Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A new Android trojan named Brokewell can steal user’s sensitive information and allows attackers to take over devices.

More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published.

More than 90,000 unique IPs are still infected with a PlugX worm variant that spreads via infected flash drives.

Noteworthy stories that might have slipped under the radar: Volkswagen hacked by Chinese threat group, DDoS service shut down, Rubrik IPO.

UK cybersecurity firm Darktace has agreed to sell itself to private equity giant Thoma Bravo for approximately $5.32 million in cash.

A vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and web shells into websites.

Predictive attack intelligence and risk protection startup BforeAI has raised $15 million in a Series A funding round led by SYN Ventures.

Palo Alto Networks has shared remediation instructions for organizations whose firewalls have been hacked via CVE-2024-3400.

A new phishing campaign abuses compromised email accounts and targets corporate users with PDF files hosted on Autodesk Drive.

The FTC is sending a total of $5.6 million in refunds to over 117,000 Ring customers as result of a 2023 settlement.

The Brocade SANnav management application is affected by multiple vulnerabilities, including a publicly available root password.

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move
Android Malware Android Malware

A new Android trojan named Brokewell can steal user’s sensitive information and allows attackers to take over devices.

Palo Alto Networks Palo Alto Networks

Palo Alto Networks has shared remediation instructions for organizations whose firewalls have been hacked via CVE-2024-3400.

CISA Warns of Windows Print Spooler Flaw After Microsoft Sees Russian Exploitation

CISA warns organizations of a two-year-old Windows Print Spooler vulnerability being exploited in the wild.

Top Cybersecurity Headlines

A new Android trojan named Brokewell can steal user’s sensitive information and allows attackers to take over devices.

More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published.

More than 90,000 unique IPs are still infected with a PlugX worm variant that spreads via infected flash drives.

Noteworthy stories that might have slipped under the radar: Volkswagen hacked by Chinese threat group, DDoS service shut down, Rubrik IPO.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 25-26, Ritz-Carlton, Half Moon Bay, CA]

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Learn More

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Threat Detection and Incident Response (TDIR) Summit dives into Threat hunting tools and frameworks, and explores the value of threat intelligence data in the defender’s security stack.

Learn More

Vulnerabilities

Cybercrime

NEW DELHI - (AFP) - India ended its ban on bulk text messages Thursday, two weeks after imposing restrictions to halt the spread of threats and rumours that sparked an exodus of migrants fearing attack.

Enterprises Experience 643 “Advanced Malware” Infections Each WeekAccording to FireEye’s most recent threat report released today, organizations are seeing a massive increase in advanced malware that is working its way inside enterprise walls by bypassing traditional IT security defenses.

In my previous SecurityWeek column, I wrote about how information is at the heart of most U.S. bills to secure the Internet. From CISPA to CSA to SECURE IT, all of these bills have one common tactic they are looking to tap: information sharing. My colleagues and I have a more descriptive saying for exactly what this is.

The zero-day in Java that SecurityWeek reported on Monday has gotten worse, as it can be targeted from within the Blackhole Exploit Kit and Metasploit. While this means good guys can use Metasploit as a means to proactive protection, the bad guys now have a way to automate victim collection.

Raynaldo Rivera, a 20 year-old from Tempe, Arizona, surrendered to authorities in Phoenix on Tuesday. Rivera stands accused of being a member of LulzSec and taking part in their attack on Sony last year. If true, he would be the second member of the group arrested in connection to the attack.

VMworld 2012 - HP announced on Tuesday that it would integrated their own portfolio of cloud-based services introduced in April, with VMware’s newest suite, vCloud 5.1. HP’s Converged Cloud enables customers to integrate various combinations of private, managed, and public cloud deployments, in addition to traditional IT, from an offering built on a single open architecture.

FORT MEADE, Maryland - (AFP) - Lawyers for the US soldier charged with passing a trove of classified documents to WikiLeaks accused the military Tuesday of withholding hundreds of emails over fears of a publicity nightmare. The defense team for Private Bradley Manning, who could be jailed for life for "aiding the enemy" over the massive security breach, alleged that more than 1,300 messages were ignored by prosecutors for at least six months.

VMworld 2012 – NetApp has announced a new integration between their Data ONTAP 8 software and VMware’s vSphere 5.1 in order to offer customers the ability to deliver and manage data migration between hundreds of virtual machines at once.

Intel and VMware are partnering to bring more security into the cloud using hardware-based security technologies. The two companies announced this week that VMware's vSphere 5.1 platform will support Intel's Trusted Execution Technology (TXT). The integration will provide a hardened platform for organizations to run their business-critical applications in both private and public clouds.

Radware Discovers “Admin.HLP” - A New Keylogger Used in Targeted Attack Security researchers from Radware have discovered a new Trojan Key Logger named “Admin.HLP” that they say captures sensitive user information and attempts to export it to a server in a remote location.

Splunk, the recently gone public provider of software that helps organizations gather and make use of machine data from a diverse set of sources, today launched Splunk Storm, a cloud service based on its flagship Splunk software.

As you are likely aware, the number of generic top-level domains (gTLDs) is about to increase dramatically. In June, the Internet Corporation for Assigned Names and Numbers (ICANN) announced that 1,930 applications were filed for New gTLDs (and although six applications were recently withdrawn, that leaves 1,924 applications in play). Domains that might go live in the months and years ahead include .CLOUD, .BUY, .BOOK and .APP, which received 13 separate requests to be delegated as a gTLD.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Cloud Security

Artificial Intelligence

Cisco announces Hypershield, an AI-native and cloud-native enterprise security solution with a wide range of capabilities.