The MFA Identity Trap: When Authentication Creates a False Sense of Security
Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop.
The post The MFA Identity Trap: When Authentication Creates a False Sense of Security appeared first on SecurityWeek.
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests
The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an
Chrome 152 Patches Over 300 Vulnerabilities
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.
The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
The accounts “were being used to promote the International Burke Institute (IBI), a
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
“The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups,” INTERPOL said.
“These groups are
Sensitive Information Exposed in Nutex Health Data Breach
Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration.
The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek.
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across
