Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The incident occurred on April 20 and did not affect customer data in the company’s production and staging environments.

A malicious version of the plugin was published to the Jenkins Marketplace late last week.

Tens of thousands of students studying for final exams around the world have regained access to a key online learning system after a cyberattack had earlier knocked it offline.

Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released.

The second iteration of the German-speaking online crime marketplace had over 22,000 users and more than 100 sellers.

Victims span across the aviation, critical infrastructure, energy, logistics, public administration, and technology sectors.

Other noteworthy stories that might have slipped under the radar: US gov targets 72-hour patch cycles, malware uses Windows Phone Link to steal OTPs, spy operation targets Eurasian drone industry.

The hackers gained the ability to modify equipment operational parameters, creating a direct risk to the public water supply.

Hackers accessed one of the company’s AWS accounts and compromised AI provider secrets stored in Braintrust.

A system that thousands of schools and universities use went offline due to a cyberattack, creating chaos as students tried to study for finals.

The malware framework targets web applications and cloud environments, including AWS, Docker, Kubernetes, and more.

RansomHouse has published several screenshots to demonstrate access to internal Trellix services.

Lax extension permissions and improper trust implementation allow attackers to inject prompts in the Claude Chrome extension.

Linux vulnerability Linux vulnerability

Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released.

Chrome security Chrome security

Lax extension permissions and improper trust implementation allow attackers to inject prompts in the Claude Chrome extension.

Ivanti vulnerability exploited Ivanti vulnerability exploited

CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.

Top Cybersecurity Headlines

The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was. 

“TrustFall” attack shows how AI coding agents can be manipulated into launching stealthy supply chain compromises.

Dragos has published a report describing how threat actors used Claude AI in an attack on a water and drainage utility in Mexico.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Upcoming Cybersecurity Events

TDIR 2026 Summit

SecurityWeek’s 2026 Threat Detection & IR Summit will bring together security practitioners from around the world to share war stories on breaches, APT attacks and more.
[May 20, 2026 | Virtual]

Read More
CISO Forum 2026 Mid-Year Review Roundtable

SecurityWeek’s CISO Forum 2026 Mid-Year Review is a virtual roundtable to evaluate the year’s most pressing challenges and share critical updates shaping the 2026 security landscape.
[June 10, 2026 | Virtual]

Read More
Cloud Security Summit 2026

SecurityWeek’s 2026 Cloud Security Summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments.
[July 15, 2026 | Virtual]

Read More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More

Vulnerabilities

Cybercrime

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Cloud Security

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.