News

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

The Linux Foundation said Tuesday it will take on governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open specification for producing verifiable evidence of how AI agents and other confidential workloads run.  Contributed by confidential computing vendor OPAQUE, the specification was developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII). TRACE creates a hardware-backed, cryptographically verifiable record that ties together the runtime environment, the software executed, the policies applied,…

Read More

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited. ReliaQuest revealed on August 17 in a post on X that it had been tracking a widespread ShinyHunters phishing campaign involving domains with the ‘company.claims’ URL pattern.  The company also warned that the hacker gang has been expanding its social engineering tactics to include legal team impersonation alongside IT and help…

Read More

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Cybersecurity companies this week shared information about new and updated banking trojans targeting users worldwide. These types of malware can enable their operators to phish credentials, steal sensitive user data, and remotely control compromised devices.  Manic ThreatFabric has detailed Manic, described as an Android malware that combines banking trojan and spyware capabilities.  The malware has mainly been used against Ukraine, including banks, government services, and messaging applications. However, it has also been observed targeting Russian…

Read More

Former NSA Director Paul Nakasone Launches National Security Advisory Firm

Retired U.S. Army General Paul M. Nakasone, former director of the National Security Agency and commander of U.S. Cyber Command, has launched a boutique national security advisory firm. The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. “After more than three decades in uniform — including leading U.S. Cyber Command and the National Security Agency — I’ve seen how quickly the threats…

Read More

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  CISA warns of actively exploited Ray vulnerability  CISA has mandated that…

Read More

Hackers Target Zimbra Servers in Active Exploitation Campaign

A recently patched Zimbra Collaboration vulnerability is being exploited in the wild, according to Poland’s CERT Polska. The security hole is tracked as CVE-2026-73570 and it was patched by the developers of the enterprise email server and collaborative software suite with the release of version 10.1.20, announced on July 20. The high-severity flaw exists when the optional ‘zimbra-snmp’ package is installed and SNMP notifications are enabled.  An attacker can exploit the vulnerability without authentication to…

Read More

Virtual Event Today: CodeSecCon – Secure Your Code and Applications

Join more than 1,500 registered attendees today for CodeSecCon, the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. Designed to address the most pressing challenges in software security, CodeSecCon empowers attendees to: Develop Secure Applications: Learn best practices for secure coding and application design. Reduce Software Vulnerabilities: Discover innovative tools and techniques to minimize risks. Enhance Collaboration: Bridge the gap between security and development teams to foster…

Read More

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks

Rethinking Cyber Defense for AI-Speed Attacks | August 18, 2026 at 1PM ET- Register to Attend Artificial intelligence is fundamentally changing cybersecurity. As patch-to-exploit timelines shrink and attackers move at machine speed, long-standing security models are being put to the test. Can detection-first security operations keep pace, or is it time to rethink prevention as the strongest default? Join Jason Kikta, Chief Technology Officer at Automox, Dmitri Alperovitch, Co-Founder and Chairman of Silverado Policy Accelerator,…

Read More

680,000 Impacted by French Tax Authority Data Breach

France’s Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. The incident was disclosed after a threat actor boasted on a hacking forum about accessing DGFiP’s internal systems and exfiltrating data. According to DGFiP, the threat actor accessed its systems in June and July, and the unauthorized access was suspended immediately upon detection. However, the public tax authority did not discover evidence of data exfiltration at the time. Last…

Read More

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Government AI platform deal sparks outrage The Defense Department’s recent award…

Read More