Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

Anthropic reveals how criminal groups are increasingly targeting AI vendors’ own infrastructure, including to steal a pre-release Claude model.

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.

Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.

Threat Intelligence Sharing Threat Intelligence Sharing

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.

Cryptocurrency Cryptocurrency

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

VPN attack VPN attack

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

Top Cybersecurity Headlines

Anthropic reveals how criminal groups are increasingly targeting AI vendors’ own infrastructure, including to steal a pre-release Claude model.

Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

SecurityWeek’s 2026 Zero Trust Summit will deep-dive into the world of digital identity management and the role of zero-trust principles and associated technologies
[October 14, 2026 | Virtual]

Read More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More

Vulnerabilities

Cybercrime

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.