Attackers have been uploading PHP webshells to WordPress sites through a critical flaw in a third-party WooCommerce plugin, four months after a fix was released. In a technical write-up published on September 14, Wordfence said its firewall had blocked more than… Read More "PHP Webshell Campaign Targets WordPress Through Critical WooCommerce P"
The Ultimate Vendor Risk Management Guide For Healthcare
The healthcare industry stores an abundance of sensitive information and relies on third-party vendors for critical business services, two factors that make the sector a prime target for cyber attacks. In 2022, 707 data breaches compromised 500 or more patient… Read More "The Ultimate Vendor Risk Management Guide For Healthcare"
Virtual Event Today: Attack Surface Management Summit
SecurityWeek’s 2026 Attack Surface Management Summit takes place today from 11AM-3PM as a fully immersive virtual event. Join a large community of cyber defenders as we explore how organizations can identify, understand, and reduce risk across an increasingly complex digital… Read More "Virtual Event Today: Attack Surface Management Summit"
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Swati KhandelwalSep 16, 2026Artificial Intelligence / Software Security Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended… Read More "Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories"
CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have issued final guidance for protecting cloud identity tokens and assertions from theft, forgery and misuse, aimed at federal agencies, cloud service providers and… Read More "CISA and NIST Issue Guidance to Protect Cloud Identity Tokens"
What is a Third-Party Risk Assessment in Cybersecurity?
A third-party risk assessment pulls vendor risk data to help cybersecurity teams understand how to best mitigate supplier risks. Though the field of Third-Party Risk Management (TPRM) is evolving to prioritize compliance, security, and supply chain risk, third-party risk assessments… Read More "What is a Third-Party Risk Assessment in Cybersecurity?"
AIUC Raises $40 Million to Certify Enterprise AI Agents
AIUC (Artificial Intelligence Underwriting Company) has announced raising $40 million in a Series A funding round that brings the total raised by the company to $55 million. The investment round was led by Ribbit Capital, with additional support from First… Read More "AIUC Raises $40 Million to Certify Enterprise AI Agents"
Threat Intelligence Alone Won’t Close the Exploitation Gap
The Hacker NewsSep 16, 2026Threat Intelligence / Security Validation A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have… Read More "Threat Intelligence Alone Won’t Close the Exploitation Gap"
Reducing Supply Chain Security Risks with Vendor Segmentation
Security teams often spend the same assessment effort on a commodity SaaS tool as they do on a critical enterprise resource planning integration. That mismatch leaves high-exposure suppliers under-watched while low-stakes vendors consume the queue. Vendor segmentation isolates which third… Read More "Reducing Supply Chain Security Risks with Vendor Segmentation"
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google on Tuesday informed Pixel phone owners that it has patched a zero-day vulnerability exploited in targeted attacks. The zero-day is tracked as CVE-2026-58704, and Google said it’s aware of “limited, targeted exploitation”. The vulnerability has been rated high severity… Read More "Pixel Modem Zero-Day Exploited in Targeted Attacks"