A security researcher says he has received a significant bug bounty from Meta after discovering a critical vulnerability that exposed customer support data. The vulnerability was discovered and reported to Meta in January 2026 by independent researcher Rony K Roy. The initial report to the social media giant described a security hole of limited severity, ..
Categoria : Security
Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information. Discovered on July 4, the incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts. Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged ..
Una vulnerabilità critica nella piattaforma AI di ServiceNow consente a un attaccante non autenticato di eseguire codice da remoto e prendere il controllo dell’istanza. Identificata come CVE-2026-6875 , è passata dalla pubblicazione del proof of concept tecnico ai primi payload osservati in rete in circa 72 ore, e la finestra di esposizione per chi gestisce ..
This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets the Standard for Campus Drone Security.” SkySafe is a leader in drone detection, airspace intelligence, ..
Purple teaming nasce per chiudere un cortocircuito che la sicurezza offensiva si porta dietro da sempre. Il red team entra, dimostra che si poteva entrare, consegna un report. Il blue team lo legge, corregge qualcosa, e l’esercizio si esaurisce lì. Quello che quasi mai accade è la verifica sistematica di una domanda diversa e più ..
The Coca-Cola Company stated a dairy company it owns (fairlife, LLC), has suspended production in the United States due to a cyberattack. After a user gained unauthorized access to parts of its systems, including production-related operations, the organization was forced to temporarily suspend operations. Outside cybersecurity experts have been called upon by the organization to ..
Hugging Face, a host platform for AI models and datasets, confirmed it had experienced a data breach. Furthermore, the organization asserted the breach had been carried out entirely by an AI agent. “We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services,” the platform stated in ..
American-Israeli cybersecurity startup Neo emerged from stealth mode on Monday with $100 million in funding for a platform that enables enterprises to control and secure AI software. Neo received the investment across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. The company will use the money ..
Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before patches were released, according to cybersecurity firm Volexity. SonicWall released a public advisory for the vulnerabilities on July 14, informing customers that CVE-2026-15409 and CVE-2026-15410 had been exploited in the wild. Remote, unauthenticated attackers can exploit the flaws to hack SMA1000 ..
Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cyber security group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for example, the ..


