News

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  OnTrac hacked Parcel delivery company OnTrac is notifying customers after attackers…

Read More

CareCloud Data Breach Impacts Over 350,000

Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it. On June 24, the investigation determined that personal, financial, and medical information…

Read More

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco on Wednesday announced patches for an actively exploited zero-day vulnerability affecting its Secure Firewall Management Center (FMC) product. The security hole, tracked as CVE-2026-20316, has been described as a static credential issue. Specifically, an attacker can leverage default credentials for a low-privilege user account to log into vulnerable devices and access sensitive data. Cisco assigned a ‘high severity’ rating to the vulnerability, noting that it can be chained with other FMC flaws to escalate…

Read More

Cyera Acquiring Oasis Security in $1 Billion Deal

Data security company Cyera announced on Tuesday that it has entered into an agreement to acquire agentic access management provider Oasis Security. Cyera confirmed to SecurityWeek multiple reports that this is a $1 billion deal. Calcalist reported that roughly $700 million will be paid in cash, with the remainder in shares.  Oasis has developed a non-human identity and agentic access governance platform to address the growing use of AI agents in enterprise environments. Its Agentic…

Read More

Origin Energy Data Breach Affects 900,000 Australians

Australian power company Origin Energy Limited said the recent data breach affects 900,000 current and former customers. Origin Energy, which has roughly 4.8 million customers, is one of Australia’s largest electricity and gas retailers.  The company recently started investigating a cybersecurity incident and determined that threat actors gained access to customer data, including names, dates of birth, phone numbers, addresses, account information, and partial payment card or bank account numbers.  In an update shared on…

Read More

MCBS Data Breach Affects 1.2 Million Individuals

A data breach suffered last year by Atlanta-based medical business management company MCBS (Medical Computer Business Services) affects more than 1.2 million individuals. According to a data breach notification posted on its website, MCBS was targeted by hackers in September 2025.  An investigation showed that attackers had access to its systems between September 22 and September 26, potentially stealing files that contained personal information such as name, address, SSN, date of birth, health insurance information,…

Read More

Rockwell Patches Code Execution Flaws in Arena Simulation Software

Rockwell Automation has patched four vulnerabilities in its Arena Simulation software that could let an attacker execute arbitrary code on an affected system, according to advisories published by CISA and Rockwell. Arena Simulation is a discrete-event simulation software that provides organizations with a virtual environment to model, visualize, and test complex operational workflows, allowing them to identify issues and evaluate process changes before implementing them in production. The four high-severity flaws — CVE-2026-8085, CVE-2026-8312, CVE-2026-8313,…

Read More

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Dolphin X malware leverages AI to profile victims  Varonis Threat Labs…

Read More

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

Zenity Labs has found and disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents, which it names AgentForger; a tailored cross-site request forgery (CSRF). With a single successful phish, an unsuspecting employee could be tricked into launching an invisible autonomous agent that is remotely controlled by the attacker. Zenity explains in two blogs (Part 1 and Part 2) that the vulnerability was in ChatGPT’s Agent Builder allowing an over permissive parameter. Researchers found that the…

Read More

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Hackers have stolen tens of millions of records from AI music generator Suno and gig-work platform Paidwork, according to data breach notification service Have I Been Pwned (HIBP). Suno was targeted in November 2025, and the intrusion came to light earlier this month, when 404 Media reported that hackers had obtained source code and user data.  The stolen source code revealed that Suno had been scraping music and podcasts from major platforms such as Deezer,…

Read More