Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > former-nsa-director-paul-nakasone-launches-national-security-advisory-firm

Former NSA Director Paul Nakasone Launches National Security Advisory Firm

57+ min ago   (418+ words) Retired U.S. Army General Paul M. Nakasone, the former director of the National Security Agency and commander of U.S. Cyber Command, has launched a boutique national security advisory firm. Nakasone serves as founder and chairman of the firm, while former Defense Digital Service…...

SecurityWeek
securityweek.com > in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

1+ hour, 57+ min ago   (571+ words) Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. Here are this week’s highlights: CISA warns of actively exploited Ray vulnerability GitHub says vulnerability found by autonomous Wiz agent not…...

SecurityWeek
securityweek.com > new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

2+ hour, 47+ min ago   (597+ words) Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. iAuthFlow V2 is a new phishing toolkit demonstrating the rapidly improving sophistication of phishing techniques. iAuthFlow V2 is a malware toolkit first…...

SecurityWeek
securityweek.com > encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

2+ hour, 47+ min ago   (709+ words) Researchers at Adversa AI discovered a new attack technique and named it Cryptographic Context Injection. They reported their findings to xAI on June 3, 2026, and attempted to coordinate disclosure on August 4 and August 10. At the time of writing, they had received…...

SecurityWeek
securityweek.com > critical-isolated-vm-vulnerability-leads-to-rce-on-host

Critical Isolated-vm Vulnerability Leads to RCE on Host

4+ hour, 41+ min ago   (578+ words) The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. A critical-severity type confusion in the isolated-vm Node.js library could allow threat actors to achieve remote code execution (RCE) on the host system....

SecurityWeek
securityweek.com > rust-supply-chain-attack-linked-to-north-korean-hackers > amp

Rust Supply Chain Attack Linked to North Korean Hackers

7+ hour, 15+ min ago   (514+ words) Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. North Korean hackers are responsible for a new open source software (OSS) supply chain attack targeting the Rust ecosystem, cybersecurity firm…...

SecurityWeek
securityweek.com > contractors-cmmc-confidence-rises-as-ability-to-prove-it-falls-behind

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

8+ hour, 40+ min ago   (758+ words) Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. Two industry surveys released this week paint a consistent picture of the defense industrial base: contractors say they’re more confident in…...

SecurityWeek
securityweek.com > microsoft-rolls-out-22-fresh-security-patches

Microsoft Rolls Out 22 Fresh Security Patches

8+ hour, 54+ min ago   (456+ words) Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products. Most of the patches address critical and high-severity flaws in Microsoft Azure, Entra ID, Exchange, Fabric, and Partner Center products. The most severe…...

SecurityWeek
securityweek.com > cisa-urges-immediate-patching-of-exploited-trueconf-vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

9+ hour, 59+ min ago   (577+ words) The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The US cybersecurity agency CISA on Thursday warned federal agencies that threat actors have been exploiting two vulnerabilities in TrueConf. A secure on-premises video conferencing…...

SecurityWeek
securityweek.com > hackers-target-zimbra-servers-in-active-exploitation-campaign

Hackers Target Zimbra Servers in Active Exploitation Campaign

1+ day, 2+ hour ago   (386+ words) Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. A recently patched Zimbra Collaboration vulnerability is being exploited in the wild, according to Poland’s CERT Polska. The security hole is tracked as CVE-2026-73570 and it…...