SecurityWeek today announced the launch of the Critical Impact Awards, a new recognition program honoring the individuals, organizations, and technologies delivering measurable impact and contributions in industrial cybersecurity. Winners will be announced live at the 2026 ICS Cybersecurity Conference, taking place October 6–8, 2026, at the W Nashville, as the event celebrates its 25-year anniversary. Unlike pay-to-play ..
Categoria : Security
A recently discovered piece of malware abuses the Microsoft 365 calendar for command-and-control (C&C) communication, Group-IB reports. Dubbed HollowGraph, the malware is believed to be part of a larger toolkit and is likely linked to Cavern Manticore, an Iran-nexus threat actor that Check Point detailed earlier this month. The malware’s communication mechanism relies on the ..
Korber AG is the holding company of a diverse German technology and manufacturing organization with around 13,000 employees in 100 locations around the world. “Take Pharma,” comments Andreas Gaetje. “Probably every vaccine you ever received has been through our machines.” Korber services companies that supply consumers. So, despite its size and importance, it is rarely ..
Cosmetics giant Estée Lauder has started notifying employees that their information was stolen from its Oracle E-Business Suite (EBS) instance last year. The incident, the company says, occurred in early August 2025, when the infamous Cl0p cybercrime group started exploiting CVE-2025-61882, a zero-day vulnerability in Oracle EBS that enabled unauthenticated remote code execution (RCE), to ..
A security researcher says he has received a significant bug bounty from Meta after discovering a critical vulnerability that exposed customer support data. The vulnerability was discovered and reported to Meta in January 2026 by independent researcher Rony K Roy. The initial report to the social media giant described a security hole of limited severity, ..
Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information. Discovered on July 4, the incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts. Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged ..
Una vulnerabilità critica nella piattaforma AI di ServiceNow consente a un attaccante non autenticato di eseguire codice da remoto e prendere il controllo dell’istanza. Identificata come CVE-2026-6875 , è passata dalla pubblicazione del proof of concept tecnico ai primi payload osservati in rete in circa 72 ore, e la finestra di esposizione per chi gestisce ..
This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets the Standard for Campus Drone Security.” SkySafe is a leader in drone detection, airspace intelligence, ..
Purple teaming nasce per chiudere un cortocircuito che la sicurezza offensiva si porta dietro da sempre. Il red team entra, dimostra che si poteva entrare, consegna un report. Il blue team lo legge, corregge qualcosa, e l’esercizio si esaurisce lì. Quello che quasi mai accade è la verifica sistematica di una domanda diversa e più ..
The Coca-Cola Company stated a dairy company it owns (fairlife, LLC), has suspended production in the United States due to a cyberattack. After a user gained unauthorized access to parts of its systems, including production-related operations, the organization was forced to temporarily suspend operations. Outside cybersecurity experts have been called upon by the organization to ..


