SecurityWeek
VerifiedOnline/Digital
SecurityWeek helps cybersecurity professionals do their jobs better by providing timely news, information, analysis and insights from experts in the trenches. Source
Actions
Media Outlet details
| Scope | International |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesCyera Acquiring Oasis Security in $1 Billion Deal
Data security company Cyera announced on Tuesday that it has entered into an agreement to acquire agentic access management provider Oasis Security. Cyera confirmed to SecurityWeek multiple reports that this is a $1 billion deal. Calcalist reported that roughly $700 million will be paid in cash, with the remainder in shares. Oasis has developed a non-human identity and agentic access governance platform to address the growing use of AI agents in enterprise environments.
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify the file system, bypass security, add contacts without authorization, spoof the UI, and escalate privileges.
OT Security Startup Frenos Raises $1.52 Million
AI-native OT security startup Frenos today announced raising $1.52 million in a seed funding round extension that brings the total raised by the company to $6.4 million. The new investment round was led by Momenta and Exposition Ventures, with additional support from Riptide Ventures. Frenos will use the new funding to expand its customer success team and to grow its AI R&D.
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
Microsoft has unveiled its first cybersecurity AI model, MAI-Cyber-1-Flash, which the company claims got significantly better results in finding vulnerabilities than its main competitors. MAI-Cyber-1-Flash, designed to identify challenging vulnerabilities in complex code, has been integrated into Microsoft’s MDASH multi-agent vulnerability identification and remediation harness.
Act Security Emerges from Stealth to Fight the Patch Problem
Keeping pace with new CVEs resulting from AI vulnerability discovery is a constant and losing battle. Founded in 2025, Tel-Aviv Israel based Act Security has emerged from stealth with total funding of $60 million. The funding comprises a $20 million Seed round led by Team8 and Bessemer Venture Partners (with participation from Hetz Ventures and Claltech); and a $40 million Series A round led by Notable Capital (with participation from Startpoint Capital and SVCI).
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so.
Hush Security Raises $30 Million for AI Agent Governance
Cybersecurity startup Hush Security today announced raising $30 million in a Series A funding round that brings the total raised by the company to $41 million. The fresh investment came from Akamai Technologies and previous backers Battery Ventures and YL Ventures. Founded in 2024, Tel Aviv-based Hush Security emerged from stealth in September 2025 with a machine access platform that enables organizations to securely control enterprise AI agents and their underlying infrastructure.
Google Adopts New Threat Actor Naming System
Google has announced that Google Threat Intelligence Group (GTIG) is adopting a new cryptonym-based naming convention for tracking threat actors. According to the internet giant, the schema moves away from sequential numbers and disparate identifiers, relying instead on two-word combinations for each activity cluster. The first word, Google explains, is a unique and memorable term that may have been used in public reporting and which is meant to represent the threat actor.
Unpatched Fastjson Vulnerability Exploited in Attacks
Threat actors have been exploiting a critical-severity remote code execution (RCE) vulnerability in Fastjson, security researchers warn. A popular JSON processing library for Java, Fastjson was developed by Alibaba for JSON serialization and deserialization. Tracked as CVE-2026-16723 (CVSS score of 9), the unauthenticated bug impacts all deployments running as a Spring Boot executable fat-jar, which is the most widely used deployment model.
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Arista Networks on Monday released patches for a critical-severity OS injection vulnerability in the VeloCloud Orchestrator (VCO) centralized management platform, warning that it has been exploited in the wild as a zero-day. The security defect is tracked as CVE-2026-16812, has a maximum CVSS score of 10, and could be exploited remotely to access privileged functionality intended for internal use only.