Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.
The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption.
The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities appeared first on SecurityWeek.
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028.
The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.
The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek.
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.
The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek.
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.
The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek.
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek.