Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) appeared first on SecurityWeek.
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
The three most serious:
An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5
A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused for later users’
How AI-powered phishing killed blocklists for good
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
The new dead drop resolver approach, observed in two trojanized npm package “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield.
The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek.
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Hackers stole personal information, medical records, and financial information from the organization’s server.
The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.
