Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.
Continue reading Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
Continue reading SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. 
The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek.
Continue reading ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.
The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek.
Continue reading China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek.
Continue reading Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities