From SecurityWeek · 40 stories
Cybersecurity Startup Neo Secures $100M for Enterprise AI Control Platform
Cybersecurity startup Neo has emerged from stealth with $100 million in funding for its platform designed to control and secure AI software within enterprises. The platform provides security teams with tools for monitoring AI agents and applications while offering real-time attribution to identify unauthorized actions.
New HIH Index Launches to Track Material Cyber Breaches
Richard Bird has launched the HIH Index to track material breaches, using two ledgers for data collection. The index aims to provide a resource for cybersecurity stakeholders and highlights discrepancies in reported losses over time, emphasizing an increase in companies affected rather than individual breach costs.
Cybersecurity Week in Review: Key Incidents and New Malware
A roundup of significant cybersecurity incidents highlights vulnerabilities from local actors, vendor breaches, and emerging malware. Notably, the new CrashStealer macOS malware poses threats to Apple devices, while various cyberattacks disrupt operations and lead to financial consequences for businesses.
Interview Discusses Governance Failures and MindStone Agent in Cybersecurity
Brian Schleifer interviews Clint Bodungen about governance challenges in cybersecurity and introduces the MindStone Agent, a new open-source AI project. This discussion highlights the ongoing evolution of cybersecurity and the critical role of human factors over technology in vulnerabilities.
Beacon Security Secures $13M Seed Funding for Threat Detection Platform
Beacon Security has raised $13 million in seed funding led by Notable Capital to develop its cybersecurity data platform. The platform enhances threat detection by integrating various data sources and leveraging AI, positioning Beacon to address new security needs in enterprise environments.
Pentagon Suspends CMMC Phase 2 Pending Review to Address Contractor Challenges
The Pentagon has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) to review its implementation and address industry concerns. This suspension pauses third-party assessments but maintains Phase 1 self-assessments and existing regulations. A CMMC Reform Task Force will lead a 60-day evaluation to recommend future measures.
Risk Ledger Secures $32 Million in Series B Funding for Supply Chain Security
Risk Ledger has raised approximately $32.3 million in a Series B funding round, led by Axiom Equity. This funding will expand its network of organizations tackling supply chain cyber risks and facilitate entry into the US market.
China Suspends Major Cybersecurity Firms from Military Procurement
China has suspended or banned over a dozen leading cybersecurity firms from military procurement due to contract bidding misconduct. This marks a significant enforcement action in the country's state procurement system, highlighting concerns about compliance within the industry.
Trend Micro, Tanium, ESET, and Tenable Patch Critical Vulnerabilities
Cybersecurity firms Trend Micro, ESET, Tanium, and Tenable have released patches for severe vulnerabilities in their products. These updates are crucial as they address potential exploits that could allow attackers to execute remote code and escalate privileges.
Windows Bind Link Attacks Can Evade Endpoint Detection Tools
Researchers at Bitdefender reveal that Windows bind links can be exploited to hide malware from EDR tools. This manipulation allows attackers to redirect legitimate paths to malicious files, evading detection by security systems reliant on path validation.
Siemens, Schneider, Rockwell Address Critical ICS Vulnerabilities in July Patch Tuesday
Siemens, Schneider Electric, and Rockwell Automation released advisories for vulnerabilities in their industrial control system (ICS) products. Significant vulnerabilities, including critical flaws with CVSS scores up to 10, were addressed, mitigating risks of remote exploitation and operational disruption.
Synopsys Denies Data Breach Claims Linked to Bosch Hack
Synopsys has found no evidence of a data breach after a cybercriminal group, D1R, claimed to have hacked its systems and accessed customer data, including from Bosch. The firm maintains that its systems are secure and that the hackers’ claims are unfounded, potentially minimizing the urgency of the security threat.
Valarian Secures $50 Million in Series A Funding for AI Governance Platform
Valarian raised $50 million in Series A funding to expand its AI governance platform, ACRA. The investment will enhance its cloud-agnostic infrastructure designed to isolate and manage workloads securely.
June 2026 Sees 37 Cybersecurity M&A Deals Announced
In June 2026, a total of 37 cybersecurity merger and acquisition deals were announced. Notable transactions include 1Password acquiring Apono, Accenture's purchase of Dragos, runZero, and NetRise, and Cisco's intent to acquire WideField Security.
QIZ Security Secures $17 Million for Cryptographic Governance Platform
QIZ Security has raised $17 million in seed funding to enhance its post-quantum cryptography management platform. The platform aims to enable organizations to govern encryption across various environments and prepare for quantum computing risks.
Palo Alto Networks Addresses 13 Security Vulnerabilities in Recent Patch
Palo Alto Networks has patched 13 vulnerabilities across its products, including a severe buffer overflow in PAN-OS that could allow DoS attacks and remote code execution. Organizations are advised to apply these updates to mitigate risks, particularly given the vulnerabilities' potential for exploitation despite currently low attack activity.
8Layers Secures $2.9 Million for Identity Security Platform Expansion
8Layers, a Spanish security startup, has closed a $1.1 million pre-seed extension, reaching a total of $2.9 million in funding. This investment will enhance its digital identity protection platform, which integrates multiple security features and aims to expand its presence across Europe.
CISA Uses Anthropic's Mythos AI to Audit Federal Software for Vulnerabilities
CISA is deploying Anthropic’s Mythos AI model to scan federal government software for vulnerabilities. The initiative aims to identify and rectify potential security flaws that could be exploited before they are discovered by adversaries.
Tarah Wheeler Shares Insights on Her Career in Cybersecurity Leadership
Tarah Wheeler, CISO at TPO Group, discusses her unexpected journey into cybersecurity and her social science perspective on the field. Her insights highlight the importance of understanding human behavior in shaping effective security policies and leadership roles in cybersecurity.
Canadian Hacker Jailed for Cyberattack; KDDI Data Breach Impacts 14 Million
Aubrey Cottle, a Canadian hacker linked to Anonymous, was sentenced to 18 months in prison for a 2021 cyberattack on the Texas GOP. Meanwhile, KDDI announced a data breach affecting over 14 million users, exposing email addresses and passwords.
Microsoft Introduces Controls to Block Unauthorized AI Bots in Teams Meetings
Microsoft has launched a new Teams admin policy to control external bots joining meetings. By requiring organizer confirmation for bots, the company aims to enhance security and privacy during sensitive discussions.
CrowdSec Reports Source Code Leak from May 2026, Attributes to Tanstack Compromise
CrowdSec confirmed a source code leak from May 2026 involving its private GitHub repositories, which contained code for its SaaS console, AWS routines, connectors, and automations. The company states no client data or sensitive credentials were leaked, and the incident's impact is limited to CrowdSec, with the Tanstack compromise identified as the likely vector.
Levi Strauss & Co. Reports Corporate Data Exfiltration After Social Engineering Attack
Levi Strauss & Co. disclosed that hackers accessed and exfiltrated corporate information from three employee computers through a social engineering attack. The company stated that the incident did not disrupt business operations and found no evidence of consumer data exposure, but the specific corporate data taken was not disclosed. The company believes the incident will not materially impact its business.
Analog Devices Discloses Data Breach, Files Exfiltrated
Semiconductor company Analog Devices reported a data breach detected on June 23, where an unauthorized party accessed systems and exfiltrated certain files. The company stated that operations were not disrupted and the incident is not expected to materially impact its business, though it is also assessing public reports of a separate cybersecurity matter from July 26.
Only 13% of OT Network Segments Are Fully Isolated, According to Forescout Research
New research from Forescout's Vedere Labs indicates that only 13% of network segments containing operational technology (OT) devices are fully isolated, with most sharing space with IT or IoT equipment. This lack of segmentation increases the attack surface for critical infrastructure and medical devices, posing significant cybersecurity risks.
Ransomware Attacks on Manufacturers Increase 40% in 2026, Disrupting Supply Chains
Ransomware incidents targeting manufacturing companies rose by 40% in the first seven months of 2026 compared to the previous year, according to the Black Kite 2026 Manufacturing & Distribution Ransomware Report. This surge is attributed to the significant operational impact and supply chain disruption these attacks cause, making manufacturers, particularly mid-sized suppliers, attractive targets for ransomware groups.
Proposed Open Revocable Key Standard (ORKS) Aims to Standardize API Key Revocation
A new draft specification, ORKS (Open Revocable Key Standard), has been proposed to standardize the revocation of API keys, addressing a long-standing security vulnerability. This standard aims to provide a universal method for identifying API key issuers and programmatically revoking compromised keys, similar to how OAuth tokens are handled.
CISOs Face Disconnect Between Technical Hiring Expectations and Business-Oriented Performance Metrics
Chief Information Security Officers (CISOs) are often hired for their technical expertise but evaluated on business metrics like cost, growth, and customer trust, leading to a disconnect in expectations. This gap arises because security is frequently viewed as an insurance function rather than a business driver, despite its critical role in customer purchasing decisions and retention. To bridge this, CISOs need to articulate how security directly enables business growth and trust.
Defense Contractors Confident in CMMC Compliance, But Struggle to Prove It
Two industry surveys indicate that defense contractors are increasingly confident in their cybersecurity compliance, yet many lack the necessary documentation to prove it. This disconnect raises concerns about potential False Claims Act liability and highlights confusion regarding CMMC requirements, even after the CMMC 2.0 Phase 2 assessment suspension.
AI Governance Lags Adoption, Creating Risks for Organizations
Many organizations are delaying AI governance until regulations are finalized, despite 46% reporting that governance issues cause AI underperformance. This delay creates risks due to rapid AI adoption, fragmented regulatory environments, and evolving threat landscapes.
Cyber Operations Emerge as Fourth Domain of Military Conflict Alongside Land, Air, and Sea
Cyberspace has become a critical fourth domain of military conflict, influencing geopolitical disagreements alongside traditional land, air, and sea forces. This integration means cyber activities now frequently precede kinetic warfare, highlighting the evolving nature of international conflict and the strategic importance of cyber capabilities.
SIM Swap Attack Highlights Vulnerabilities in Identity Verification
A recent near account takeover incident underscores the inadequacy of current identity verification methods. It reveals the need for organizations to continuously evaluate identity throughout the customer journey rather than relying on one-time authentication.
Operational Technology Security Faces Unique Challenges in Vulnerability Management
Operational Technology (OT) security presents distinct challenges compared to IT security, especially in vulnerability management processes. This difference arises from the traditional design of OT systems, which often lack modern security features and focus primarily on denial of service (DoS) impacts rather than remote code execution.
Shift Towards Business-Aligned Risk Management in Risk Assessment
Organizations are moving toward a business-aligned approach to risk management. This shift integrates risk assessments with operational disruptions that could lead to financial loss, enhancing decision-making effectiveness.
Surfshark VPN reports breach of internal test and proxy servers due to misconfiguration
Surfshark disclosed that hackers accessed an internal test server and a separate proxy server after a configuration error exposed them to the internet. The company stated that no customer data or production VPN infrastructure was impacted, and users do not need to take action.
SecurityWeek Opens Call for Presentations for 2026 CISO Forum Virtual Summit
SecurityWeek has opened its Call for Presentations for the 2026 CISO Forum Virtual Summit, scheduled for November 11-12, 2026. The summit seeks original, vendor-neutral presentations from cybersecurity leaders on topics like AI-driven attacks, supply-chain risk, and Zero Trust.
Kiteworks Acquires Bonfy.AI to Enhance Data Governance for AI and Human Workflows
Kiteworks acquired Bonfy.AI, an AI data security company, to extend real-time policy enforcement over sensitive data exchanged by human users and AI agents. This acquisition aims to fill a gap in enterprise data protection by classifying data at the point of exchange and applying security policies before transfer, including interactions with AI assistants.
Catch Raises $5 Million to Develop AI Executive Assistant with Guardrails
Catch, an AI startup, secured $5 million in funding co-led by Entrée Capital and Pitango to advance its AI executive assistant product. The funding will support the development of an AI agent designed to handle sensitive administrative tasks with built-in security and user-defined access controls, aiming to move AI beyond analysis to active decision-making.
Sevii Extends Autonomous Defense Platform with New AI Security Module for Real-Time Remediation
Sevii has added a new AI security module to its Autonomous Defense & Remediation (ADR) platform, designed to provide instant and autonomous responses to AI-driven attacks. This module ingests alerts from existing security tools, analyzes them in real-time, and uses AI agents to confirm and remediate genuine AI attacks across a customer's infrastructure. The update addresses the increasing speed of AI attacks, which often outpace human response capabilities.
Xpander Secures $7.5 Million Seed Funding for AI Management and Governance Platform
AI enablement platform Xpander raised $7.5 million in seed funding to expand its market penetration. The company provides a platform for organizations to manage and govern AI agents across various environments, addressing challenges in AI adoption and migration.