News

Beacon Security Raises $13 Million for Security Data Platform

Cybersecurity startup Beacon Security has announced raising $13 million in a seed funding round led by Notable Capital. AlphaDrive Ventures, Holly Ventures, Jefferies Family Office, SVCI, and dozens of angel investors also participated in the investment round. Based in New York, Beacon was founded in 2024 by IDF veterans Gal Tal-Hochberg (CEO), Or Mattatia (CPO), and Iddo Israely (CTO). Beacon is providing organizations with a agentic security data platform that enables defenders to prevent, detect,…

Read More

Legacy Systems, Real-World Impacts: The Reality of OT Security

I’m here today to write about one particularly thorny area of operational technology (OT) and security that I run into somewhat routinely. Given my own particular interests as an incorrigible vulnerability-gazer, and my professional role as vice president of security research at runZero, I deal with OT security issues more often than the average bear. I’ve noticed that there’s definitely a vibe of, “IT be like this, but OT be like that” going on in…

Read More

Unpatched Cursor Vulnerability Exposes Users to Code Execution

An unpatched vulnerability in Cursor on Windows can be triggered for code execution when a developer opens a repository in the application, Mindgard reports. Cursor is one of the most popular AI-assisted development environments, with more than 7 million active users. The security defect, Mindgard says, is straightforward: when opening a repository, Cursor would automatically execute a malicious git.exe binary in the project’s root without warning the user or asking for approval. “The vulnerability is…

Read More

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft on Tuesday announced patches for a record-breaking 622 vulnerabilities, including two bugs in Active Directory and SharePoint Server that have been exploited in the wild as zero-days. Tracked as CVE-2026-56155, the exploited AD flaw affects Federation Services (AD FS) and could allow attackers to elevate their privileges locally to administrator. Also leading to privilege escalation, the SharePoint Server flaw is tracked as CVE-2026-56164 and can be exploited over the network without authentication. Another security…

Read More

Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption

Jesse McGraw isn’t a hacker; at least, not by his own definition. He accepts he was a hacker, and a blackhat hacker, and that he still retains the mindset of a hacker. But he is no longer a hacker, he says. Early days He realized he was a hacker while in high school. “My one and only friend was a hacker, and I had never seen anything like what he did.” Before then, McGraw had…

Read More

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Threat actors are abusing the GitHub API to systematically enumerate organizations, repositories, and user accounts, Datadog reports. Spanning multiple overlapping campaigns, the activity has been ongoing for several months, relying on ghost accounts that were registered two to five years ago but left dormant. The activity, Datadog says, involves automated scanners, the abuse of leaked credentials, and coordinated networks of dormant accounts. While the observed GitHub API requests are targeting publicly available data, blending with…

Read More

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Armenian man pleads guilty in the US to ransomware attacks Karen…

Read More

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang

Another cybersecurity expert from the United States, accused of helping a cybercrime gang while working as a ransomware negotiator, has been sentenced to prison. Angelo Martino, 41, of Florida, was sentenced on Thursday to 70 months in prison after he pleaded guilty in April.  Martino is one of the three individuals charged by US authorities last year over their role in ransomware attacks. The three men worked at cybersecurity firms, and two of them served…

Read More

QIZ Security Raises $17 Million for Cryptographic Governance Platform

Israeli startup QIZ Security announced on Thursday that it has raised $17 million in seed funding for its cryptographic posture and post-quantum cryptography (PQC) management platform. The funding round was led by Bessemer Venture Partners and Merlin Ventures, with participation from Evolution Equity Partners, Qbeat Ventures, Singtel Innov8, and Qino Cyber Capital.  The investment will be used to accelerate the company’s growth and enhance its platform. QIZ Security has developed a platform designed to help…

Read More

Accenture Confirms Data Breach After Hacker Claims Source Code Theft

Professional services giant Accenture confirmed a data breach after a hacker claimed the theft of internal source code from the company. The incident came to light this week, when a threat actor boasted on the hacker forum PwnForums about compromising Accenture and stealing 35 gigabytes of data. According to the hacker, the information, including Azure access keys and tokens, configuration files, RSA and SSH keys, and source code, was exfiltrated from Accenture earlier this month.…

Read More