Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm.

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.

Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.

The Israeli company has nearly $2 billion in total assets under management since 2014.

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.

Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements.

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.

Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.

The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.

Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.

Signal has also made a security announcement: an automatic key verification feature to complement its safety number system.

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

White House cybersecurity White House cybersecurity

Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements.

Data breach and cybersecurity incident tracker Data breach and cybersecurity incident tracker

Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.

Ceva Logistics cyberattack Ceva Logistics cyberattack

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

Top Cybersecurity Headlines

LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.

Cloud Security

Artificial Intelligence

Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries...

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.