Archive for the Uncategorized Category

By Ionut Arghire

CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.

The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.

…read more

Source:: securityweek

By Eduard Kovacs

Anthropic has been conducting tests to identify issues in how AI agents interact with each other.

The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek.

…read more

Source:: securityweek

By Associated Press

Atalanta’s Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek.

…read more

Source:: securityweek

By Ionut Arghire

Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.

The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.

…read more

Source:: securityweek

By algerj@bnpmedia.com (Jordyn Alger)

A hacker claimed to have stolen 3.6 million Azure account records from major organizations. Security leaders discuss.

…read more

Source:: Security magazin

By Kevin Townsend

With no formal training and no career plan, Waisman built a path from Argentina’s early hacking scene to leading security at an AI-powered offensive security firm.

The post CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW appeared first on SecurityWeek.

…read more

Source:: securityweek

By Ionut Arghire

The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.

The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.

…read more

Source:: securityweek

In this threat landscape, the assumption that what we see and hear is always real is disintegrating.

…read more

Source:: Security magazin

By Kevin Townsend

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.

The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.

…read more

Source:: securityweek

By Ionut Arghire

Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand.

The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek.

…read more

Source:: securityweek