From SecurityWeek · 40 stories
Liechtenstein's Register of Beneficial Owners Breached, 31,000 Records Exfiltrated
A cyberattack on Liechtenstein's Register of Beneficial Owners resulted in the exfiltration of data belonging to approximately 31,000 individuals. The breach, which occurred from Wednesday night into Thursday last week, compromised a critical financial transparency tool used to combat money laundering and terror financing in the principality.
Visa Acquires Fraud Prevention Firm BioCatch for $2.4 Billion
Visa is acquiring BioCatch, a fraud prevention company, for $2.4 billion in cash. This acquisition integrates BioCatch's behavioral biometrics technology into Visa's services to enhance cybersecurity and financial crime detection, addressing a global economy cost of over $1 trillion annually from scams and account takeovers.
Horizon3 Raises $250M Series E, Reaching $2 Billion Valuation
Cybersecurity startup Horizon3 secured $250 million in Series E funding, increasing its valuation from $650 million to $2 billion in 14 months. The funding, co-led by NightDragon and NEA, will support the company's growth as enterprises seek solutions for continuous, automated vulnerability testing against escalating AI-driven threats.
ShinyHunters Leaks Brinks Home Data After Breach Affecting 4.9 Million Records
Brinks Home, a residential security company, experienced a data breach identified on July 20, with the ShinyHunters extortion group claiming responsibility. ShinyHunters has leaked over 41 gigabytes of data, including 4.9 million Salesforce records with personally identifiable information (PII), after Brinks Home did not pay a ransom. The breach did not affect alarm monitoring or system functionality.
Okta Acquires AI Identity Security Startup Permiso for Reported $200 Million
Okta has signed an agreement to acquire Permiso Security, an AI identity security startup, for a reported $200 million in an all-cash deal. This acquisition expands Okta's identity management capabilities to include continuous monitoring and threat detection for human, non-human, and AI agent identities in multi-cloud environments, addressing the growing need for securing autonomous software deployments.
Hush Security Raises $30 Million to Secure Enterprise AI Agents
Hush Security, a Tel Aviv-based cybersecurity startup, secured $30 million in Series A funding, bringing its total raised to $41 million. The funding will be used to expand its platform for securing enterprise AI agents, focusing on identity and access management for autonomous AI within sensitive systems.
CISA and ACSC Release Guidance for Isolating Critical Infrastructure OT Systems During Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Cyber Security Centre (ACSC) have issued joint guidance, "CI Fortify – Advice for isolating vital systems," for critical infrastructure organizations. This guidance advises preparing to isolate operational technology (OT) systems from less trusted networks to maintain essential services during cyberattacks or other disruptions, addressing threats from state-sponsored actors.
Spur Intelligence Secures $200 Million Investment from Insight Partners for Bot Detection
Spur Intelligence, a cybersecurity startup specializing in IP intelligence and bot detection, raised $200 million in a funding round led by Insight Partners. This investment will accelerate and scale Spur's operations, which help organizations distinguish legitimate human users from increasingly sophisticated bot traffic and anonymized web activity. The funding addresses the growing challenge of bot activity, which now surpasses human internet traffic.
Cyera Acquires Oasis Security for $1 Billion to Secure AI Agents and Non-Human Identities
Data security company Cyera is acquiring agentic access management provider Oasis Security in a $1 billion deal, with approximately $700 million paid in cash and the remainder in shares. This acquisition integrates Oasis's non-human identity and agentic access governance platform into Cyera's offerings, addressing security challenges posed by the increasing use of AI agents in enterprise environments.
Apple Releases iOS 26.6 and iPadOS 26.6 with 87 Security Fixes
Apple released iOS 26.6 and iPadOS 26.6, addressing 87 vulnerabilities across its mobile operating systems. These updates fix flaws that could allow arbitrary code execution, privilege escalation, and data access, enhancing device security for iPhone and iPad users.
Google Threat Intelligence Group Unifies Threat Actor Naming System
Google Threat Intelligence Group (GTIG) has introduced a new unified naming schema for tracking threat actors, replacing the previously separate systems used by Mandiant and Google's Threat Analysis Group (TAG). This change aims to standardize threat actor identification across platforms and public reporting, making it easier for defenders to understand and respond to threats.
Dolphin X Malware Uses AI Profiling to Rank High-Value Targets
A new remote access trojan named Dolphin X incorporates an "AI Profiler" feature to score and rank infected users, helping cybercriminals prioritize victims. This development allows attackers to automate the identification of high-value targets from a large pool of compromised accounts, potentially increasing the efficiency of cyberattacks.
Chick-fil-A reports data breach from credential stuffing attacks
Chick-fil-A has alerted customers about a data breach caused by credential stuffing attacks affecting accounts. The breach may involve sensitive information like names, email addresses, and partial credit card numbers.
AegisAI raises $36M Series A to combat AI-driven spear phishing with AI agents
AegisAI, a startup founded by former Google security executives, secured $36 million in Series A funding to develop AI agents that detect and prevent AI-crafted spear phishing attacks. The company's technology analyzes email messages for anomalies that traditional rule-based systems often miss, addressing the increasing sophistication of AI-powered cyber threats.
White House Launches AI-Driven Gold Eagle Initiative for Cybersecurity Coordination
The White House has launched the Gold Eagle initiative, an AI-supported federal clearinghouse for cybersecurity vulnerabilities. This program aims to enhance vulnerability detection and remediation across government and private sectors by facilitating collaboration between software maintainers and infrastructure operators. Gold Eagle is backed by multiple federal agencies and uses AI to manage cybersecurity risks efficiently.
Upbound Group discloses $13M fraud in Acima leases following data breach
Upbound Group reported a cybersecurity incident where threat actors stole non-sensitive customer information and documents, leading to $13 million in fraudulent Acima lease-to-own agreements. The stolen data was used to obtain goods, resulting in financial losses for the company when fraudsters failed to make payments. Upbound has implemented enhanced security measures and notified federal law enforcement.
Cyberattack Halts Operations of Japanese Cold-Chain Operator Nichirei, Impacts Food Supply
A cyberattack on Nichirei Logistics Group disrupted frozen food shipments in Japan, affecting major chains like KFC. Operations began partial restoration post-attack, with a focus on data safety due to potential personal data compromise.
AI-Driven Security Startup Glow Emerges With $180M Funding at $1.2B Valuation
Glow, a cybersecurity startup leveraging AI to bolster endpoint security, has emerged from stealth with a $1.2 billion valuation and $180 million in Series A funding. Founded by former Meta and Snowflake executives, the startup seeks to address AI-related cyber risks by providing tools that manage software on employee devices. This reflects the growing concern over AI-augmented cyber threats and the need for enhanced security strategies.
Estée Lauder Data Breach Exposes Sensitive Details Through Oracle E-Business Vulnerability
Estée Lauder disclosed a significant data breach resulting from the exploitation of a zero-day vulnerability in Oracle E-Business Suite. The attack occurred in August 2025 and was revealed in June 2026, impacting personal data including Social Security numbers, financial, and health information of employees. The breach was connected to the Cl0p cybercrime group and affected multiple companies.
Israeli Startup Oak Launches AI-Driven Identity Management Solution with $60M Funding
Startup Oak has raised $60 million in funding, launching an AI-powered identity management system. This aims to unify identity governance across enterprises, addressing challenges exacerbated by AI. Oak's system combines various identity management tools into a single control plane, already deployed by some enterprise clients.
Critical RabbitMQ Vulnerabilities Risk Exposing OAuth Secrets and Tenant Data
A critical vulnerability in RabbitMQ, CVE-2026-5721, exposes OAuth secrets, enabling unauthorized access to sensitive information. An additional flaw can allow logged-in users to access cross-tenant data. These flaws, present since early 2024, have been patched in recent updates. These vulnerabilities underscore the importance of applying security updates to prevent unauthorized access risks.
Attackers Use Dormant GitHub Accounts for Reconnaissance via API
Datadog Security Labs has identified multiple attack campaigns exploiting dormant GitHub accounts for organizational reconnaissance. Attackers use these accounts with automated tools to gather data, occasionally accessing private repositories. This is significant due to potential risks of further targeted attacks.
200 GitHub Repositories Used to Spread Malware in 'Operation Muck and Load'
A threat actor has leveraged 200 GitHub repositories to distribute malware in 'Operation Muck and Load'. The campaign uses a deceptive Go module posing as a DNS scanner, distributing over 700 malicious variants since January 2023 to execute spyware, trojans, and other malware. This highlights significant risks in software supply chain security.
Armenian Man Pleads Guilty to Involvement in Ryuk Ransomware Attacks
Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleaded guilty in the US to charges related to deploying Ryuk ransomware. Extradited from Ukraine, Vardanyan facilitated attacks from November 2019 to April 2020, securing approximately $15 million in ransoms. His case underscores ongoing cybersecurity threats impacting various sectors.
GigaWiper: New Sophisticated Windows Backdoor with Destructive Capabilities
Microsoft has uncovered GigaWiper, a sophisticated malware targeting Windows machines. This backdoor combines older destructive programs to offer disk wiping, fake ransomware, and spyware functions, showcasing a shift in wiper malware to extortion activities. Its likely connections to cyber threats against Israeli organizations highlight the need for vigilance and strong cyber defenses.
UK Unveils AI-Driven 'Cyber Shield' for Enhanced National Cybersecurity
The UK announced the Cyber Shield initiative to improve national cybersecurity through agentic AI systems. The initiative, led by the National Cyber Security Centre, focuses on countering advanced threats that exploit AI to rapidly identify vulnerabilities. This collaboration with academia and industry aims to hardwire AI advancements into national security defenses against increasingly sophisticated cyber threats.
Mount Royal University Hit by Ransomware Attack, Data Stolen and Deleted
Mount Royal University in Calgary experienced a ransomware attack that led to the theft and deletion of student and employee data from its 'H drive' file storage systems. The CMD Organization, the group responsible for the attack, demanded a $1.9 million ransom for over 10 terabytes of data. This incident, impacting various university systems, emphasizes the ongoing risk of ransomware threats in the education sector.
Accenture Confirms Data Breach as Hacker Offers Source Code for Sale
Accenture has confirmed a data breach involving the theft of 35 GB of sensitive data, including source code and Azure credentials. A hacker is offering the data for sale, raising concerns about potential future exploitation. Accenture stated there is no impact on their operations and they have addressed the breach's source.
Google Patches Critical Flaw in Dialogflow CX Chatbot Platform
Google has patched a critical vulnerability in its Dialogflow CX platform that could have allowed attackers with specific permissions to compromise multiple chatbots within a single Google Cloud project. Dubbed 'Rogue Agent' by Varonis, the issue involved the execution of shared Code Blocks, which allowed unauthorized data access and message manipulation. No attacks exploiting this flaw were reported, and it was primarily a risk from insiders or compromised accounts.
Union County, Ohio Paid $1 Million to Cyber Group to Prevent Data Leak
Union County, Ohio paid $1 million to Kairos to prevent the release of stolen data after a May 2025 breach. This marks a significant data extortion case as there was no ransomware involved, emphasizing vulnerabilities in government data security without direct system lock-ups.
Iranian APT Group Targets Israeli Organizations with New C2 Framework
An Iranian hacking group linked to the Ministry of Intelligence and Security is targeting Israeli IT and government entities using a new command-and-control framework, Cavern C2. This development, attributed to the Cavern Manticore cluster, suggests evolving threats in cybersecurity, potentially influencing strategies in these sectors.
VEIL#DROP Malware Chain Uses Blogger to Deliver PureLogs Stealer
The VEIL#DROP malware delivery chain employs compromised Blogspot pages to deploy the PureLogs Stealer through multi-stage execution involving JavaScript and PowerShell. The use of trusted platforms like Google's Blogspot allows attackers to sidestep traditional defenses. Researchers have identified the sophisticated use of this infrastructure to access victims' sensitive information.
Armored Likho Targets Government and Power Sectors with Malware Attacks
The newly discovered Armored Likho group targets government and electric power sectors in Russia, Brazil, and Kazakhstan. The group uses malware, including the BusySnake Stealer, for cyber espionage and financial motives. This poses significant threats to critical infrastructure security in the affected regions.
North Korean Hackers Launch Supply Chain Attack with Malicious Software Packages
North Korean hackers have launched the PolinRider campaign, targeting open source developers and cryptocurrency sectors through malicious software packages. The attack involves 108 unique packages and extensions, including npm libraries, Go modules, and a Chrome extension. This campaign is ongoing and poses significant risks by compromising maintainer accounts and using backdoors and information stealers.
Critical Vulnerabilities Found in Cursor AI Code Editor, Prompt Urgent Update
Two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, were discovered in the Cursor AI code editor, potentially allowing remote code execution by bypassing its security sandbox. These flaws, identified by Cato AI Labs, affect all versions before Cursor 3.0 and have been patched in the new release. The vulnerabilities could impact many Fortune 500 companies that use the editor, highlighting the urgency for affected users to update to version 3.0 to mitigate security risks.
Citrix Patches Six Critical NetScaler Vulnerabilities, Including HTTP/2 Bomb
Citrix released patches for six vulnerabilities in NetScaler ADC and Gateway, including a critical HTTP/2 Bomb exploit. These flaws, affecting versions 14.1 and 13.1, pose severe risks like denial-of-service attacks and data breaches. Organizations using these configurations should urgently update to protect against active threats.
Cisco Acknowledges Exploitation of Unified CM Vulnerability CVE-2026-20230
Cisco has confirmed active exploitation of a critical vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM). This flaw, found in systems with the WebDialer service enabled, allows attackers to execute server-side request forgery attacks and potentially gain root access. Cisco urges users to upgrade to patched versions immediately.
LayerX Reveals AI Browser Vulnerability Exploited by 'BioShocking' Attack
Security firm LayerX has discovered a vulnerability in AI-driven browsers, known as the 'BioShocking' attack, where browsers can be tricked into leaking user credentials. The attack uses game-like puzzle contexts to manipulate AI agents into bypassing security protocols, potentially exposing sensitive data. This discovery raises concerns about the security of AI-assisted browsing applications.
DARPA Selects Xint to Apply AI for Securing Military Messaging Applications
DARPA selected Xint to research using autonomous AI for deep security analysis of messaging applications used by the Department of War. This initiative aims to secure military communications against external threats by analyzing source code and compiled binaries, building on Xint's performance in a DARPA AI competition.
RemoteThreat Launches with $7 Million Seed Funding for Offensive Operations Platform
RemoteThreat launched from stealth with $7 million in pre-seed funding to develop its offensive operations platform for red teams and government mission teams. The platform aims to improve the speed and scale of offensive cyber operations by integrating various tools and AI assistance.