Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The number of exploited zero-days seen by Google in 2024 dropped to 75, from 98 observed in the previous year.

Hundreds of companies are showcasing their products and services this week at the 2025 edition of the RSA Conference in San Francisco.

More than 400 SAP NetWeaver servers are impacted by CVE-2025-31324, an exploited remote code execution vulnerability.

CISA urges immediate patching for recently disclosed Broadcom, Commvault, and Qualitia vulnerabilities exploited in the wild.

IBM will invest more than $30 billion in research and development to advance and continue its American manufacturing of mainframe and quantum computers.

Palo Alto Networks is acquiring AI security company Protect AI in a deal previously estimated at $650-700 million.

Zero-trust network security solutions provider NetFoundry has raised $12 million in funding from SYN Ventures.

This tension between hard-edged risk realism and breathless AI evangelism sets an unmistakable tone for a bellwether conference where 40,000-plus gather to do business. 

San Francisco identity security play Veza closes a Series D fund round led by New Enterprise Associates (NEA).

Threat actors have exploited a zero-day vulnerability in Craft CMS to execute PHP code on hundreds of websites.

VeriSource Services says the personal information of 4 million people was compromised in a February 2024 cyberattack.

People on the Move

Threat intelligence firm Team Cymru has appointed Joe Sander as its Chief Executive Officer.

Madhu Gottumukkala has been named Deputy Director of the cybersecurity agency CISA.

Wendi Whitmore has taken the role of Chief Security Intelligence Officer at Palo Alto Networks.

Phil Venables, former CISO of Google Cloud, has joined Ballistic Ventures as a Venture Partner.

David Currie, former CISO of Nubank and Klarna, has been appointed CEO of Vaultree.

More People On The Move
RSA Conference 2025 RSA Conference 2025

Hundreds of companies are showcasing their products and services this week at the 2025 edition of the RSA Conference in San Francisco.

RSA Conference 2025 RSA Conference 2025

This tension between hard-edged risk realism and breathless AI evangelism sets an unmistakable tone for a bellwether conference where 40,000-plus gather to do business. 

RSA Conference 2025 RSA Conference 2025

Hundreds of companies are showcasing their products and services this week at the 2025 edition of the RSA Conference in San Francisco.

Top Cybersecurity Headlines

A zero-day vulnerability in SAP NetWeaver potentially affects more than 10,000 internet-facing applications.

Yale New Haven Health System recently discovered that the personal information of millions of patients was stolen from its systems.

British retailer Marks & Spencer has been experiencing certain service disruptions after falling victim to a cyberattack.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

This webinar will guide you in aligning your security testing strategy with the right tools, helping you move beyond identifying weaknesses to effectively validating your overall security posture.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

In a blog post examining cases from 2012, Verizon Business’ Andrew Valentine presented a tale of a critical infrastructure firm in the U.S. who called them into investigate suspicious VPN connections to China. As it turns out, this was no complex hack, just a lazy developer – or a smart one depending on how you view things.

Zettaset, a Mountain View, California-based provider of Big Data management and security solutions, announced on Wednesday that it has closed a $10 million Series B round of venture funding. The new cash will be used to expand research and development and sales and marketing in order meet increasing demand from enterprise customers, the company said.

On Tuesday, AlienVault, the company behind open source SIEM, OSSIM, announced the version 4.1 release of their Unified Security Management platform, which looks to resolve the challenges associated with typical SIEM deployments including cost, complexity, and implementation.

Recent analysis from Frost & Sullivan shows that the security of critical facilities remains the topmost priority for the global oil and gas industry. Accordingly, these markets are increasing the amount spent on security offerings, including those offer integrated and flexible solutions with rounded protection.

SEOUL - South Korean police on Wednesday said North Korea was behind a cyber-attack that paralysed operations at a major conservative newspaper last year. Police accused the North of hacking the news website and database of the JoongAng Ilbo and sister English paper the Korea JoongAng Daily last June, saying the ministry of post and telecommunications might have been involved.

It’s easy to feel uncertainty about where to start to properly cover all the bases when it comes to securing your infrastructure. Evolving security threats are demanding that protective solutions develop just as rapidly – or faster. It’s not enough to stick to the same generic security measures you’ve always assumed were working, and hope for the best. Hackers are becoming smarter and scrappier, so you have to beat them in both departments too.

I am an optimist by nature, which often makes me a minority amongst many of my colleagues in the security sector. Despite my optimism, I live in fear of a coming Distributed Denial of Service (DDoS) disaster.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Software and AI supply chain transparency firm Manifest has raised $15 million in a Series A funding round led by Ensemble VC.

Cloud Security

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.