Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.

Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen.

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. 

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.

Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden.

The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions.

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.

Chinese AI Chinese AI

The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.

Cryptocurrency Cryptocurrency

Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen.

File notification attack leak File notification attack leak

Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.

Top Cybersecurity Headlines

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

SecurityWeek’s 2026 Zero Trust Summit will deep-dive into the world of digital identity management and the role of zero-trust principles and associated technologies
[October 14, 2026 | Virtual]

Read More

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[Originally September 16, 2026]

Read More

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[Originally August 19, 2026]

Learn More

Vulnerabilities

Cybercrime

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.

Cloud Security

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.