Latest Cybersecurity News and Articles
29 July 2026
The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period.
The post US, Australia Release OT Isolation Guidance for Critical Infrastructure appeared first on SecurityWeek.
29 July 2026
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation.
The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek.
29 July 2026
The IP intelligence company will use the fresh investment to accelerate and scale its operations.
The post Spur Raises $200 Million for IP Intelligence Platform appeared first on SecurityWeek.
29 July 2026
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that
29 July 2026
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek.
29 July 2026
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities.
The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek.
29 July 2026
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.
Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The
29 July 2026
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers.
They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password
29 July 2026
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack.
The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than
29 July 2026
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.
The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek.
29 July 2026
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.
The list of affected packages is as follows -
@joyfill/layouts@0.1.2-2773.beta.0
@joyfill/components@4.0.0-rc24-2773-beta.4
The two packages "contain an import-time JavaScript implant that resolves encrypted code
28 July 2026
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128.
The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server
28 July 2026
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process.
If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.
Tengu supports 25 distributed denial-of-service (
28 July 2026
Oasis Security recently raised $120 million in Series B funding for its agentic access management platform.
The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek.
28 July 2026
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.
Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to
28 July 2026
Apple announced that dozens of vulnerabilities have been patched in each of its operating systems.
The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek.
28 July 2026
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.
Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud
28 July 2026
The company will use the fresh investment to grow its customer success and AI R&D teams.
The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek.
28 July 2026
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.
The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6
28 July 2026
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.
The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,