4 sources 18 reports 22d ago

Craneware Reports Data Breach Affecting US Hospitals and Pharmacies

Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.

security data breach healthcare cybersecurity Craneware
4 sources 7 reports 24d ago

Two Berlin State Ministries Disconnected from Government Network Following Security Breach

Two Berlin state ministries, responsible for urban development and mobility, have been isolated from the city government's IT network due to a security breach. This incident has disrupted internal communications and some public services, highlighting vulnerabilities in government IT infrastructure.

security government breach germany cybersecurity
4 sources 4 reports 29d ago

Hackers deliver malicious Virtualizor update via BGP hijacking

Hackers used BGP hijacking to redirect traffic for Virtualizor's update infrastructure, delivering malicious updates to a small number of installations. Softaculous, the vendor, released a new Virtualizor version and advised users to check for a malicious service and reset credentials.

security bgp virtualizor softaculous supply chain
4 sources 4 reports 30d ago

Sality P2P Botnet Dismantled After 23 Years of Operation

The Sality peer-to-peer (P2P) botnet, active since 2003, has been disrupted through an international law enforcement effort involving the U.S. Department of Justice, Europol, Eurojust, and private partners like CrowdStrike and the Shadowserver Foundation. The operation, which took place on August 31, 2026, included a P2P sinkhole and domain seizures, effectively neutralizing a long-standing threat that infected over 15,000 devices and distributed various malware, including the EggJagger clipjacking tool.

security botnet malware cybercrime cybersecurity
4 sources 5 reports 32d ago

Boston Scientific reports cyberattack disrupting global operations and order processing

Medical technology company Boston Scientific experienced a cyberattack on August 25 that disrupted its IT systems, causing a network outage and affecting its ability to process and ship customer orders globally. The incident impacts a major medical device manufacturer, potentially affecting the supply chain for critical medical equipment worldwide.

security cybersecurity data breach medical devices supply chain
4 sources 4 reports 34d ago

ATF confirms "major incident" after Qilin ransomware group claims breach

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a "major incident" involving a breach of one of its standalone systems, following claims by the Qilin ransomware group. The agency stated that its main enterprise network, eForms system, and other ATF systems were not affected, and operations remain uninterrupted.

security ransomware government breach cybersecurity
4 sources 4 reports 41d ago

Grok AI Vulnerable to Data Exfiltration via Encrypted Malicious Instructions

Researchers discovered a new prompt injection attack against Grok that uses encrypted malicious instructions to bypass guardrails and exfiltrate user data. This method exploits the LLM's inability to distinguish between trusted user input and harmful content, allowing it to steal chat data and personal information.

security ai vulnerability llm grok
4 sources 5 reports 45d ago

Ransom Cartel Creator Sentenced to 16 Years for Ransomware-as-a-Service Operation

Maksim Silnikau, the 40-year-old Belarusian creator and administrator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison in Virginia. Silnikau developed the ransomware and recruited affiliates to attack at least 18 companies globally between 2021 and 2023, providing them with tools and infrastructure for intrusions and ransom negotiations.

security ransomware cybercrime sentencing doj
4 sources 4 reports 45d ago

SafePal data breach exposes order information for 39,798 customers

Cryptocurrency hardware wallet provider SafePal reported a data breach affecting approximately 39,798 customers, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. A threat actor is now claiming to sell this stolen data on a cybercrime forum. This breach could lead to targeted phishing and social engineering attacks against affected customers.

security data breach cryptocurrency hardware wallet
4 sources 6 reports 46d ago

New 'ShieldBreak' Zero-Day Exploit Bypasses Microsoft Defender Patch, Grants SYSTEM Privileges

Security researcher Nightmare Eclipse released "ShieldBreak," a new zero-day exploit for Microsoft Defender that bypasses a previous patch for the RoguePlanet vulnerability (CVE-2026-50656). This exploit allows SYSTEM privileges on fully updated Windows 10, Windows 11, and Windows Server systems, highlighting an incomplete patch for a privilege escalation flaw.

security vulnerability microsoft defender zero-day windows
4 sources 4 reports 51d ago

Mozilla Replaces GPG Signing Key for Firefox and Thunderbird After Accidental Exposure

Mozilla has replaced the GPG signing subkey used for Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files. The previous key was inadvertently committed in an unencrypted copy to a private GitHub repository. This change primarily affects users who manually verify GPG signatures or use Firefox RPM packages on older Linux distributions, who will need to import the new key and the old key's revocation.

security mozilla firefox thunderbird gpg
4 sources 4 reports 55d ago

UNC6671 Extortion Group Rebrands and Continues Vishing Attacks on Financial Firms

The UNC6671 extortion group has rebranded its operations under new names including Redact, Pink, Helix, and Falcon, despite an alleged retirement of its previous BlackFile brand. The group continues to use voice phishing (vishing) to target enterprise employees, particularly in financial services, private equity, and professional services, leading to data theft from cloud environments like Microsoft 365 and Okta.

security vishing extortion cloud cybersecurity
4 sources 4 reports 55d ago

Apple Implements Bug Report Caps Due to Surge in AI-Generated Submissions

Apple has introduced a cap on open security reports and a 30-day cool-off period for submissions to its bug bounty program, effective June. This change was made in response to a significant increase in AI-assisted reports, many of which were not genuine vulnerabilities, leading to review teams being overwhelmed. The new policy impacted Italian cybersecurity company Bynario, which used GPT-5.5 to find a critical macOS bug (CVE-2026-43760) but was initially unable to report it due to reaching the submission limit.

security apple ai vulnerability bug bounty
4 sources 4 reports 57d ago

Over 24,000 Internet-Exposed Servers Leak BMC Password Hashes via Decades-Old Flaw

More than 24,000 internet-exposed servers are leaking authentication password hashes due to CVE-2013-4786, a 20-year-old vulnerability in the Intelligent Platform Management Interface (IPMI) v2.0 specification. This flaw allows remote attackers to obtain password hashes before login and conduct offline password guessing attacks, potentially leading to full control over physical servers and broader management plane compromise.

security vulnerability bmc ipmi datacenter
4 sources 6 reports 59d ago

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.

security phishing dns microsoft365 wi-fi
4 sources 5 reports 66d ago

Origin Energy Confirms Customer Data Breach Affecting Personal and Partial Banking Details

Origin Energy confirmed a data breach affecting its 4.8 million customer accounts, compromising personal details and partial banking information. This incident exposes customers to potential identity theft and phishing, highlighting ongoing cybersecurity risks for critical service providers.

security data breach cybersecurity australia origin energy
4 sources 4 reports 70d ago

Symlink Vulnerability in AI Coding Assistants Poses Security Threat

Researchers discovered that a vulnerability in six AI coding assistants allows malicious repositories to execute code on developers' machines. By exploiting symbolic link (symlink) flaws, attackers could bypass user consent and access sensitive files, raising significant security concerns.

security ai dev coding vulnerability
4 sources 4 reports 71d ago

Adobe Acrobat Integration in WhatsApp Web Exposes User Data Through Chrome Extension Vulnerability

Adobe Acrobat tools are now available within WhatsApp Web and Windows app, allowing users to handle PDFs easily. However, a critical vulnerability in the Adobe Acrobat Chrome extension, affecting 329 million users, could enable unauthorized access to WhatsApp Web chats. The flaw has been patched, ensuring data security moving forward.

security whatsapp adobe acrfat pdf
4 sources 5 reports 73d ago

Researcher Releases Windows Zero-Day Exploit 'LegacyHive' Post-Patch Tuesday

Security researcher Chaotic Eclipse released a zero-day exploit for Windows shortly after Microsoft's Patch Tuesday. The exploit, called LegacyHive, targets the Windows User Profile Service and allows privilege escalation on all supported Windows versions. This revelation underscores ongoing security challenges and may necessitate urgent updates from Microsoft.

security windows vulnerabilities exploit vulnerability
4 sources 4 reports 78d ago

US Charges Russians for Operating 'Bulletproof' Hosting Services Linked to $62M in Cybercrime Losses

U.S. prosecutors have unsealed charges against three Russian nationals linked to bulletproof hosting providers Media Land and ML.Cloud. The Russians allegedly supported ransomware attacks through these services, causing over $62 million in damages. A $10 million reward is offered for information leading to their arrests.

security cybercrime indictment law enforcement ransomware
4 sources 4 reports 84d ago

Microsoft Patches Windows Defender 'RoguePlanet' Vulnerability CVE-2026-50656

Microsoft has patched the 'RoguePlanet' vulnerability (CVE-2026-50656) affecting Windows Defender on Windows 10 and 11, which allowed SYSTEM privileges escalation. The vulnerability was disclosed by researcher Nightmare Eclipse, and a month later Microsoft released the patch in Malware Protection Engine update version 1.1.26060.3008. The flaw's potential use in privilege escalation makes its resolution important for system security.

security windows vulnerabilities microsoft defender
4 sources 5 reports 87d ago

Google and FBI Disrupt NetNut Proxy Network of 2 Million Devices

Google, the FBI, Lumen, and others disrupted the NetNut residential proxy network involving over 2 million devices used for malicious activities. The operation disabled command-and-control features, protecting home devices from being exploited. This action significantly reduces cybercriminals' ability to mask their activities using residential IPs.

security google proxy malware cybercrime
3 sources 3 reports 2d ago

New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data

Researchers from VUSec and Scuola Superiore Sant'Anna have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), impacting Intel, AMD, and Arm CPUs. This vulnerability exploits how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers in web browsers, language runtimes, and operating system kernels. BTR can lead to sensitive data leaks, such as root password hashes from Intel Linux systems, and fixes for CVE-2026-64507 and CVE-2026-64508 have been merged into the Linux kernel.

security spectre cpu vulnerability linux
3 sources 3 reports 3d ago

Former US Soldier Sentenced to 70 Months for Extorting Tech and Telecom Firms

A former U.S. Army soldier received a 70-month prison sentence for hacking and extorting at least 10 U.S. technology and telecommunications companies. He and accomplices stole login credentials, extorted companies for over $1 million, and sold stolen data, impacting sensitive customer records and leading to SIM-swapping fraud.

security cybercrime extortion hacking telecom
3 sources 4 reports 6d ago

ShinyHunters Breaches Clop Ransomware Leak Site, Claims Data and Private Key Theft

The ShinyHunters extortion group breached the Clop ransomware operation's data leak site, defacing it and claiming to have stolen server data and the private keys for its onion service. This incident highlights the ongoing conflict between different cybercriminal groups and could impact Clop's future operations if the claims of private key theft are verified.

security cybersecurity ransomware data breach tor
3 sources 3 reports 7d ago

Rydox Cybercriminal Marketplace Operator Pleads Guilty After Brother's Deportation

Ardit Kutleshi, an operator of the Rydox cybercriminal marketplace, pleaded guilty to aggravated identity theft and money laundering charges. This development follows the deportation of his brother, who was also involved in running the illicit platform that facilitated the sale of stolen personal information and fraud tools.

security cybercrime identity theft money laundering law enforcement
3 sources 3 reports 8d ago

Ryuk Ransomware Member Sentenced to 24 Months in Prison for Hacking US Companies

Karen Serobovich Vardanyan, a member of the Ryuk ransomware group, received a 24-month prison sentence for hacking US companies and deploying ransomware. Vardanyan specialized in gaining initial access to corporate networks, contributing to attacks that extorted over $15 million in Bitcoin from victims.

security ransomware cybercrime sentencing ryuk
More stories →