News

Vishing Extortion Group UNC6671 Rebrands After Making Millions

UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports. The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks. Mainly focusing on Microsoft 365 and Okta infrastructure,…

Read More

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

AI security company Zenity has disclosed the details of two AI browser hacking techniques targeting Claude in Chrome and ChatGPT Atlas, demonstrating how they can be used for account takeovers, phishing, and making unauthorized Amazon purchases. Zenity described its research in two separate blog posts published on Wednesday, one covering the ChatGPT Atlas research and one covering the Claude in Chrome attack. ChatGPT Atlas hacking Zenity researchers discovered that OpenAI’s agentic browser, ChatGPT Atlas, is…

Read More

311,000 Impacted by Brown Health Medical Group-MA Data Breach

Lifespan Physician Group of Massachusetts, doing business as Brown Health Medical Group-MA, is notifying over 311,000 individuals that their personal, medical, and financial information was stolen in a data breach. The incident occurred in December 2025 at its Hawthorn location. It involved a historic file server, the healthcare organization says in a sample notification letter filed with the Massachusetts Office of Consumer Affairs and Business Regulation. While the practice’s electronic health record system was not…

Read More

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

Pillar Security discovered an agent-to-agent attack method in Google’s Agent Development Kit for Python that could lead to secret exposure and pull request (PR) poisoning. The google/adk-python repository had two classes of automated AI agents, namely low-privileged ones open to user interaction, and high-privileged ones accessible only to maintainers. An attacker could manipulate the low-privileged, public-facing agent to pass a prompt to the high-privileged one, gaining access to restricted capabilities, including command execution, and potentially…

Read More

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

The INC Ransomware group is responsible for most of the recent activity surrounding two fresh vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, Resecurity reports. Tracked as CVE-2026-15409 (CVSS score of 10) and CVE-2026-15410 (CVSS score of 7.2), the security defects allow unauthenticated remote attackers to open a WebSocket tunnel to restricted services and escalate their privileges to root. Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same…

Read More

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

Cybersecurity investment management startup Balance Theory has raised $19 million in Series A funding to expand its platform for helping CISOs evaluate and manage security spending. Balance Theory’s platform is designed to bring cybersecurity investment planning, market intelligence and execution into a single system. It maintains contextual information about an organization’s security program, supplements it with proprietary market data, and employs AI agents and automated workflows to support purchasing and portfolio-management decisions. As the company…

Read More

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  OnTrac hacked Parcel delivery company OnTrac is notifying customers after attackers…

Read More

CareCloud Data Breach Impacts Over 350,000

Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it. On June 24, the investigation determined that personal, financial, and medical information…

Read More

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco on Wednesday announced patches for an actively exploited zero-day vulnerability affecting its Secure Firewall Management Center (FMC) product. The security hole, tracked as CVE-2026-20316, has been described as a static credential issue. Specifically, an attacker can leverage default credentials for a low-privilege user account to log into vulnerable devices and access sensitive data. Cisco assigned a ‘high severity’ rating to the vulnerability, noting that it can be chained with other FMC flaws to escalate…

Read More

Cyera Acquiring Oasis Security in $1 Billion Deal

Data security company Cyera announced on Tuesday that it has entered into an agreement to acquire agentic access management provider Oasis Security. Cyera confirmed to SecurityWeek multiple reports that this is a $1 billion deal. Calcalist reported that roughly $700 million will be paid in cash, with the remainder in shares.  Oasis has developed a non-human identity and agentic access governance platform to address the growing use of AI agents in enterprise environments. Its Agentic…

Read More