News

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

Zenity Labs has found and disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents, which it names AgentForger; a tailored cross-site request forgery (CSRF). With a single successful phish, an unsuspecting employee could be tricked into launching an invisible autonomous agent that is remotely controlled by the attacker. Zenity explains in two blogs (Part 1 and Part 2) that the vulnerability was in ChatGPT’s Agent Builder allowing an over permissive parameter. Researchers found that the…

Read More

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Hackers have stolen tens of millions of records from AI music generator Suno and gig-work platform Paidwork, according to data breach notification service Have I Been Pwned (HIBP). Suno was targeted in November 2025, and the intrusion came to light earlier this month, when 404 Media reported that hackers had obtained source code and user data.  The stolen source code revealed that Suno had been scraping music and podcasts from major platforms such as Deezer,…

Read More

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

President Donald Trump has signed an executive order requiring the Department of War to develop new rules for mapping and securing critical defense supply chains, including the software, services and technology used in national security systems. While primarily focused on domestic sourcing of critical materials, the executive order contains several provisions relevant to cybersecurity teams, particularly those responsible for software supply chain security, third-party risk and defense contractor compliance. The order states that the United…

Read More

Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

American-Israeli cybersecurity startup Neo emerged from stealth mode on Monday with $100 million in funding for a platform that enables enterprises to control and secure AI software. Neo received the investment across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. The company will use the money to grow its engineering and go-to-market teams.  Neo’s platform serves as a control layer that governs AI agents, AI-enabled applications,…

Read More

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Dutch authorities eye local actors in Odido telecom breach Law enforcement…

Read More

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

[embedded content] In this exclusive SecurityWeek interview, Brian “SchleiF” Schleifer sits down with Clint Bodungen, Director of AI/ML Engineering at Arcovo, founder of ThreatGen, and one of the industry’s leading voices in industrial cybersecurity. Together they tackle why traditional governance often fails practitioners, how cybersecurity has evolved over the past two decades, and why the biggest vulnerability is still people not technology. Clint also shares, for the first time publicly, the story behind the MindStone…

Read More

Beacon Security Raises $13 Million for Security Data Platform

Cybersecurity startup Beacon Security has announced raising $13 million in a seed funding round led by Notable Capital. AlphaDrive Ventures, Holly Ventures, Jefferies Family Office, SVCI, and dozens of angel investors also participated in the investment round. Based in New York, Beacon was founded in 2024 by IDF veterans Gal Tal-Hochberg (CEO), Or Mattatia (CPO), and Iddo Israely (CTO). Beacon is providing organizations with a agentic security data platform that enables defenders to prevent, detect,…

Read More

Legacy Systems, Real-World Impacts: The Reality of OT Security

I’m here today to write about one particularly thorny area of operational technology (OT) and security that I run into somewhat routinely. Given my own particular interests as an incorrigible vulnerability-gazer, and my professional role as vice president of security research at runZero, I deal with OT security issues more often than the average bear. I’ve noticed that there’s definitely a vibe of, “IT be like this, but OT be like that” going on in…

Read More

Unpatched Cursor Vulnerability Exposes Users to Code Execution

An unpatched vulnerability in Cursor on Windows can be triggered for code execution when a developer opens a repository in the application, Mindgard reports. Cursor is one of the most popular AI-assisted development environments, with more than 7 million active users. The security defect, Mindgard says, is straightforward: when opening a repository, Cursor would automatically execute a malicious git.exe binary in the project’s root without warning the user or asking for approval. “The vulnerability is…

Read More

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft on Tuesday announced patches for a record-breaking 622 vulnerabilities, including two bugs in Active Directory and SharePoint Server that have been exploited in the wild as zero-days. Tracked as CVE-2026-56155, the exploited AD flaw affects Federation Services (AD FS) and could allow attackers to elevate their privileges locally to administrator. Also leading to privilege escalation, the SharePoint Server flaw is tracked as CVE-2026-56164 and can be exploited over the network without authentication. Another security…

Read More