SecurityWeek
VerifiedOnline/Digital
SecurityWeek helps cybersecurity professionals do their jobs better by providing timely news, information, analysis and insights from experts in the trenches. Source
Actions
Media Outlet details
| Scope | International |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesAnthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
The CEO of Anthropic said Saturday the artificial-intelligence industry should slow its fast-moving development to give safety measures time to catch up. Without such a slowdown, Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet.
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it on August 28. Within days, several other Chinese threat actors started using it, but the activity might not be exclusive to China-aligned groups.
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Anthropic says Claude users in northern Yemen, territory controlled by Iran-backed Houthi rebels, tried to use the AI model to develop advanced missiles. AI is already transforming warfare from Ukraine to Gaza, and its use on a rugged and remote battlefield is likely to increase concerns about its rapid spread. Anthropic said the users of the accounts, which it blocked after identifying them, did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.
Phishing Research Challenges Conventional Security Awareness Testing
The message is simple: fine-tune future in-house phishing simulation tests through the findings and analysis of Pistachio’s research. Pistachio was founded in Oslo Norway in 2019, with additional offices in London and Valencia. It specializes in automated human risk management, employee security awareness training, and phishing simulations. Between 1 June, 2025 and 31 May, 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees in more than 1,200 organizations.
GitLab Vulnerability Exploited One Day After Disclosure
Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns. Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that can allow unauthenticated users to read arbitrary files from the GitLab server. All Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked. The incident involved the marketing platform Brevo, which Trezor uses for newsletters. Brevo said an attacker exploited how it handles SAML Single Sign-On (SSO) to access 138 accounts.
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
A United States court sentenced Ukrainian national Oleksii Oleksiyovych Lytvynenko to four years in prison this week for his role in the Conti ransomware operation. Lytvynenko, 44, was arrested in Ireland in 2023 and extradited to the United States in late 2025. He pleaded guilty to wire fraud in June 2026, admitting to helping the Conti group develop malware and possessing stolen victim data. He faced up to 20 years in prison.
Check Point Patches Critical VPN Vulnerabilities
Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality. Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns.
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Kiteworks has announced the acquisition of AI data security company Bonfy.AI, a move aimed at extending real-time policy enforcement over sensitive data exchanged by both human users and AI agents. Kiteworks delivers a content-sharing platform to safeguard sensitive data as it moves across enterprise networks, external organizations, and internal systems. It includes regulatory compliance, governance, and audit tracking.