News

Security Week
securityweek. com > underminr-vulnerability-lets-attackers-hide-malicious-connections-behind-trusted-domains

Underminr" Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

1+ day, 13+ hour ago  (595+ words) The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. Threat actors are exploiting a vulnerability in shared content delivery network (CDN) infrastructure to hide connections to malicious domains. Dubbed Underminr,…...

Symbols: ncsc-nl,nasdaq:eose,btc-usd,nginx-ui
Security Week
securityweek. com > drupal-vulnerability-in-hacker-crosshairs-shortly-after-disclosure

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

2+ day, 7+ hour ago  (587+ words) Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. Drupal is warning users that it's already seeing attempts to exploit CVE-2026-9082, the highly critical vulnerability patched…...

Security Week
securityweek. com > in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking

In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking

2+ day, 10+ hour ago  (411+ words) Other noteworthy stories that might have slipped under the radar: CISA contractor exposes credentials, Mythos testing and new features, Huawei router flaw triggered telecom blackout. Here are this week's highlights: Iranian hackers suspected in US gas station tank monitor breaches…...

Symbols: rpv-16
Security Week
securityweek. com > canadian-man-arrested-for-operating-kimwolf-botnet

Canadian Man Arrested for Operating Kimwolf Botnet

2+ day, 12+ hour ago  (545+ words) Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges. The US Justice Department announced on Thursday that a Canadian man has been arrested for operating the recently disrupted Kimwolf DDo S…...

Symbols: cert-fr,aic.sh
Security Week
securityweek. com > first-vpn-cybercrime-service-disrupted-administrator-arrested

First VPN" Cybercrime Service Disrupted, Administrator Arrested

2+ day, 15+ hour ago  (515+ words) The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. Authorities in North America and Europe have participated in a law enforcement operation to disrupt First VPN, a popular cybercrime service used…...

Symbols: btc-usd,eth-usd
Security Week
securityweek. com > trendai-patches-apex-one-zero-day-exploited-in-the-wild

Trend AI Patches Apex One Zero-Day Exploited in the Wild

2+ day, 16+ hour ago  (508+ words) CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. Trend AI, Trend Micro's enterprise business, has informed customers that it has patched another Apex One vulnerability that has been exploited in the…...

Symbols: cwe-20
Security Week
securityweek. com > grafana-says-codebase-and-other-data-stolen-via-tanstack-supply-chain-attack

Grafana Says Codebase and Other Data Stolen via Tan Stack Supply Chain Attack

2+ day, 16+ hour ago  (517+ words) Hackers accessed Grafana's Git Hub repositories after a token compromised in the Tan Stack attack was not rotated. Grafana this week revealed that the unauthorized access to the Grafana Labs Git Hub repositories disclosed earlier this month was the result…...

Symbols: nyse:path
Security Week
securityweek. com > cisco-patches-critical-vulnerability-in-secure-workload

Cisco Patches Critical Vulnerability in Secure Workload

3+ day, 12+ hour ago  (458+ words) Insufficient validation and authentication in the Secure Workload's REST APIs provide remote attackers with Site Admin privileges. Cisco on Wednesday announced patches for a critical-severity vulnerability in Secure Workload that could allow attackers to access site resources with Site Admin…...

Security Week
securityweek. com > ocean-emerges-from-stealth-with-28m-for-agentic-email-security-platform

Ocean Emerges From Stealth With $28 M for Agentic Email Security Platform

3+ day, 12+ hour ago  (375+ words) The company has developed a platform that uses specialized AI agents to inspect every incoming message. Ocean emerged from stealth mode this week with $28 million in funding for its agentic email security platform. The funding came from Lightspeed Venture Partners,…...

Symbols: btc-usd
Security Week
securityweek. com > apple-rejected-2-million-app-store-submissions-in-2025-for-security-and-fraud-prevention

Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

3+ day, 13+ hour ago  (568+ words) The company blocked over 1. 1 billion accounts and $2. 2 billion in potentially fraudulent transactions. Apple rejected over 2 million applications from entering the App Store in 2025 and blocked over 1. 1 million fraudulent accounts from being created. These actions, a result of AI use combined…...

Symbols: 700-H0,nasdaq:aapl,nasdaq:rblx