CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.
Continue reading CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
Continue reading AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on S… Continue reading US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.
The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek.
Continue reading Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.
The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek.
Continue reading Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.
The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek.
Continue reading Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation