Search the Portal

Recent Articles

JUL22
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover

Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek.

Security Week by Torsten George
JUL22
StrongestLayer Raises $4.1 Million in Seed Funding Extension

The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek.

Security Week by Ionut Arghire
JUL22
Vibe-Coded Apps Riddled With Exploitable Security Flaws

Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.

Security Week by Kevin Townsend
JUL22
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}"). "The filename parameter is concatenated into

The Hacker News by info@thehackernews.com (The Hacker News)
JUL22
The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. According to McKinsey's State of AI report, 76 percent of employees now use AI in some capacity at work, up from 55

The Hacker News by info@thehackernews.com (The Hacker News)
JUL22
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models were operating with "reduced cyber refusals for evaluation purposes" that might otherwise limit their ability to

The Hacker News by info@thehackernews.com (The Hacker News)
JUL22
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.

Security Week by Eduard Kovacs
JUL22
Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on

The Hacker News by info@thehackernews.com (The Hacker News)
JUL22
Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation

Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek.

Security Week by Ionut Arghire
JUL22
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates

Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.

Security Week by Eduard Kovacs
JUL22
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek.

Security Week by Eduard Kovacs
JUL22
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face 

OpenAI says its AI models went rogue, as CISOS call the incident a watershed moment, warning that autonomous AI threat models have officially crossed into production reality. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek.

Security Week by Eduard Kovacs
JUL22
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA)

The Hacker News by info@thehackernews.com (The Hacker News)
JUL22
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the

The Hacker News by info@thehackernews.com (The Hacker News)
JUL21
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had

The Hacker News by info@thehackernews.com (The Hacker News)