Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Russian hackers have been targeting government, defense, telecoms, and other organizations in a device code phishing campaign.

After governments announced sanctions against the Zservers/XHost bulletproof hosting service, Dutch police took 127 servers offline.

DeepSeek has temporarily paused downloads of its chatbot apps in South Korea while it works with local authorities to address privacy concerns.

Xerox released security updates to resolve pass-back attack vulnerabilities in Versalink multifunction printers.

In a signal move for the cybersecurity sector, identity and access management (IAM) vendor SailPoint has made its return to public markets.

The chief deputy attorney general of the agency sent an email on Wednesday that said nearly all of is computer systems were offline.

Former RNC official Sean Cairncross has been nominated for the post of National Cyber Director to streamline the US cybersecurity strategy.

In the latest edition of “Rising Tides” we talk with Lesley Carhart, Technical Director of Incident Response at Dragos.

Meta received close to 10,000 vulnerability reports and paid out over $2.3 million in bug bounty rewards in 2024.

Noteworthy stories that might have slipped under the radar: Google pays $10,000 bug bounty for YouTube vulnerability, Cybereason CEO sues two investors, Otorio launches new OT security tool.

The exploitation of a recent SonicWall vulnerability has started shortly after proof-of-concept (PoC) code was published.

People on the Move

The US arm of networking giant TP-Link has appointed Adam Robertson as Director of Information and Security.

Raj Dodhiawala has been named Chief Product Officer at Eclypsium.

Cyber exposure management firm Armis has promoted Alex Mosher to President.

Software giant Atlassian has named David Cross as its new CISO.

Dan Pagel has been named the new CEO of risk management and remediation firm Brinqa.

More People On The Move
Windows vulnerability exploited Windows vulnerability exploited

ClearSky Cyber Security says it has seen a new Windows zero-day being exploited by a Chinese APT named Mustang Panda. 

zero-day flaw zero-day flaw

Rapid7 finds a new zero-day vulnerability in PostgreSQL and links it to chain of attacks against a BeyondTrust Remote Support product.

Cybersecurity M&A 2024 Cybersecurity M&A 2024

An analysis conducted by SecurityWeek shows that 405 cybersecurity-related mergers and acquisitions were announced in 2024.

Top Cybersecurity Headlines

A subgroup of the Russia-linked Seashell Blizzard is tasked with broad initial access operations to sustain long-term persistence.

The Microsoft Patch Tuesday machine hummed loudly this month with urgent fixes for a pair of already-exploited Windows zero-days.

Intel says roughly 100 of the 374 vulnerabilities it patched last year were firmware and hardware security defects.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Examine the state of cybersecurity in the context of quantum computing and artificial intelligence. Discuss the implications of the new White House administration’s cybersecurity policies and how they will influence the industry’s direction in 2025 and beyond.

Register

Dive into critical topics such as incident response, threat intelligence, and attack surface management. Learn how to align cyber resilience plans with business objectives to reduce potential impacts and secure your organization in an ever-evolving threat landscape.

Watch Now

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 2025, Stay Tuned]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.(February 26, 2025)

Learn More

Supply Chain Security Summit
Join us as we explore the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects. (March 19, 2025)

Learn More

Vulnerabilities

Cybercrime

Officials at Coca-Cola reportedly hid the fact that the company was victimized in a breach in 2009. According to Bloomberg News, the FBI approached the company when it learned hackers had stolen sensitive files about the company's $2.4 billion acquisition of China Huiyuan Juice Group, which eventually collapsed. The compromise was reportedly occurred via emails with malicious links that were sent to company executives.

WASHINGTON - New Jersey's decision to allow voters displaced by superstorm Sandy to cast ballots by email has prompted a flood of warnings over security, secrecy and a potential for legal entanglements. State officials in New Jersey announced the plan Saturday, saying it could help victims of the unprecedented storm along with rescuers who may also be unable to get to polling places.

Rumors circulated early on Monday that Anonymous has kicked off their OpVendetta campaign with a hack on PayPal. While this hasn’t been confirmed, other related defacements and server compromises have been linked to the operation, as the faceless legion aims to make people remember the 5th of November. [Updated With Additonal Statements from PayPal Below]

With Halloween past us, there’s an excess of sugar in our blood, and remnant imaginings of monsters under the bed. So perhaps that’s why when the topic of “silver bullet security” recently came up, my mind immediately went to Werewolves. The term was used, as it often is, in a discussion about Application Whitelisting—the industrial automation industry’s rightful poster child for endpoint security.

Malware protection firm FireEye has teamed up with EMC’s RSA Security division through a new interoperability agreement that will leverage threat information from FireEye’s Malware Protection System (MPS) and feed that data into RSA’s NetWitness network monitoring platform.

Hundreds of webpages maintained by NBC Universal were defaced over the weekend, by a hacker going by the name of “pyknik.” In addition to NBC, this attacker also targeted a Lady Gaga fan site. Web software used by both domains is speculated to be the primary source of access used in the attack.

A hacker zine has posted details that expose some questionable security practices maintained by image hosting service ImageShack, in addition to source code used by the service. The zine also singled out Symantec and exposed the personal details (dox) for several Anonymous supporters.

WASHINGTON - Few want to even think about it, but the 2012 US election result could be clouded by problems with voting machines ... again. Twelve years after the Florida punch card debacle in which thousands of votes went uncounted in the crucial state, some experts cite similar concerns about voting technology.

Security software firm Quarri Technologies has extended its hardened Web browser technology to iOS devices to protect against various Web attacks, including session hijacking and data theft. Quarri Protect on Q Mobile for iOS prevents Web browsers from copying and saving data onto iOS devices, Quarri Technologies told SecurityWeek. POQ Mobile for iOS will be part of Quarri's Protect On Q security suite, which already protects Windows systems and Android devices.

According to a recent report from AVG Technologies, many SMBs in the US and UK are missing out on the benefits of cloud technologies due to basic confusion. The organizations that particpated in the study were unsure of cloud services or felt they were only for large organizations.

Researchers at VUPEN Security say they have uncovered multiple vulnerabilities in Windows and Internet Explorer 10 that can be combined to bypass security features in Windows 8. According to VUPEN CEO Chaouki Bekrar, exploiting the vulnerabilities result in remote code execution without any user interaction beyond visiting a webpage.

WASHINGTON - The Pentagon will no longer retain an exclusive contract with Blackberry maker Research in Motion and has invited companies such as Apple to offer smart phones to its vast work force. The move, announced Thursday, comes only days after another government agency, the US Immigration and Customs Enforcement agency, said it was dropping the Blackberry device altogether in favor of Apple's iPhone.

GlobalSign, an SSL Certificate provider, and CloudFlare, a company that helps accelerate Web site performance and improve site security, have teamed up to help GlobalSign customers improve the load time of SSL-secured web content.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

San Francisco application security startup raises $100 million in a Series D funding round led by Menlo Ventures. 

Cloud Security

Application Security

APIs are easy to develop, simple to implement, and frequently attacked. They are  prime and lucrative targets for cybercriminals. 

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.