News

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Government AI platform deal sparks outrage The Defense Department’s recent award…

Read More

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Most of the 2,500 organizations believed to have been affected by the LiteLLM supply chain attack were actually exposed before, SOCRadar reports. The compromise was blamed on and claimed by TeamPCP, the threat actor behind multiple open source software (OSS) supply chain attacks involving the Shai-Hulud worm. It started with Aqua Security’s Trivy scanner and propagated downstream to multiple packages and repositories in a ripple effect fueled by the malware’s worm-like behavior and by the…

Read More

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

Google Cloud has published an updated roadmap for migrating its infrastructure to post-quantum cryptography (PQC), targeting full readiness by 2029, with some work expected to continue into the next decade. In March, Google announced it was moving up its timeline for transitioning to PQC, setting a 2029 target after faster-than-expected advances in quantum hardware and error correction. The tech giant announced this week that the plan, built around its own Quantum Threat Model, organizes work…

Read More

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

Twenty-one cybersecurity-related merger and acquisition (M&A) deals were announced in July 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report. Here are some of the most important cybersecurity M&A deals announced in July 2026:    Bank of America to acquire MDSec Bank of America announced plans to acquire UK-based information security consultancy MDSec Consulting Limited. MDSec provides technical information security consulting services and employs roughly…

Read More

SharePoint Vulnerability Exploited Shortly After PoC Release

A SharePoint vulnerability patched last month is now being exploited in the wild, with the attacks starting shortly after the release of a proof-of-concept (PoC) exploit. The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates. Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network. “Exploiting this vulnerability could allow an attacker to disclose files and modify data,” Microsoft…

Read More

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS). These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an…

Read More

OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

OpenAI has flagged its upcoming AI model, Astra, for potentially reaching a ‘critical’ cybersecurity risk threshold, prompting the company to suspend internal development activities that lack newly mandated security controls. Recent internal evaluations of Astra revealed massive leaps in its agentic coding and cybersecurity abilities.  Under OpenAI’s Preparedness Framework, a model hits the ‘critical’ tier if it can autonomously build zero-day exploits against hardened, real-world systems. It also qualifies if the AI can independently design…

Read More

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

DEF CON — Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session.  Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input. Rovo functions as an AI layer spanning Jira, Confluence, Bitbucket, and third-party tools such as Slack,…

Read More

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  OpenAI disrupts Cambodia scam network abusing ChatGPT OpenAI banned a coordinated…

Read More

Vishing Extortion Group UNC6671 Rebrands After Making Millions

UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports. The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks. Mainly focusing on Microsoft 365 and Okta infrastructure,…

Read More