CyberSecure Specialist

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

The INC Ransomware group is responsible for most of the recent activity surrounding two fresh vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, Resecurity reports. Tracked as CVE-2026-15409 (CVSS score of 10) and CVE-2026-15410 (CVSS score of 7.2), the security defects allow unauthenticated remote attackers to open a WebSocket tunnel to restricted services and escalate their privileges to root. Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same…

Read More

This month in security with Tony Anscombe – July 2026 edition

OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup 31 Jul 2026 With July coming to a close, ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past month and offers insights that they may hold for your own cyber-defenses. Here’s some of what caught Tony’s attention this month:…

Read More

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

Cybersecurity investment management startup Balance Theory has raised $19 million in Series A funding to expand its platform for helping CISOs evaluate and manage security spending. Balance Theory’s platform is designed to bring cybersecurity investment planning, market intelligence and execution into a single system. It maintains contextual information about an organization’s security program, supplements it with proprietary market data, and employs AI agents and automated workflows to support purchasing and portfolio-management decisions. As the company…

Read More

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  OnTrac hacked Parcel delivery company OnTrac is notifying customers after attackers…

Read More

Beyond the screenshot: Why you should verify what you see

Digital Security The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine Phil Muncaster 30 Jul 2026  •  , 6 min. read Someone sends you a screenshot showing that a payment has gone through. It carries the right logo, amount, timestamp and transaction status. Yet the money never arrives. What passes for proof today can generally be very different from just a few years ago. Screenshots, often…

Read More

CareCloud Data Breach Impacts Over 350,000

Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it. On June 24, the investigation determined that personal, financial, and medical information…

Read More

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro Falé…

Read More

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in…

Read More

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco on Wednesday announced patches for an actively exploited zero-day vulnerability affecting its Secure Firewall Management Center (FMC) product. The security hole, tracked as CVE-2026-20316, has been described as a static credential issue. Specifically, an attacker can leverage default credentials for a low-privilege user account to log into vulnerable devices and access sensitive data. Cisco assigned a ‘high severity’ rating to the vulnerability, noting that it can be chained with other FMC flaws to escalate…

Read More

Cyera Acquiring Oasis Security in $1 Billion Deal

Data security company Cyera announced on Tuesday that it has entered into an agreement to acquire agentic access management provider Oasis Security. Cyera confirmed to SecurityWeek multiple reports that this is a $1 billion deal. Calcalist reported that roughly $700 million will be paid in cash, with the remainder in shares.  Oasis has developed a non-human identity and agentic access governance platform to address the growing use of AI agents in enterprise environments. Its Agentic…

Read More