Latest Cybersecurity News and Articles
16 July 2026
The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges.
The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek.
16 July 2026
Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also
16 July 2026
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext.
A researcher publishing under the handle tokay0 put the method online on Monday, having tested it only against vacuums he
16 July 2026
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek.
16 July 2026
Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.
The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek.
16 July 2026
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely.
"GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injection attacks," the artificial intelligence (AI) company said. "We use GPT‑Red to adversarially train
16 July 2026
Signed by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS.
The post Old UEFI Shims Expose Systems to Secure Boot Bypass appeared first on SecurityWeek.
16 July 2026
Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover.
The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows.
"Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for
16 July 2026
The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability.
The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek.
16 July 2026
The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek.
16 July 2026

‘Malicious actor’ obtains sensitive data including Medicare numbers, treatment details and pathology results in cyber-attack on Partnered HealthFollow our Australia news live blog for latest updatesGet our breaking news email, free app or daily news podcastAustralians’ medical records and patient information could be sold on the hidden market, an expert has warned, after a cyber-attack at one of the nation’s biggest healthcare providers.Partnered Health revealed 21 clinics across several cities including Sydney, Melbourne and Canberra were affected when a “malicious actor” accessed its data on 23 June. Continue reading...
15 July 2026
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results.
"While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed
15 July 2026
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase.
On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and
15 July 2026
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically.
The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.
15 July 2026
Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.
The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek.
15 July 2026
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.
The vulnerabilities are listed below -
CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component
CVE-2026-15719, a site isolation in the DOM: Navigation component
"We are aware that exploit code for this is public, however we are not aware of
15 July 2026
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.
The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek.
15 July 2026
Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.
The post Virtual Event Today: Cloud & Data Security Summit appeared first on SecurityWeek.
15 July 2026
The suspects and their companies were previously sanctioned by the United States and its allies.
The post US Charges Russian Individuals and Firms for Running Cybercrime Services appeared first on SecurityWeek.
15 July 2026
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up.
Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into