South Korean startup platform breach exposes key management failures
Hired for One Job, Judged on Another: The CISO’s Real Problem
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job.
The post Hired for One Job, Judged on Another: The CISO’s Real Problem appeared first on SecurityWeek.
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
Dutch data protection authorities have fined Uber nearly $1 billion, saying the ride-hailing company used automated software to suspend driver accounts, sometimes permanently, with no human review to check for mistakes. The Dutch Data Protection Authority said Friday it is imposing a fine of 825 million euros ($964 million) because Uber violated the EU’s General […]
The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts appeared first on SecurityWeek.
Microsoft: August updates break printing, PDF export in WPF apps
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
91 Vulnerabilities Patched in Spring Application Framework
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.
The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek.
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate
