Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > threat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

14+ min ago   (621+ words) Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. A threat actor has conducted a mass-hacking campaign against Dahua IP cameras, compromising over 14,000 of them across Ukraine and Russia, Hunt.io reports. The activity,…...

SecurityWeek
securityweek.com > atlassian-splunk-patch-dozens-of-critical-high-severity-vulnerabilities

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

1+ hour ago   (452+ words) The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. Atlassian and Splunk this week announced patches for over 250 vulnerabilities across their products, including dozens of critical- and high-severity flaws. On Tuesday, Atlassian published a…...

SecurityWeek
securityweek.com > mlflow-vulnerability-exploited-for-cloud-credential-theft

MLflow Vulnerability Exploited for Cloud Credential Theft

1+ hour, 15+ min ago   (445+ words) The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. Threat actors have been exploiting a recent MLflow vulnerability to steal sensitive information, including credentials and secrets. An open source AI engineering platform, MLflow…...

SecurityWeek
securityweek.com > cisco-patches-critical-crosswork-secure-workload-vulnerabilities

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

1+ hour, 38+ min ago   (476+ words) The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. Cisco on Wednesday announced patches for 15 vulnerabilities across its products, including critical- and high-severity flaws in Crosswork and Secure Workload. Crosswork version 7.2.1-SP was released with…...

SecurityWeek
securityweek.com > ai-assisted-tool-helped-secure-satellite-communication-system-after-2022-russian-hacking

AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking

2+ hour, 9+ min ago   (675+ words) Atalanta’s Argo product is now being used to prove the resilience of Viasat’s satellite communications network. On the same day it invaded Ukraine in 2022, Russia disabled thousands of satellite modems across Ukraine and other European countries, aiming to disrupt communications....

SecurityWeek
securityweek.com > openai-overhauls-model-security-with-sandboxing-30-minute-alerts-and-training-pauses

OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

2+ hour, 44+ min ago   (535+ words) The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. OpenAI has detailed new containment and continuous monitoring protocols for its AI research, introducing stricter isolation and a…...

SecurityWeek
securityweek.com > exploitation-expected-for-critical-authentication-bypass-patched-in-citrix-netscaler

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

4+ hour, 20+ min ago   (468+ words) Citrix on Wednesday announced patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical-severity flaw. The critical bug, tracked as CVE-2026-19490 (CVSS score of 9.3), is described as an authentication bypass using an alternative path, and impacts NetScaler…...

SecurityWeek
securityweek.com > critical-gitlab-flaw-exploited-shortly-after-disclosure

Critical GitLab Flaw Exploited Shortly After Disclosure

5+ hour, 38+ min ago   (525+ words) CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. Tracked as CVE-2026-19478 (CVSS score of 9.4), the code injection defect was patched on August 17, when GitLab warned that it could be exploited remotely without authentication....

SecurityWeek
securityweek.com > hackers-using-ai-to-target-siemens-plcs-in-critical-us-sectors

Hackers Using AI to Target Siemens PLCs in Critical US Sectors

6+ hour, 15+ min ago   (597+ words) A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies. According to the NSA, CISA, FBI, EPA, and DOE, the hackers are scanning the internet to identify exposed PLCs and developing exploits…...

SecurityWeek
securityweek.com > cisa-urges-immediate-patching-of-exploited-microsoft-vmware-apple-vulnerabilities > amp

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

22+ hour, 59+ min ago   (452+ words) The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday called for the immediate patching of four vulnerabilities in Microsoft, VMware, and Apple products that have…...