For you Ai Security Dev Cloud Hardware Startups Releases General

From SecurityWeek · 40 stories

3 sources 7 reports 83d ago

Critical Linux Kernel Vulnerabilities: DirtyClone, Bad Epoll, and GhostLock

Three critical Linux kernel vulnerabilities, DirtyClone (CVE-2026-43503), Bad Epoll (CVE-2026-46242), and GhostLock (CVE-2026-43499), have been disclosed, each allowing privilege escalation. DirtyClone targets cloned network packets, Bad Epoll exploits a race condition, while GhostLock leverages a 15-year-old use-after-free flaw. Each vulnerability has a patch available, emphasizing the need for prompt system updates to mitigate exploitation risks.

security linux vulnerability kernel malware
3 sources 3 reports 83d ago

Critical Gitea Docker Vulnerability CVE-2026-20896 Faces Active Exploitation

Gitea Docker images are subject to a critical authentication bypass vulnerability (CVE-2026-20896) now under active exploitation. The flaw allows attackers to impersonate any user, including administrators, via reverse proxy authentication with default configurations. It affects versions before 1.26.3 and about 6,200 instances globally.

security devops docker vulnerabilities gitea
3 sources 3 reports 85d ago

12 Million Affected in KDDI Data Breach, Exploiting Zero-Day Vulnerability

KDDI, a major Japanese telecom provider, confirmed a breach affecting 12.2 million email addresses and 7.6 million passwords via a compromised email system used by five ISPs. The breach exploited a zero-day vulnerability in third-party software. KDDI has implemented security measures and coordinated password resets to prevent future incidents.

security cybersecurity data breach kddi japan
3 sources 3 reports 85d ago

Chinese APT UAT-7810 Develops New Malware to Expand ORB Network

Chinese APT group UAT-7810 has advanced its Operational Relay Box (ORB) network with new malware, including LONGLEASH, DOGLEASH, and JARLEASH. These tools exploit known router vulnerabilities to enhance the group's cyber espionage capabilities, posing potential risks to critical infrastructure.

security malware cybersecurity threat UAT-7810
3 sources 3 reports 86d ago

GitHub Agentic Workflows Vulnerable to Prompt Injection, Exposing Private Repos

Noma Labs identified a prompt injection vulnerability, named GitLost, in GitHub's Agentic Workflows, enabling data leaks from private repositories. Attackers can manipulate AI agents to disclose private content through crafted public issues. This highlights security concerns in using AI-driven workflows in GitHub's system.

security github ai data leakage vulnerability
3 sources 3 reports 87d ago

Medtronic Hack Exposes Data of Nearly 4 Million People in ShinyHunters Breach

Medtronic suffered a data breach in April 2026, compromising the personal and medical information of over 3.8 million individuals, with some sources claiming 9 million records affected. The ShinyHunters group accessed Medtronic's corporate IT systems, despite the company's reassurance about device safety. Medtronic is offering credit monitoring and support services to those impacted, highlighting security vulnerabilities in healthcare technology.

security data breach healthcare cybersecurity shinyhunters
3 sources 3 reports 91d ago

FortiBleed Campaign Compromises Fortinet Devices, Linked to Ransomware Groups

The FortiBleed campaign has been connected to the INC and Lynx ransomware groups, compromising credentials from Fortinet devices. Researchers found the operation entailed scanning 11,250 FortiGate portals and compromised 354 targets, leading to 12 ransomware deployments. The breach highlights significant cybersecurity risks, affecting organizations globally.

security ransomware credential-theft fortinet fortibleed
1 source 1 report 53d ago

Critical Flaws Found in Belgian eID Software Affecting 2 Million Users

Security researcher James Arnott discovered critical vulnerabilities in Connective digital identity software, used by over two million people in Belgium for digital identity authentication and electronic signatures. These flaws allowed malicious websites to read eID details, trick users into revealing PINs, forge electronic signatures, and execute remote code, impacting the trust model of Belgium's digital ecosystem.

security vulnerability eid belgium
1 source 1 report 63d ago

EU Establishes New Team to Enforce AI Act, Targeting Deepfakes and Illicit Imagery

The European Union launched a new team in Brussels to enforce its AI Act, which comes into force on Sunday. This team will monitor AI companies for violations related to deepfakes, illicit imagery, and cyber threats, requiring AI-generated content to be labeled.

ai eu regulation deepfakes
1 source 1 report 64d ago

AI Weaponizes Dangling DNS Takeovers, Expanding Attack Surface and Automation

Security firm Silent Push demonstrated how AI can significantly scale 'dangling DNS takeover' attacks, a method where attackers exploit forgotten DNS records pointing to deleted cloud resources. This research, dubbed 'DangleGeddon', shows AI's capability to automate discovery, script generation, and exploitation, making these attacks a more potent threat for nation-state actors focused on disruption.

security ai dns cybersecurity
1 source 1 report 72d ago

Oracle Patches 1,449 Vulnerabilities in July 2026 Security Update

Oracle released its July 2026 Critical Patch Update, addressing 1,449 vulnerabilities across 334 products, many identified using AI. With around 600 patches allowing remote exploitation, organizations are urged to update immediately to mitigate the risk of attacks.

security oracle vulnerabilities ai
1 source 1 report 72d ago

Trump Executive Order Mandates Mapping of Defense Supply Chains for Cybersecurity

President Trump signed an executive order requiring the mapping and securing of critical defense supply chains, emphasizing software and technology used in national security. This initiative aims to enhance visibility and security against cyber and economic threats across all tiers of suppliers, impacting both prime and subcontractors.

security cybersecurity defense supplychain software
1 source 1 report 79d ago

VMware Avi Load Balancer Patches 7 Critical Vulnerabilities

Broadcom announced patches for seven vulnerabilities in VMware Avi Load Balancer, including critical authentication bypass and remote code execution issues. Organizations are advised to update promptly to prevent potential exploitation, especially as VMware flaws have been targeted in past attacks.

security vmware vulnerabilities load balancer
1 source 1 report 81d ago

Centers Laboratory Data Breach Impacts Over 540,000 Individuals

Centers Laboratory reported a data breach affecting 542,377 individuals, revealing personal and health information. The breach occurred due to limited access by cybercriminals from the WorldLeaks group, which highlights ongoing threats to healthcare data security.

security data breach healthcare cybersecurity worldleaks
1 source 1 report 87d ago

Keyfactor Secures Over $1 Billion for AI and Post-Quantum Security Solutions

Keyfactor has raised over $1 billion to enhance its Trust Control Plane, addressing identity sprawl and preparing for post-quantum security. This investment will help expand its global operations and advance product innovation amid rising demand for unified cryptographic solutions.

startups keyfactor investment post-quantum security
1 source 1 report 88d ago

Prompt Injection Attacks Target AI Agents for Fraudulent Crypto Payments

Threat actors are using prompt injection attacks to deceive AI agents into making cryptocurrency payments. Zscaler identified two tactics, including a payment scam disguised as API documentation and a typosquatting operation impersonating a crypto service, which could significantly undermine trust in AI-integrated financial transactions.

security cryptocurrency ai cybersecurity threats
2 sources 2 reports 3d ago

ShinyHunters Launches New Oracle PeopleSoft Exploitation Campaign Bypassing WAFs

Mandiant and Google Threat Intelligence Group reported that the ShinyHunters group initiated a new mass-exploitation campaign targeting Oracle PeopleSoft customers. This campaign uses a modified exploit for CVE-2026-35273 to bypass web application firewalls (WAFs), expanding its targets beyond the education sector to various industries.

security vulnerability oracle cyberattack peoplesoft
2 sources 2 reports 3d ago

Modulate Secures $25M in Funding for Voice AI Analysis and Deepfake Detection

Modulate, a Boston-based startup, has raised $25 million in new funding to advance its voice intelligence platform, which provides transcription, emotional analysis, deepfake detection, and policy enforcement for voice agents. This funding enables Modulate to further develop its array of small voice models for nuanced conversation understanding and protection against AI audio generation and scams. The investment highlights continued interest in voice AI technologies that aim to make AI voices more human-like and detect malicious uses of voice cloning.

ai voice ai funding deepfake detection deepfake
2 sources 2 reports 8d ago

Astrana Health Reports Data Breach After Social Engineering Attack

Astrana Health, a healthcare management company, disclosed a data breach where private and confidential information was exfiltrated from its servers following a social engineering attack on employees. The company is assessing the extent to which patient, employee, and business data may have been accessed.

security data breach social engineering healthcare cybersecurity
2 sources 2 reports 9d ago

BigCommerce Merchants Alerted to Data Breach via Compromised Ribon App Credentials

BigCommerce has notified merchants of data breaches stemming from compromised credentials for third-party Ribon applications, which attackers used to inject malicious scripts into online stores. The breach exposed shopper information such as names, email addresses, phone numbers, and shipping addresses, affecting multiple BigCommerce customers.

security ecommerce data breach third-party supply chain attack
2 sources 2 reports 13d ago

US Coast Guard and FBI Board Two Oil Tankers After Cyberattacks During Voyage

US Coast Guard and FBI personnel boarded two oil tankers bound for Texas last month following cyberattacks that disrupted the vessels during their journey. Investigators found evidence of a malicious cyber actor on one ship, the VL Prosperity, which reportedly experienced interference with engine, navigation, and communication systems. This incident highlights ongoing cyber threats to the maritime sector, prompting the Coast Guard to establish a dedicated Office of Maritime Cybersecurity Policy.

security cybersecurity maritime fbi coast guard
2 sources 2 reports 14d ago

BIND 9 Updates Address 14 Vulnerabilities, Including Critical DoH Crash Flaw

The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to fix fourteen security vulnerabilities in its open-source DNS server software. One critical flaw, CVE-2026-77692, allows an unauthenticated attacker to crash a BIND server configured for DNS-over-HTTPS (DoH) with a single crafted request. These updates are important for maintaining the stability and security of DNS infrastructure.

security dns bind vulnerability
2 sources 2 reports 18d ago

ConnectWise warns of new ScreenConnect vulnerability, provides temporary mitigations

ConnectWise issued a security advisory regarding a new vulnerability in its ScreenConnect Remote Access platform that affects file transfer behavior. While a permanent patch is expected later this week, the company has provided temporary mitigation steps for administrators to implement. This vulnerability is significant because ScreenConnect is widely used by IT professionals, and previous flaws in the platform have been actively exploited by threat actors, including ransomware gangs and state-backed groups.

security vulnerability connectwise screenconnect patch
2 sources 2 reports 21d ago

Amazon appoints cybersecurity expert Kevin Mandia to its board of directors

Amazon has added Kevin Mandia, founder of Mandiant and a cybersecurity veteran, to its board of directors. This appointment comes as companies face increasing cybersecurity threats, particularly those related to artificial intelligence.

security board appointment amazon ai cybersecurity
2 sources 2 reports 22d ago

Deceptive Android Apps Exploit Google Play Early Access Program to Evade Reviews

Threat actors are misusing Google Play's Early Access program to distribute deceptive Android applications. These apps, which promise rewards or premium content, bypass public reviews and ratings, primarily serving ads to users to generate revenue. Bitdefender identified this activity, noting that some apps, like a Grand Theft Auto imitator, accumulated over a million downloads before removal.

security android malware google play scam
2 sources 2 reports 24d ago

Mathspace discloses data breach affecting over 1 million students, staff, and parents

Online learning platform Mathspace reported a data breach impacting over 1 million individuals in Australia and New Zealand. Attackers exploited a vulnerability in the company's self-hosted Metabase internal reporting system to steal personal information.

security data breach education metabase vulnerability
2 sources 2 reports 27d ago

OpenAI Expands Daybreak Initiative with $1 Billion for Critical Infrastructure Cyber Defense

OpenAI announced Daybreak for Frontline Defenders, an expansion of its existing Daybreak initiative, committing $1 billion to help critical infrastructure sectors like power, water, and banking use frontier cyber AI for defense. This initiative provides subsidized access to AI models, training, and support to cyber defenders protecting essential services globally and within the United States.

security openai cybersecurity ai critical infrastructure
2 sources 2 reports 27d ago

12-Year-Old PostgreSQL Vulnerability Allows Database and Server Takeover

A cybersecurity firm discovered a critical vulnerability, CVE-2026-6471 (PostGREShell), in PostgreSQL versions released since 2014, enabling attackers with low privileges to achieve remote code execution and privilege escalation. This flaw, stemming from missing authorization in logical decoding, allows unauthorized file loading and execution, posing a significant risk to the tens of thousands of companies using PostgreSQL.

security vulnerability postgresql database cve
2 sources 2 reports 29d ago

AIR Raises $50M to Secure AI Agent Software Supply Chain

AI security startup AIR emerged from stealth with $50 million in seed funding to develop a platform for vetting AI agent skills and add-ons. The platform discovers AI agents, continuously vets their components, and blocks interactions that fail security criteria, addressing risks associated with AI agents operating autonomously across enterprise systems.

security ai startups funding
2 sources 2 reports 29d ago

Palo Alto Networks Acquires AI Agent Platform Console to Enhance Cortex Capabilities

Palo Alto Networks has acquired Console, an AI-native platform that enables organizations to build agentic workflows and automate operational tasks using natural language. This acquisition will integrate Console's technology into Palo Alto's Cortex platform, allowing security teams to automate investigation, prioritization, and action across enterprise environments.

security ai acquisition automation it automation
2 sources 2 reports 34d ago

Hasbro discloses data breach affecting employee personal and financial information

Toy manufacturer Hasbro has disclosed a data breach impacting an undisclosed number of employees, with personal and financial information exposed. This incident follows a separate cyberattack in March that caused $25 million in revenue loss, though Hasbro has not linked the two events.

security data breach cybersecurity employee data hasbro
2 sources 2 reports 35d ago

Trump Order Declares National Emergency to Block Foreign Backdoors in US Power Grid

President Trump issued Executive Order 14420, declaring a national emergency to address vulnerabilities in the US bulk power system from foreign-supplied electrical equipment. The order prohibits the acquisition, import, transfer, or installation of certain foreign-produced bulk-power equipment after August 26, 2026, if deemed to pose security risks. This aims to mitigate supply chain risks and potential embedded hardware backdoors in critical infrastructure.

security cybersecurity critical infrastructure supply chain national security
2 sources 3 reports 36d ago

Okta Exceeds Q2 Estimates, Reports Increased Demand for AI Identity Security

Okta surpassed Wall Street's fiscal second-quarter earnings and revenue estimates, driven by increased demand for identity security solutions related to AI agents. The company's shares rose 20% in extended trading, reflecting strong financial performance and strategic moves in the evolving AI security landscape.

security okta earnings ai cybersecurity
2 sources 2 reports 38d ago

ReliaQuest employee targeted in social engineering attack by ShinyHunters

Cybersecurity firm ReliaQuest confirmed that an employee was targeted in a social engineering attack by the ShinyHunters group, which attempted to gain access to internal systems. Although one employee entered credentials on a fake SSO page, device-trust controls prevented the attackers from accessing applications or customer data. This incident highlights the ongoing threat of social engineering and the importance of multi-layered security controls.

security social engineering phishing shinyhunters cyberattack
2 sources 2 reports 39d ago

Apollo Global Management Confirms Data Breach Affecting Personal Information

Private equity firm Apollo Global Management confirmed a data breach where hackers stole personal information from its cloud systems between July 6 and July 10. The incident involved a social engineering attack and is part of a wider hacking campaign targeting financial institutions.

security data breach social engineering financial services cybersecurity
2 sources 2 reports 44d ago

Apple Releases Security Updates for macOS, iOS, and iPadOS Addressing WebKit Vulnerabilities

Apple released security updates for macOS, iOS, and iPadOS to fix dozens of vulnerabilities, primarily in the WebKit browser engine. These patches are important for user security, as the flaws could lead to crashes, data disclosure, and arbitrary code execution.

security apple webkit ios safari
2 sources 2 reports 45d ago

Heights Finance Data Breach Exposes Financial and Personal Information of Nearly 750,000 Customers

Heights Finance, a debt consolidation loan company, experienced a data breach in May that exposed sensitive financial and personal information, including Social Security numbers, for approximately 734,828 customers. The breach occurred on a third-party cloud platform and did not affect the company's internal loan management systems. This incident highlights the ongoing risks associated with third-party cloud service providers and the potential for widespread data compromise in the financial sector.

security data breach cybersecurity financial services cloud security
2 sources 2 reports 49d ago

RingCentral Data Breach Impacts 1.6 Million Accounts After Social Engineering Attack

RingCentral experienced a data breach in July, affecting 1.6 million individuals, following a "sophisticated social engineering campaign." The ShinyHunters extortion group claimed responsibility and leaked data after RingCentral did not meet their demands, leading to the information being added to HaveIBeenPwned.

security data breach cybersecurity ringcentral shinyhunters
2 sources 2 reports 49d ago

Trezor Customers Affected by Data Breach at Shipping Partner ShipMonk

Hardware wallet manufacturer Trezor disclosed a data breach impacting nearly 14,000 customers after its shipping provider, ShipMonk, experienced unauthorized access to its systems. The incident exposed customer order data, including names, addresses, emails, and phone numbers, for orders placed between May 10 and August 8, 2026. Trezor's own systems were not compromised, but the breach raises concerns about potential phishing attempts targeting affected users.

security data breach cryptocurrency hardware wallet cybersecurity
2 sources 3 reports 52d ago

New York Funds Water System Cybersecurity; Senate Bill Proposes $300M Annual Federal Aid

New York State has allocated over $9 million to 153 drinking water and wastewater systems to enhance cybersecurity defenses and comply with new state standards. Concurrently, Senate Democrats introduced the Water Cyber Shield Act, proposing $300 million annually for national water infrastructure cybersecurity improvements and expanded EPA authority, following recent cyberattacks on water systems.

security cybersecurity new york critical infrastructure government
More stories →