Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The Antidot Android banking trojan snoops on users and steals their credentials, contacts, and SMS messages.

The Black Basta group abuses remote connection tool Quick Assist in vishing attacks leading to ransomware deployment.

The US government has announced charges, seizures, arrests and rewards as part of an effort to disrupt a scheme that generates revenue for North Korea.

C/side has emerged from stealth mode with $1.7 million in pre-seed funding from Scribble Ventures and angel investors

Network infrastructure as-a-service Alkira has raised $100 million in a Series C funding round led by Tiger Global Management.

Honoring my father by translating his timeless life lessons into practical wisdom for the cybersecurity profession.

Nissan North America determined recently that a ransomware attack launched last year resulted in employee personal information compromise.

Google is boosting fraud and malware protections in Android 15 with live threat detection and expanded restricted settings.

The City of Wichita says files containing personal information were exfiltrated in a recent ransomware attack.

Palo Alto Networks and IBM announced a significant partnership to jointly provide cybersecurity solutions.

Google releases Chrome 125 to the stable channel with patches for nine vulnerabilities, including a zero-day.

People on the Move

Cloud identity and security solutions firm Saviynt has hired former Gartner Analyst Henrique Teixeira as Senior Vice President of Strategy.

PR and marketing firm FleishmanHillard named Scott Radcliffe as the agency’s global director of cybersecurity.

Portnox, a provider of zero trust access control solutions, announced that Joseph Rodriguez has joined the company as Chief Revenue Officer.

Cybersecurity awareness training firm NINJIO has appointed Jon Dion as its Chief Revenue Officer.

IAM firm Device Authority has announced the appointment of Richard Seward as its VP of Product Management.

More People On The Move
Palo Alto Networks partners with IBM on cybersecurity Palo Alto Networks partners with IBM on cybersecurity

Palo Alto Networks and IBM announced a significant partnership to jointly provide cybersecurity solutions.

Intel Intel

Intel has published 41 new May 2024 Patch Tuesday advisories covering a total of more than 90 vulnerabilities. 

zero-day flaw zero-day flaw

Patch Tuesday: Microsoft documents 60 security flaws in multiple software products and flags an actively exploited Windows zero-day for urgent attention.

Top Cybersecurity Headlines

The Antidot Android banking trojan snoops on users and steals their credentials, contacts, and SMS messages.

The Black Basta group abuses remote connection tool Quick Assist in vishing attacks leading to ransomware deployment.

The US government has announced charges, seizures, arrests and rewards as part of an effort to disrupt a scheme that generates revenue for North…

C/side has emerged from stealth mode with $1.7 million in pre-seed funding from Scribble Ventures and angel investors

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 25-26, Ritz-Carlton, Half Moon Bay, CA]

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Learn More

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Threat Detection and Incident Response (TDIR) Summit dives into Threat hunting tools and frameworks, and explores the value of threat intelligence data in the defender’s security stack.

Learn More

Vulnerabilities

Cybercrime

Database giant Oracle on Thursday issued its pre-release announcement for its July 2012 Critical Patch Update, saying it would issue 88 new security vulnerability fixes across hundreds of Oracle products. As part of the update, Oracle will issue 4 new security fixes for vulnerabilities in the company’s flagship Oracle Database Server, 3 of which may be remotely exploitable without authentication.

nCircle, a provider of information risk and security solutions, today announced PureCloud™ Enterprise, a new scanning solution designed to help enterprises address the common gaps in security visibility. PureCloud Enterprise enables scan results to be integrated into the nCircle Suite360 Intelligence Hub™ to provide users with a single view of security risk, consolidated reporting and analytics.

Computer graphics technology firm NVIDIA, a company that holds more the 5,000 patent and credited with inventing the GPU, on Thursday said it had shut down its “NVIDIA Developer Zone,” after the online community for developers had been hacked.

A few heart freezing moments:• A phone call that begins with the words: We have your child – we want $250,000 to guarantee her safe return. If you go to the police, you will never see her again.• You receive a thick manila envelope with compromising pictures of you and a young woman, not your wife. You’ve been invited to a local bar to talk.

Earlier this week, SecurityWeek detailed the shutdown of the DarkComet project by its creator, because his works were used to attack protesters in Syria. The RAT had an interesting lifespan, and it was used in several attacks, according to Arbor Networks.Jean-Pierre Lesueur, who was responsible for bringing DarkComet to life, said that DarkComet was developed and given away for free, as long as people didn’t use it for malicious purposes.

Taking a break form the normal spin-cycle of security news, assets from the once popular Digg.com have been sold for $500,000, or 0.0005 Instagrams (Instagram was purchased by Facebook for a cool $1 billion earlier this year).At one point, Digg was valued at $175,000,000, but the shift to sites like Reddit (Digg’s longtime Web rival) and Twitter as an instant news source eventually caused the site’s decline.

After Reuters reported that China’s ZTE Corp (ZTEC) had sold monitoring equipment to Iran, in addition to software and technological goods manufactured in the U.S. – something that is forbidden under trade embargos – the Department of Commerce initiated an investigation. Now, according to an FBI affidavit, it has emerged that ZTE Corp went out of its way to impede the Department of Commerce’s inquiry.

Phandroid, a web site dedicated to Android news and discussion, is urging all of its users – more than a million of them in fact – to change their passwords after a server hosting their online forum was hacked earlier this week. News of this latest compromise comes after a string of security incidents this month, leaving some to wonder what’s next.

Using technology to steal high-tech cars is not new. In my book, When Gadgets Betray Us, I use the example of Radko Soucek, a car thief from the Czech Republic who would steal luxury cars off the streets of Prague in about twenty minutes. Soucek used a laptop preloaded with an algorithm for specific makes and models of cars to help him decipher the keyless entry and ignition sequence.

Three months after announcing a partnership with several security companies to provide free antivirus, Facebook has now established a new service Malware Checkpoint for users worried their computer may be infected.

Microsoft has issued a security advisory, and encouraged users of Windows Vista and Windows 7 to disable the Windows Sidebar and associated gadgets. The move comes just before a scheduled talk at BlackHat this month, where researchers will explore the types of flaws that exist in existing gadgets, as well as other weaknesses.

Instagram "Friendship" Vulnerability Exposed Users' Private Photos and Profile InformationSpanish researcher Sebastián Guerrero published an advisory on Wednesday, detailing what he called a ‘friendship’ vulnerability in the popular image application, Instagram. The imaging social phenomenon fixed the flaw within hours of his public disclosure.

Backupify, a provider of online backup services for cloud application data, today announced that it has secured $9 million in series C funding that will be used to accelerate further development and adoption of its backup tools.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly.

Cloud Security

Cloud Security

Financial terms were not released but the price tag is expected to be hefty with Exabeam’s most recent valuation pegged at $2.5 billion.