Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Noteworthy stories that might have slipped under the radar: powerful US law firm hacked by China, Symantec product flaw, $10,000 Meta AI hack, cryptocurrency thieves bypassing FIDO keys. 

AI-native email security firm StrongestLayer has emerged from stealth mode with $5.2 million in seed funding.

Dozens of FortiWeb instances have been hacked after PoC targeting a recent critical vulnerability was shared publicly.

Radiology Associates of Richmond has disclosed a data breach impacting protected health and personal information. 

With generative AI enabling fraud-as-a-service at scale, legacy defenses are crumbling. The next wave of cybercrime is faster, smarter, and terrifyingly synthetic.

The CitrixBleed 2 vulnerability in NetScaler may expose organizations to compromise even if patches have been applied.

Google has filed a lawsuit against the Badbox 2.0 botnet operators, after identifying over 10 million infected Android devices.

Wiz researchers discovered NVIDIAScape, an Nvidia Container Toolkit flaw that can be exploited for full control of the host machine.

Anne Arundel Dermatology said hackers had access to its systems for three months and may have stolen personal and health information. 

A settlement has been reached in the class action brought by investors against Meta over the Cambridge Analytica incident, but details have not been shared.

Virtual event brings together leading experts, practitioners, and innovators for a full day of insightful discussions and tactical guidance on evolving threats and real-world defense strategies in cloud security.

People on the Move

Coro, a provider of cybersecurity solutions for SMBs, has appointed Joe Sykora as CEO.

SonicWall has hired Rajnish Mishra as Senior Vice President and Chief Development Officer.

Kenna Security co-founder Ed Bellis has joined Empirical Security as Chief Executive Officer.

Robert Shaker II has joined application security firm ActiveState as Chief Product and Technology Officer.

MorganFranklin Cyber has promoted Nick Stallone and Ferdinand Hamada into newly created roles.

More People On The Move
Badbox 2 botnet lawsuit by Google Badbox 2 botnet lawsuit by Google

Google has filed a lawsuit against the Badbox 2.0 botnet operators, after identifying over 10 million infected Android devices.

NVIDIAScape cloud container escape vulnerability NVIDIAScape cloud container escape vulnerability

Wiz researchers discovered NVIDIAScape, an Nvidia Container Toolkit flaw that can be exploited for full control of the host machine.

Oracle patches Oracle patches

Oracle’s July 2025 Critical Patch Update contains 309 security patches that address approximately 200 unique CVEs.

Top Cybersecurity Headlines

Cyberattack disrupted UNFI’s operations in June; company estimates $50–$60 million net income hit but anticipates insurance will cover most losses.

Chinese hacking group Salt Typhoon targeted a National Guard unit’s network and tapped into communications with other units.

DragonForce says it stole more than 150 gigabytes of data from US department store chain Belk in a May cyberattack.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

This online session will explore resilience planning in response to geopolitical tensions and help CISOs navigate the current state of federal cybersecurity initiatives.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Lockbox, a provider of secure file sharing solutions, today announced the availability of Lockbox for iPad and iPhone. Lockbox offers a Client Portal that allows information to be shared with multiple parties simultaneously, providing quick, easy, and secure and private collaboration.

Security software maker Trend Micro officially announced the grand opening of its Global Operations Headquarters in Irving/Las Colinas, Texas this week. Located just outside of Dallas, the new location will house operations for the company’s threat research, finance, legal, customer support, commercial sales and marketing, and human resources business units.

WASHINGTON - Revelations about the US government's secret surveillance programs has had a big impact on "trust metrics" of Internet companies like Facebook, the social network chief Mark Zuckerberg said Wednesday.

BROOKLYN, N.Y. -- The Brooklyn campus of the Polytechnic Institute of New York University (NYU-Poly) will be the nerve center this week for the world's biggest hacking competition, as more than 10,000 participants from across the world compete in the preliminary round to find the best student teams for the tenth annual NYU-Poly Cyber Security Awareness Week (CSAW).

DeviceLock, a provider of data leak prevention (DLP) software for endpoints, today today released DeviceLock Endpoint DLP Suite version 7.3, a new version that extends support to Mac OS X-based computers.

In my previous column, I examined the legality of parents monitoring their kids’ electronic communications. After I submitted the article, I realized I’d addressed the subject in the wrong order. Parenting, much like our legal system, is founded on three basic steps: 1) establish rules, 2) monitor compliance, and 3) modify non-compliant behavior.

LynuxWorks, a provider of tools and technologies for the embedded software market, today announced the RDS5201, a new product designed to help detect the stealthiest of advanced persistent threats (APT), the rootkit.

BRASïLIA - Hackers have hit back in retaliation for US cyber-spying on Brazil but mistook the US space agency NASA for the National Security Agency (NSA), a news website reported here Tuesday. "Some activists decided to protest this US practice but it seems that they picked the wrong target," a specialized blog of the Brazilian news portal Uol said.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

RevEng.ai has raised $4.15 million in seed funding for an AI platform that automatically detects malicious code and vulnerabilities in software.

Cloud Security

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.