Our own breakdowns of what happened
SharePoint Servers Under Fire as Remote Code Execution Flaw Gets Weaponized
AWS Coding Assistant Tricked Into Running Malicious Commands Hidden in Web Pages
Researchers reveal how AI-powered developer tools can be exploited through hidden text tricks to execute unauthorized code on developer machines.
Read full story βNew Awards Program Shines Spotlight on Industrial Cybersecurity Leaders
SecurityWeek introduces recognition program for OT security innovators, with winners announced at 2026 Nashville conference.
Read full story βCloud Infrastructure Flaw Could Allow Renters to Weaponize Power Consumption Against Energy Systems
Researchers discover method for cloud users to trigger cascading power grid failures through coordinated computing attacks.
Read full story βEmail Software Maker Fixes Multiple Security Holes Before Attackers Can Weaponize Them
Zimbra releases patches for dangerous vulnerabilities that could let hackers take control of email systems and steal data.
Read full story βCriminal Gang Exploits Palo Alto Networks Flaw to Break Into Company Systems
Qilin ransomware operators using PAN-OS vulnerability to gain unauthorized access to networks before deploying encryption attacks.
Read full story βMeta Rewards Security Expert $78,000 After Support System Flaw Exposed User Information
Meta paid a significant bug bounty after a researcher found improper access controls in its customer support platform.
Read full story βLuxury Giant EstΓ©e Lauder Hit by Major Database Breach Through Enterprise Software Vulnerability
EstΓ©e Lauder confirms attackers stole sensitive customer data after exploiting a security flaw in business management software.
Read full story βHackers Found Using Microsoft 365 Calendar as Secret Messaging System
Attackers leverage hijacked Office 365 accounts to hide malware commands in calendar events, evading detection.
Read full story βMajor VPN Vulnerability Becomes Active Weapon in Ransomware Attacks
Cybercriminals exploiting critical Palo Alto security flaw to launch ransomware campaigns against businesses worldwide.
Read full story βZimbra Releases Emergency Security Fixes for Multiple Critical Flaws
Popular email platform Zimbra patched severe security holes that could let attackers take control of systems and steal data.
Read full story βHackers Already Targeting ServiceNow Software Flaw Just Days After Details Released
Attackers are exploiting a newly discovered ServiceNow flaw that allows them to run malicious code remotely on company systems.
Read full story βClover Health Hit by Cyberattack Through Manipulated Employee Access
Healthcare insurance firm Clover Health confirms attackers gained access to sensitive patient and employee data via social engineering tactics.
Read full story βHackers Deploy New Ransomware Targeting AI Systems Through ServiceNow Vulnerability
Attackers exploiting ServiceNow flaw to install AI-focused ransomware that destroys machine learning models and data.
Read full story βCritical WordPress Flaws Create Perfect Storm for Website Takeovers
Two newly discovered WordPress vulnerabilities working together allow hackers complete control of websites without needing login credentials.
Read full story βWordPress Plugin Flaw Triggers Wave of Automated Attacks as Hackers Share Easy-to-Use Tools
A serious vulnerability in a WordPress plugin is spreading rapidly as criminals use publicly available hacking tools to target websites.
Read full story βCryptocurrency Platform Loses Millions After Attackers Exploit Corporate Network Flaws
Hackers breached a crypto firm through unpatched security gaps in widely-used VPN equipment, stealing $23.7M in digital assets.
Read full story βMajor Beauty Brand Hit by Software Vulnerability Attack; Hackers Steal Customer Data
EstΓ©e Lauder discloses breach tied to unpatched software flaw affecting personnel systems and customer information.
Read full story βLuxury Beauty Giant EstΓ©e Lauder Hit by Security Vulnerability in Business Software
EstΓ©e Lauder confirms customer data was compromised through a weakness in Oracle's enterprise accounting system.
Read full story βAI Coding Tools Exploited to Steal Model Data and Deploy Ransomware
Security researchers reveal how attackers manipulated AI assistants to bypass safety measures and encrypt critical machine learning systems.
Read full story βMassive GitHub Poisoning Attack: Over 7,600 Repositories Weaponized to Deliver Malware
Attackers compromised thousands of code repositories to distribute dangerous malware to unsuspecting developers.
Read full story β