By Ionut Arghire
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »
By Eduard Kovacs
Anthropic has been conducting tests to identify issues in how AI agents interact with each other.
The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »
By Associated Press
Atalanta’s Argo product is now being used to prove the resilience of Viasat’s satellite communications network.
The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »
By Ionut Arghire
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »
By algerj@bnpmedia.com (Jordyn Alger)
A hacker claimed to have stolen 3.6 million Azure account records from major organizations. Security leaders discuss.
Source:: Security magazin
Posted in Uncategorized | No Comments »
By Kevin Townsend
With no formal training and no career plan, Waisman built a path from Argentina’s early hacking scene to leading security at an AI-powered offensive security firm.
The post CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »
By Ionut Arghire
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »
In this threat landscape, the assumption that what we see and hear is always real is disintegrating.
Source:: Security magazin
Posted in Uncategorized | No Comments »
By Kevin Townsend
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.
The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »
By Ionut Arghire
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand.
The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek.
Source:: securityweek
Posted in Uncategorized | No Comments »