SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant...
A compromised JavaScript file distributed through advertising technology provider Adform was used by attackers to secretly replace cryptocurrency wallet addresses on websites, potentially redirecting payments to...
A critical security vulnerability in the open-source Ruflo artificial intelligence platform could allow unauthenticated attackers to execute commands remotely, steal sensitive credentials, and manipulate AI memory...
Amazon Threat Intelligence has linked the 2025 hijacking of popular npm packages debug and chalk to a North Korean cyber threat group, marking a major shift...
A coordinated cyberattack targeted more than 30 community water systems across Minnesota, prompting a statewide cybersecurity response after several utilities experienced operational disruptions, including one water...
A newly disclosed security vulnerability in Cisco Secure Firewall Management Center (FMC) Software is being actively exploited, prompting U.S. cybersecurity authorities to issue urgent warnings and...
Broadcom has released emergency security updates to address multiple vulnerabilities affecting VMware products, including vCenter Server, ESXi, Workstation, and Fusion. Three of the vulnerabilities have been...
A critical security vulnerability in the Ruby on Rails framework could allow unauthenticated attackers to access sensitive files from application servers by uploading specially crafted image...
Cybersecurity experts have uncovered a new wave of attacks linked to the Cl0p ransomware group, with threat actors exploiting critical vulnerabilities in internet-facing PTC Windchill and...
A sophisticated online advertising campaign is using a new malware delivery method that allows victims’ own web browsers to assemble malicious Windows files, making traditional detection...
July 26, 2026 — Cybersecurity experts are warning developers and organizations to take immediate action after attackers began exploiting a critical remote code execution (RCE) vulnerability...
Recent Comments