Latest Cybersecurity News and Articles
29 July 2026
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.
Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls.
Braham's water plant went offline, and the city asked residents to minimize
29 July 2026
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years.
According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
29 July 2026
The agency said imports of advanced robots pose cybersecurity and other national security risks.
The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek.
29 July 2026
The startup will use the investment to expand its customer support, sales, and R&D teams.
The post Mate Security Raises $35 Million for Agentic SOC appeared first on SecurityWeek.
29 July 2026
The company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation.
The post ThreatLocker Raises $190 Million in Series F Funding appeared first on SecurityWeek.
29 July 2026
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along.
The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change?
The honest answer is
29 July 2026
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.
Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update.
"No settings or additional user interaction are required," Eten Zou,
29 July 2026
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek.
29 July 2026
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack.
According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January
29 July 2026
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law.
The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform that are
29 July 2026
The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period.
The post US, Australia Release OT Isolation Guidance for Critical Infrastructure appeared first on SecurityWeek.
29 July 2026
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation.
The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek.
29 July 2026
The IP intelligence company will use the fresh investment to accelerate and scale its operations.
The post Spur Raises $200 Million for IP Intelligence Platform appeared first on SecurityWeek.
29 July 2026
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that
29 July 2026
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek.
29 July 2026
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities.
The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek.
29 July 2026
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.
Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The
29 July 2026
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers.
They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password
29 July 2026
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack.
The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than
29 July 2026
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.
The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek.