Critical Isolated-vm Vulnerability Leads to RCE on Host
A critical-severity type confusion in the isolated-vm Node.js library could allow threat actors to achieve remote code execution (RCE) on the host system. Through isolated-vm,…
A critical-severity type confusion in the isolated-vm Node.js library could allow threat actors to achieve remote code execution (RCE) on the host system. Through isolated-vm,…
Cybersecurity companies this week shared information about new and updated banking trojans targeting users worldwide. These types of malware can enable their operators to phish…
iAuthFlow V2 is a new phishing toolkit demonstrating the rapidly improving sophistication of phishing techniques. iAuthFlow V2 is a malware toolkit first seen on a…
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader…
Retired U.S. Army General Paul M. Nakasone, former director of the National Security Agency and commander of U.S. Cyber Command, has launched a boutique national…
Researchers at Adversa AI discovered a new attack technique and named it Cryptographic Context Injection. They reported their findings to xAI on June 3, 2026,…
North Korean hackers are responsible for a new open source software (OSS) supply chain attack targeting the Rust ecosystem, cybersecurity firm Wiz reports. The attack…
Atlassian and Splunk this week announced patches for over 250 vulnerabilities across their products, including dozens of critical- and high-severity flaws. On Tuesday, Atlassian published…
A threat actor has conducted a mass-hacking campaign against Dahua IP cameras, compromising over 14,000 of them across Ukraine and Russia, Hunt.io reports. The activity,…
A recently patched Zimbra Collaboration vulnerability is being exploited in the wild, according to Poland’s CERT Polska. The security hole is tracked as CVE-2026-73570 and…
The US this week announced charges against 17 members of the Iran-based company Mabna Institute for hacking into hundreds of organizations in the US and…
AI-powered data fabric company Prevalent AI today announced raising $22 million in growth funding from Integrity Growth Partners (IGP). Founded in 2017 by former GCHQ…