News

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Microsoft releases cloud patches Microsoft has released patches for nine vulnerabilities…

Read More

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are tracked together under single CVEs. Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The critical security defects are rooted…

Read More

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations,…

Read More

OpenLeash Adds a Human Check to Risky AI Agent Actions

AI Agents can be incredibly useful, but their autonomous actions can be incredibly dangerous if not adequately controlled. Max Brin is developing a product he describes as an ‘AV for AI’. The analogy with antivirus can be a little confusing since this product is nothing like a traditional antivirus – but the designation is at least well-known, and the purpose of protecting networks from software mishaps is well understood by security practitioners. The name of…

Read More

Palo Alto Networks Acquires AI Agent Platform Console

Palo Alto Networks (NASDAQ: PANW) on Tuesday announced that it has acquired Console, an AI-native platform designed to help organizations build agentic workflows and automate operational tasks using natural language. The cybersecurity giant said Console will deepen the agentic capabilities of its Cortex platform, allowing security teams to investigate signals, prioritize work, and automatically take action across enterprise environments. Console’s technology enables users to describe an operational objective in natural language, with AI agents then…

Read More

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws.  The researcher started dropping zero-days after growing frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits remained at the PoC stage, a few ended up being…

Read More

Hasbro Data Breach Exposed Employee Personal Information

Toy and game giant Hasbro is notifying employees that their personal information may have been compromised in a data breach. The notifications sent to affected individuals contain little detail, but they indicate that the exposed information, which varies by individual, may include names, email addresses, postal addresses, phone numbers, national ID numbers, and financial information.  The information comes from notification letters that Hasbro submitted to the Massachusetts Attorney General’s Office.  It’s unclear how many individuals…

Read More

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Developers say Log4j vulnerability alert overblown An Apache Log4j 2 vulnerability…

Read More

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed suffering a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency. In a statement on its website, ATF said the incident affected a standalone system, which was disconnected after the intrusion was discovered.  “The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF…

Read More

Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

President Trump issued Executive Order 14420 on Wednesday, declaring a national emergency to mitigate vulnerabilities in the United States’ bulk power system arising from foreign-supplied electrical equipment. The order attributes the heightened emergency status to rapid growth across data centers, AI, advanced manufacturing, and defense production.  Officials noted that dependence on grid reliability magnifies the impact of foreign supply chain disruptions or targeted attacks that exploit built-in backdoors for remote access. The order covers critical…

Read More