Security news.
Today's security landscape is heavily influenced by the accelerating use of AI in cyberattacks, with multiple reports highlighting AI's role in developing exploits, automating device control, and facilitating sophisticated social engineering. Alongside this, several critical vulnerabilities and data breaches underscore the ongoing need for robust patching and proactive defense strategies across diverse platforms and services.
Brevo Supply Chain Attack Injects Malware into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker, injecting malicious scripts into customer websites and impacting a large number of sites.
Critical Check Point Flaw Lets Hackers Execute Code with Root Privileges
Check Point has released security updates for a critical vulnerability allowing unauthenticated attackers to execute code with root privileges on management systems.
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138, an unauthenticated remote code execution flaw in Orkes Conductor, is actively being exploited via inline workflow definitions.
23 Million User Records Compromised in Gyazo Data Breach
Helpfeel, maker of the Gyazo image upload service, reported a breach affecting 23 million user records due to a vulnerability in its image upload server.
WeaselBiscuit Stealer Spreads via 13 npm Packages
Cybersecurity researchers found 13 npm packages delivering the new JavaScript stealer "WeaselBiscuit," which harvests Chrome extension storage and shows functional overlaps with DPRK-linked malware.
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Researchers demonstrated access to OpenAI employee accounts by leveraging an AI-built exploit and a sign-in flaw, earning a bug bounty.
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft addressed numerous vulnerabilities across Azure and AI-branded products, with privilege escalation flaws constituting the majority of fixes.
NightmareStresser DDoS Service Disrupted in International Operation
Law enforcement agencies successfully disrupted NightmareStresser, one of the longest-running DDoS-for-hire services globally, active since at least 2022.