A vulnerability in OpenSSL could allow attackers to cause a server’s memory to be exhausted before any security handshake, Okta’s red team discovered. Referred to as HollowByte, the denial-of-service (DoS) bug could be triggered via a malicious payload of only 11 bytes that declares a larger incoming message body to trigger a buffer pre-allocation that ..
Categoria : Security
A longtime cybersecurity executive has built a website that tracks disclosed material breaches, aiming to give cybersecurity professionals, journalists, policymakers, and everyday citizens a resource that doesn’t currently exist. The tracker was created by Richard Bird, who is currently Chief Strategy and Chief Security Officer at enterprise AI governance company Singulr AI. He previously held ..
Professional services giant Ernst & Young (EY) has started notifying its clients that their personal and financial information was compromised in a data breach. The incident was discovered on April 23 and involved a third-party service management platform that EY uses to support tax-related work it performs on behalf of its clients. “Support tickets submitted ..
SecurityWeek’s 2026 Cloud & Data Security Summit took place as a virtual event on July 15th. All sessions are now available to watch on demand for a limited time. Access the virtual conference center to learn the latest strategies, tools, and best practices for strengthening your cloud security posture and staying ahead of evolving cyber ..
Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source. Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner. “We designed VulnHunter with a developer-first mindset to ..
Machine learning collaboration platform Hugging Face has disclosed a data breach resulting from a cyberattack conducted by an autonomous AI agent. The attack targeted the company’s production infrastructure and resulted in unauthorized access to internal datasets and to service credentials. According to Hugging Face, a data-processing pipeline was used as the entry point, followed by ..
At the age of 18, Hannah Behnke took her first step into the security world in a classic way: she got a job as a “mall cop.” While she had an interest in criminal justice at the time, with many family members involved in the field, she recalls that the primary reason she took the ..
Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities. The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google. Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; ..
Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light. The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030. According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. ..
Protocolli ICS è il nome collettivo dei linguaggi con cui i sistemi di controllo industriale impartiscono ordini al mondo fisico: aprire una valvola, far girare un motore, leggere la temperatura di un reattore. Sono protocolli come Modbus, DNP3, EtherNet/IP, e condividono una caratteristica che continua a sorprendere chi viene dalla sicurezza informatica: non sono insicuri ..


