Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Microsoft security chief Charlie Bell pledges significant reforms and a strategic shift to prioritize security above all other product features.

Israeli startup LayerX Security banks $25 million in new financing as investors continue to pour money into secure web browsing technologies.

The US government warns of a North Korean threat actor abusing weak email DMARC settings to hide spear-phishing attacks.

Noteworthy stories that might have slipped under the radar: 4,000 take part in Locked Shields 2024 exercise, Qantas and JP Morgan hit by data exposure bugs, NVIDIA patches critical flaw. 

A botnet dismantled in January and used by Russia-linked APT28 consisted of more than just Ubiquiti Edge OS routers.

CISA and the FBI warn of threat actors abusing path traversal software vulnerabilities in attacks targeting critical infrastructure.

An analysis of IoCs suggests that a Chinese threat group may be behind the recent ArcaneDoor espionage campaign targeting Cisco firewalls.

SaaS-based, AI-assisted penetration service allows proactive defensive action against exploitation of new vulnerabilities.

Microsoft has uncovered a new type of attack called Dirty Stream that impacted Android apps with billions of installations. 

The White House has published a national security memorandum focusing on critical infrastructure security and resilience.

Yaroslav Vasinskyi was sentenced to 13 years and seven months in prison for his alleged role in the REvil ransomware operation.

People on the Move

Passwordless authentication firm Hawcx has appointed Lakshmi Sharma as Chief Product Officer.

Matt Hartley has been named Chief Revenue Officer at autonomous security solutions provider Horizon3.ai.

Trustwave has announced the appointment of Keith Ibarguen as Senior Vice President of Engineering.

Lital Asher–Dotan has been hired as Chief Marketing Officer at Beyond Identity.

Tidal Cyber announced that Jennifer Leggio has been appointed Chief Operating Officer.

More People On The Move
Microsoft Microsoft

Microsoft security chief Charlie Bell pledges significant reforms and a strategic shift to prioritize security above all other product features.

CVE-2024-21338 zero-day exploited by North Korea CVE-2024-21338 zero-day exploited by North Korea

The US government warns of a North Korean threat actor abusing weak email DMARC settings to hide spear-phishing attacks.

Dropbox data breach Dropbox data breach

Dropbox says hackers breached its Sign production environment and accessed customer email addresses and hashed passwords. 

Top Cybersecurity Headlines

Microsoft security chief Charlie Bell pledges significant reforms and a strategic shift to prioritize security above all other product features.

Israeli startup LayerX Security banks $25 million in new financing as investors continue to pour money into secure web browsing technologies.

The US government warns of a North Korean threat actor abusing weak email DMARC settings to hide spear-phishing attacks.

Noteworthy stories that might have slipped under the radar: 4,000 take part in Locked Shields 2024 exercise, Qantas and JP Morgan hit by data…

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 25-26, Ritz-Carlton, Half Moon Bay, CA]

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Learn More

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Threat Detection and Incident Response (TDIR) Summit dives into Threat hunting tools and frameworks, and explores the value of threat intelligence data in the defender’s security stack.

Learn More

Vulnerabilities

Cybercrime

SHANGHAI - Chinese telecom firm ZTE, accused by American lawmakers of doing business with Iran and posing a security threat, says US network giant Cisco Systems has ended a cooperation deal with it.

OTTAWA - Canada said Tuesday it had invoked a "national security exception" that could exclude China's Huawei Technologies from a role in helping build its new super secure government network.

WASHINGTON - The US Supreme Court let stand Tuesday an immunity law on wiretapping viewed by government as a useful anti-terror tool but criticized by rights activists as a flagrant abuse of executive power. The top US court declined to review a December 2011 appeals court decision that rejected a lawsuit against AT&T for helping the National Security Agency monitor its customers' phone calls and Internet traffic.

The growth of software activation key generators is linked to the spread of malware, according to findings from Microsoft's latest Security Intelligence report. In volume 13 of the report, which was released Monday, Microsoft reported that Win32/Keygen was the most commonly reported threat family in the first half of 2012. Win32/Keygen, which represents software activation key generators, was detected nearly five million times.

A Russian cyber-criminal going by the handle vorVzakone may be behind the plan to launch a series of Trojan attacks against financial institutions, Brian Krebs, the security researcher and reporter behind KrebsonSecurity.com, wrote Monday. Krebs identified the supposed mastermind based on a message posted on "exclusive Underweb forums," he wrote.

BEIJING - Chinese telecom firm Huawei's ambitions to become a global brand rivalling Apple and Samsung have been hit by a US report claiming that the company, founded by a former Chinese soldier, posed an espionage threat.

At RSA Conference Europe 2012 in London, RSA, The Security Division of EMC, on Tuesday introduced “Distributed Credential Protection,” new authentication technology designed to protect passwords and other credentials stored in databases from cyber attacks. RSA Distributed Credential Protection (DCP) allows customers to split authentication credentials between two points, providing a bump in protection to an often-targeted access point.

Cisco Systems has severed ties with ZTE Corp, after a Reuters investigation turned up evidence that the company’s technology was likely being sold to Iran. An internal investigation, which Cisco will not comment on, has caused enough concern that it was determined a clean break was needed.

WASHINGTON - Chinese tech giant Huawei on Monday called a congressional report warning of security risks from its telecom equipment "an exercise in China-bashing" as US lawmakers held firm to their allegations.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly.

Cloud Security

CISO Strategy

Microsoft security chief Charlie Bell pledges significant reforms and a strategic shift to prioritize security above all other product features.