Security Week
230 briefings written from Security Week's reporting, newest first. Each is a plain-language summary written here for Australian business, with a link to the original.
- Weekly Roundup: Microsoft Cloud Fixes, Dropbox Account Breach, and a Billion-Dollar Security Startup
- HPE Fixes Critical Flaws in AOS-CX Switch Software
- OpenAI Commits $1 Billion to Help Critical Infrastructure Defenders Use AI
- Sangoma Switchvox Phone Systems Under Active Attack — Patch Now
- 12-Year-Old PostgreSQL Flaw Could Let Attackers Hijack Your Database and Server
- Startup Catch Raises $5M to Build AI Executive Assistant With Built-In Security Guardrails
- Critical VMware Flaws Could Let Attackers Break Out of Virtual Machines
- Google Fixes Sixth Chrome Zero-Day Flaw of 2026 – Update Now
- Nvidia's $13 Billion Hugging Face Acquisition Signals Bigger Bets on Open-Source AI
- 8.8 Million Records Exposed After Airport Group Refuses Ransom Demand
- New 'Circuit Breaker' Tech Aims to Stop AI Agents Going Rogue
- AI Security Startup HiddenLayer Lands $100M to Protect AI Systems in Real Time
- New Startup Launches 'Firewall' to Guard Against Risky AI Agents
- 153 Million Driver's License Scans Reportedly for Sale on Dark Web
- Critical Flaw in Popular WordPress Migration Plugin Puts 3 Million Sites at Risk
- Cisco Flags Unpatched Email Encryption Flaws, Rushes Fixes for Critical Switch Bugs
- New Tool Adds a Human Safety Net to AI Agent Actions
- UK Moves to Ban Risky Tech Vendors from Critical Infrastructure
- Rockwell Automation Fixes Over a Dozen Security Flaws in Industrial Software
- New Cleo Harmony Vulnerability: Exploit Code Now Public
- Anthropic Rolls Out New Safeguards After AI Security Incidents
- Hackers Hijack Internet Routing to Push Fake Virtualizor Update
- OpenAI's 'Astra' Model Marks a New Milestone in AI-Driven Cyber Risk
- Chrome and Firefox Roll Out Critical Security Updates — Update Now
- Decades-Old Sality Botnet Finally Taken Down
- SonicWall Warns of Two Zero-Day Flaws Under Active Attack in SMA1000 Devices
- Palo Alto Networks Expands AI Capabilities with Acquisition of Console
- New AI-Powered Defense Tool Aims to Counter AI-Speed Cyberattacks
- US Coast Guard Launches Dedicated Office for Maritime Cybersecurity Policy
- AI Tools Can Speed Up Industrial Exploit Development, Researchers Warn
- Critical Langflow Flaw Under Active Attack — Patch Now
- Five Plead Guilty in ATM 'Jackpotting' Scheme in the US
- Ransomware Group Claims Breach of US Healthcare Provider Nutex Health
- Critical JFrog Artifactory Flaw Under Active Attack — Patch Now
- 9.5 Million Affected in Major Healthcare Data Breach at Aesto Health
- Critical Flaws Found in WatchGuard Firewalls — Patch Now
- CISA Warns: PaperCut Vulnerabilities Now Under Active Attack
- Vulnerability Found in Kaspersky Endpoint Security Now Patched
- ServiceNow Fixes Three Critical Flaws That Could Let Attackers Hijack Systems
- Healthcare Giant McKesson Confirms Data Breach Amid Extortion Threat
- AI Agents Need Guardrails: Lessons from the Hugging Face Access Incident
- Anthropic Alerts Claude Users to Infostealer Malware Risk
- Critical Ruby on Rails Flaw Under Active Attack — Patch Now
- Medical Device Giant Boston Scientific Still Reeling From Cyberattack
- Extortion Group Claims Massive Data Theft from Manchester Airports Group
- Judge Slams Pentagon's 'Illegal' Blacklisting of AI Firm Anthropic
- Ransomware Gang Rhysida Demands Ransom From Berlin Government — City Refuses to Pay
- PaperCut Issues Second Emergency Patch as Attackers Exploit Print Management Software
- Toy Giant Hasbro Confirms Employee Data Exposed in Cyberattack
- Weekly Roundup: Log4j Scare Resurfaces, Iranian Hacker Sanctions, and Other Security News
- US Firearms Agency ATF Confirms Cyberattack Amid Ransomware Group's Claims
- AI Agents Used to Exploit Linux Kernel Flaw on OpenAI's Own Systems
- Tech Giants Join Forces to Fight AI-Powered Cyberattacks
- Why 'Country of Origin' Labels Don't Tell the Whole AI Story
- PaperCut Rushes Out Emergency Fix for Actively Exploited Security Flaw
- US Order Targets Hidden Backdoors in Power Grid Equipment
- Two Alleged Hackers Charged in Australia After US-Australia Cybercrime Investigation
- AI Agents Learn to Say 'No': OpenAI Tightens Trust Rules After Hugging Face Incident
- Okta's Strong Earnings Signal Rising Demand for AI Identity Security
- From Naval Officer to CISO: Why Trust Is the Real Job in Cybersecurity Leadership
- Cyberattack on Medical Device Giant Boston Scientific Disrupts Global Operations
- Why AI-Powered Cybersecurity Tools Are Only as Good as Their Data
- US Authorities Take Down Chinese Hacking-for-Hire Platform Linked to Military and Infrastructure Attacks
- Pro-Russian Hacker Group Claims Cyberattack on Norway's Public Digital Services
- Urgent: Citrix NetScaler Flaw Under Active Attack — Patch Now
- AI Helps Hackers Write Malware Faster—But Not Better, Study Finds
- Adobe and Nvidia Release Critical Security Updates — Patch Now
- CISA Warns: Over 100 Water Systems Hit in Cyberattacks Linked to Iran
- MFA Isn't a Silver Bullet: Why Multi-Factor Authentication Can Still Let Attackers In
- Google Fixes Over 300 Security Flaws in Latest Chrome Update
- Nutex Health Reports Data Breach Involving Unauthorized Access
- CISA Alerts Businesses to Actively Exploited Gitea Vulnerability
- Linux Foundation to Oversee New Open Standard for Verifying AI System Security
- AI Safety Firm Alice Raises $140M to Strengthen Enterprise AI Defenses
- Critical Login Bypass Flaws Found in Popular WordPress SSO Plugin
- WhatsApp Boosts Account Security with Multiple Passkeys and Caller ID Alerts
- Hands-On Cyber-Physical Systems Training Returns for ICS Security Professionals
- New Malware Targets Car Infotainment Systems, Feeds Global Botnet
- When Software Fixes Go Quiet: Why 'Silent Patches' Put Businesses at Risk
- Taiwan Charges Nine, Including Nvidia and Super Micro Staff, Over Illegal AI Server Exports to China
- CISA Warns of Active Exploitation of Oracle WebLogic Vulnerability
- Cybersecurity Firm ReliaQuest Hit by Phishing Attack, Says Damage Was Contained
- The CISO's Hidden Challenge: Hired for Security, Judged on Business Results
- Uber Hit with Nearly $1 Billion GDPR Fine Over Automated Account Suspensions
- Spring Framework Sees Surge in Security Patches: 91 Flaws Fixed This Year
- Venezuelan National Sentenced to Record 8 Years for ATM 'Jackpotting' Scheme
- Apollo Global Data Breach Exposes Personal Information
- AI Is Speeding Up Cyberattacks - Why Patching Alone Won't Save Your Business
- Iran-Linked Hackers Knock UK Power Plant Offline for Four Days
- TikTok to Pay $400 Million in US Settlement Over Children's Privacy Violations
- Anthropic Widens Access to AI Security Tool, Commits $35M to Open Source Defenders
- Banking Trojans on the Rise: What Small Businesses Should Know About Manic, Grandoreiro and ToxicPanda 2.0
- Former NSA Chief Launches Advisory Firm for Cyber and Geopolitical Risk
- Weekly Roundup: T-Mobile's Physical Response to Hackers, Threema DDoS, and More
- New Attack Technique Tricks AI Chatbots Into Ignoring Safety Rules
- New Phishing Toolkit Turns Passkeys Against You—Even After You Reset Your Password
- Critical Flaw in 'Isolated-vm' Tool Could Let Attackers Take Over Host Systems
- North Korean Hackers Linked to Malicious Rust Software Package
- Defense Contractors Feel Ready for CMMC—But Can They Prove It?
- Microsoft Releases 22 New Security Patches — Update Now
- CISA Warns Businesses to Urgently Patch Exploited TrueConf Software Flaws
- Active Attacks Target Zimbra Email Servers via Newly Disclosed Flaw
- Understanding Digital Surveillance: What Businesses Should Know
- Hackers Compromise 14,000 IP Cameras in Russia and Ukraine
- Atlassian and Splunk Release Fixes for Dozens of Serious Security Flaws
- Critical MLflow Flaw Being Exploited to Steal Cloud Credentials
- Cisco Fixes Critical Security Flaws in Crosswork and Secure Workload Products
- AI Tool Helps Viasat Strengthen Satellite Security After 2022 Russian Cyberattack
- OpenAI Tightens AI Model Security After Recent Incidents
- Critical Citrix NetScaler Flaw Lets Attackers Bypass Login — Patch Now
- Critical GitLab Vulnerability Under Active Attack — Patch Immediately
- AI-Powered Attacks Target Siemens Industrial Control Systems in Critical Infrastructure
- CodeSecCon: Free Virtual Event Focuses on Building Safer Software
- AI Security Startup Prevalent AI Secures $22 Million Funding Boost
- US Charges 17 Iranian Hackers, Offers $10 Million for Information Leading to Arrests
- Cl0p Ransomware Gang Exposes 40+ Victims in Major Software Exploit Campaign
- Urgent: Patch Now — Microsoft, VMware and Apple Flaws Under Active Attack
- Oracle Releases Massive Security Update With 943 Patches
- Google and Mozilla Release Critical Security Updates for Chrome and Firefox
- CareCloud Data Breach Now Affects 3.7 Million People, Far More Than First Reported
- Webinar Explores Whether Cybersecurity Can Keep Up With AI-Speed Attacks
- From Self-Taught Hacker to AI Security Leader: A Career Built on Curiosity
- Why 'Patch Everything Eventually' No Longer Works Against Today's Cyber Threats
- Startup Xpander Secures $7.5M to Help Businesses Manage AI Agents Safely
- Fortinet Buys Virtue AI to Strengthen AI Security Offerings
- WordPress Form Plugin Flaw Puts 300,000 Sites at Risk of Takeover
- Heights Finance Data Breach Exposes Details of 1.2 Million People
- Critical GitLab Flaw Let Attackers Tamper With Data Without Logging In
- Apple Patches Dozens of WebKit Flaws in Latest macOS and iOS Updates
- French Tax Authority Breach Exposes Data of 680,000 People
- How a Simple Naming Mistake Let AI Models Target a Real Company
- AI Testing Reveals Risk: Claude Agents Deployed Self-Replicating Malware Under Conflicting Instructions
- SafePal Data Breach Exposes Details of 40,000 Customers
- Hackers Exploit macOS Screen Sharing Flaw to Hijack Systems for Crypto Mining
- SAP Commerce Cloud Under Attack Just Days After Critical Flaw Disclosed
- Hackers Claim Massive Data Theft from Microsoft Azure, Targeting Major Global Brands
- Weekly Roundup: Rapid7 Cuts Jobs, Boeing 737 Hack Demoed, and Refrigeration Systems Found Vulnerable
- Security Scanner Bug, Not LiteLLM, Behind Breach Affecting 2,500 Organisations
- Google Cloud Charts Path to Quantum-Safe Security by 2029
- RingCentral Data Breach May Have Exposed 1.6 Million Users' Personal Information
- Beacon CRM Breach Exposes Data from Over 1,000 Charities
- Trezor Warns 14,000 Customers After Data Breach at Shipping Partner ShipMonk
- Hackers Actively Exploiting Unpatched Flaw in GeoServer Software
- New macOS Malware 'AmnesiaStealer' Targets Passwords and Browser Data
- Cybersecurity Industry Consolidates: 21 M&A Deals Announced in July 2026
- Hackers Move Fast: Adobe Commerce Flaw Exploited Right After Patch Release
- WordPress Patch Fixes Serious Remote Code Execution Flaw
- Cybersecurity Investment Surges as Team8 Raises $365 Million
- Fortinet Fixes Critical Login Flaws in FortiWeb and FortiManager
- White House Enlists Private Security Firms to Fight Foreign Cybercrime Gangs
- Critical VMware vCenter Flaw Now Being Actively Exploited
- New Windows Zero-Day 'ShieldBreak' Lets Attackers Gain Full System Control
- Microsoft SharePoint Flaw Under Active Attack After Exploit Code Goes Public
- AI Security Startup Mindgard Secures $30 Million in Funding
- WhatsApp Rolls Out Scam Alerts as Signal Boosts Key Verification
- New 'City-Forum' Attacks Exploit Guest Access in Salesforce and ServiceNow
- Cyberattack Disrupts Global Logistics Giant Ceva, Delaying Shipments Across Europe
- Intel and AMD Patch Over 80 Security Flaws in Latest Updates
- Supply Chain Attack on LiteLLM Hits Over 2,500 Organizations
- North Korean Hackers Exploit New Windows Zero-Day to Seize Control of Victim Systems
- Ivanti Patches Remotely Exploitable Flaws in Endpoint Manager
- Industrial Equipment Makers Patch Security Flaws — Here's What Businesses Should Know
- SonicWall Fixes Critical Flaws in Discontinued Management Platform
- Cisco Fixes Actively Exploited Firewall Flaw That Can Knock Devices Offline
- Microsoft's August Patch Tuesday Fixes 421 Flaws — Including One Under Active Attack
- Adobe Sounds Alarm on Critical Flaws in ColdFusion and Campaign Classic
- Zoom Fixes Serious Flaw That Let Meeting Attendees Hack Other Participants
- AI Governance Isn't an IT Problem—It's a Leadership Problem
- SAP Issues Urgent Patches for Critical Security Flaws
- New US Initiative Aims to Shield Water Utilities From Cyberattacks
- Cybersecurity Startup Corma Secures $60 Million to Build Defensive AI Tools
- Malicious Chrome Extension Sneaks Back Into Web Store After Ban
- From WannaCry Hero to Cautionary Tale: The Marcus Hutchins Story
- OpenAI Launches GPT-5.6-Cyber to Boost Cybersecurity Defences
- Mozilla Replaces Firefox Signing Key After Accidental Public Exposure
- OpenAI's Next AI Model Could Enable Fully Autonomous Cyberattacks, Experts Warn
- New Startup Aims to Close Security Gaps in AI Cloud Infrastructure
- Cisco Flags High-Severity Flaws in ClamAV Antivirus Software—Exploit Code Already Public
- 'Ghostjacking': How Hackers Trick AI Security Tools by Poisoning Their Own Logs
- Iran-Linked Hackers Widen Attacks on US Water Systems
- Metabase Rushes Out Patch After Hackers Exploit Flaw as Zero-Day
- Hackers Used a New 'Private Network' Trick to Sabotage Polish Energy Facility
- Urgent Patch Alert: Actively Exploited Flaw Found in Progress LoadMaster Software
- Levi Strauss Confirms Data Theft After Social Engineering Attack
- Critical Security Flaws Found in Widely Used Belgian eID Software
- One-Click Flaw in Atlassian's Rovo AI Could Have Exposed Business Data
- Weekly Roundup: Low-Quality AI Bug Reports, Port Cyberattacks, and Wall Street Targeted by Hackers
- Voice Phishing Extortion Gang Rebrands Multiple Times After Making Millions
- Truck Brake Recall Quietly Fixed Hidden Cybersecurity Flaws
- Black Hat USA 2026: What SMBs Should Know About the Latest Cybersecurity Product Announcements
- Microsoft and Apple Roll Out Critical Security Patches — Update Now
- Data Breach at Unlimited Technology Systems Exposes 3.8 Million People's Personal and Health Data
- Google Releases Chrome 151 Update to Fix Critical Security Flaws
- Snowflake Hacker Pleads Guilty in US Court
- AI Browsers Can Be Hijacked Without a Single Click, Researchers Warn
- Why Ticking Compliance Boxes Won't Stop Cyberattacks
- Critical Flaw in Paperclip Software Could Have Let Attackers Seize Admin Control
- Meta's AI Went Rogue During a Security Test — What SMBs Should Know
- Ransomware Kingpin Sentenced to 16 Years in Prison
- Cisco Issues Urgent Patches for Critical Networking Vulnerabilities
- Critical JetBrains TeamCity Flaw Now Under Active Attack
- Researchers Uncover $50,000 Exploit Chain Targeting Samsung Phones via Bixby
- Black Hat USA 2026: What SMBs Should Know About the Latest Cybersecurity Vendor Announcements
- Cyber Warfare Is Reshaping Global Conflict — Here's Why That Matters to Businesses
- Passkeys Aren't Foolproof: New Malware Attacks Target Google's Synced Passkeys
- Data Breach at Brown Health Medical Group Exposes Information of 311,000 People
- New Industry Alliance Sets Ground Rules for Sharing AI Security Incidents
- AI Models Behaving Badly: Report Flags Rogue Behaviour from Anthropic and OpenAI Systems
- US Cyber Agency Warns: Attackers Actively Exploiting Flaws in Popular Business Software
- Massive Supply Chain Attack Hits Over 400 NPM Software Packages
- Cyberattacks Reportedly Strike Water Utilities Across at Least 12 US States
- Black Hat USA 2026: Cybersecurity Vendors Unveil Latest Innovations
- Why Traditional Security Tools Aren't Enough to Manage AI Risk
- Cybersecurity Firm Oligo Secures $60 Million to Boost Runtime Security Tools
- Why Passion, Not Perfection, Keeps CISOs Going: Lessons from Ping Identity's Security Chief
- AI Email Assistants Could Become Tools for Hackers, Researchers Warn
- AI Security Startup Zenity Secures $125 Million to Expand Protection for Business AI Tools
- Cybersecurity Startup Obsidian Secures $85M to Tackle AI Agent Risks
- 15 Security Flaws Found in TP-Link Omada Networking Gear
- Security Flaw in Google's Gemini AI Agent System Could Expose Secrets
- Old Server Hardware Flaw Leaves Thousands of Data Centers Exposed
- Data Breach at Madera Community Hospital Exposes Info of 150,000 People
- Microsoft Pays Out $20 Million to Security Researchers in Bug Bounty Program
- New York Invests $9 Million to Shore Up Cybersecurity at 153 Water Utilities
- Black Hat USA 2026: What Small Businesses Should Know About the Latest Security Product Announcements
- Visa Acquires Fraud-Detection Firm BioCatch in $2.4 Billion Deal
- Cyberattack Strikes Liechtenstein's Corporate Ownership Register
- River Bank Confirms Hackers Deleted Data Stolen in June Ransomware Attack
- Cybersecurity Firm Horizon3 Secures $250 Million to Expand Growth
- N-able Rushes Out Fix After Hackers Bypass Patch for N-central Servers