Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Members of Congress asked the U.S. Justice Department to investigate how foreign hackers breached a water authority near Pittsburgh, prompting CISA to warn other water and sewage-treatment utilities that they may be vulnerable.

Office supply retail giant confirms security incident disrupted online orders, communications channels and customer service lines.

Noteworthy stories that might have slipped under the radar: Utilities in US and Europe targeted in attacks, aerospace hacks, and Killnet leader unmasked.

New Turtle macOS ransomware is not sophisticated but shows that cybercriminals continue to target Apple devices.

The US has announced sanctions against North Korean cyberespionage group Kimsuky over its intelligence gathering activities. 

Researchers found that a ‘silly’ attack method could have been used to trick ChatGPT into handing over training data.

Apple’s security response team warns that flaws CVE-2023-42916 and CVE-2023-42917 were already exploited against versions of iOS before iOS 16.7.1.

Zyxel patches at least 15 security flaws that expose users to authentication bypass, command injection and denial-of-service attacks.

Meta removed three foreign influence operations from the Facebook platform during Q3, 2023. Two were Chinese in origin, and one was Russian, the company says. 

Qlik Sense vulnerabilities CVE-2023-41266, CVE-2023-41265 and CVE-2023-48365 exploited for initial access in Cactus ransomware attacks. 

The Black Basta ransomware group has infected over 300 victims and received more than $100 million in ransom payments.

US Treasury sanctions Sinbad, saying the cryptocurrency mixer is laundering funds for North Korean hacking group Lazarus.

Palo Alto Networks has launched a new rugged firewall for industrial environments and announced several OT security improvements.

ZeroedIn says personal information of 2 million individuals was compromised in an August 2023 data breach that impacts customers such as Dollar Tree.

Google shows how RETVec, a new and open source text vectorizer, can improve the detection of phishing attacks, spam and other harmful content.

Unitronics PLC hacked Unitronics PLC hacked

Members of Congress asked the U.S. Justice Department to investigate how foreign hackers breached a water authority near Pittsburgh, prompting CISA to warn other water and sewage-treatment utilities that they may be vulnerable.

North Korea Kimsuky sanctioned North Korea Kimsuky sanctioned

The US has announced sanctions against North Korean cyberespionage group Kimsuky over its intelligence gathering activities. 

Apple patches iOS zero-days Apple patches iOS zero-days

Apple’s security response team warns that flaws CVE-2023-42916 and CVE-2023-42917 were already exploited against versions of iOS before iOS 16.7.1.

Top Cybersecurity Headlines

Members of Congress asked the U.S. Justice Department to investigate how foreign hackers breached a water authority near Pittsburgh, prompting CISA to warn other…

Office supply retail giant confirms security incident disrupted online orders, communications channels and customer service lines.

Noteworthy stories that might have slipped under the radar: Utilities in US and Europe targeted in attacks, aerospace hacks, and Killnet leader unmasked.

New Turtle macOS ransomware is not sophisticated but shows that cybercriminals continue to target Apple devices.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join us as we delve into the transformative potential of AI, predictive ChatGPT-like tools and automation to detect and defend against cyberattacks.

Register

Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.

Watch Now

Upcoming Virtual Events

CISOs and risk management leaders must understand clearly the role of cyber insurance in a robust security program, ongoing changes to premiums and policy pricing, the errors that could deny coverage and how it all fits into global incident response planning.

Learn More
Cyber AI & Automation Summit

SecurityWeek’s inaugural Cyber AI & Automation Summit pushes the boundaries of security discussions by exploring the implications and applications of predictive AI, machine learning, and automation in modern cybersecurity programs.

Learn More

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place in 2023 as a virtual event. (June 13-14, 2023)

Learn More

As CISOs and corporate defenders grapple with the intricacies of securing sensitive data passing through multi-cloud deployments and APIs, the importance of frameworks, tools, controls and design models have surfaced to the front burner. (July 19, 2023)

Learn More

Vulnerabilities

Cybercrime

Top 10 Malware Threats for AprilSunbelt Software has announced the top 10 most prevalent malware threats for the month of April 2010. With nine of ten detections from March still on the list for April, it shows continued prevalence of Trojan horse programs circulating on the Internet. A new loader for a rogue security product making it into the top 10.

IT security and data protection firm Sophos announced that it has reached an agreement to sell a majority interest in the company to private equity group Apax Partners. The transaction will value the company at $830 million. Following the transaction, the founders of Sophos will retain a significant minority shareholding.

SecurityWeek staff has confirmed that portable storage, authentication, and trusted virtual computing solutions provider, IronKey, has raised $22 million in venture capital funding.

Managed information security services provider, SecureWorks, Inc., announced today the hire of Colonel Barry R. Hensley, former Director of the Army's Global Network Operations and Security Center. Hensley will be joining as Vice President of SecureWorks' Counter Threat Unit.

McAfee, Inc. (NYSE:MFE) today reported financial results for the first quarter ended March 31, 2010. McAfee generated $502.7 million in revenue, a first quarter record and marking their 17th consecutive quarter of double-digit, year-over-year revenue growth along with record operating cash flow. With the rapid growth, executives admit they continue to have finance and operations issues.

IT management software provider, CA (NASDAQ: CA), today announced the results of a European IT Security study revealing that organizations across several European countries are not utilizing Data Loss Prevention (DLP) technology.The survey revealed that 64% of organizations in the UK are not using Data Loss Prevention technology and other countries such as France (23%), Ireland (50%), and Italy (60%) report low utilization.

Symantec Corp. (Nasdaq: SYMC) today announced it would be making two key acquisitions, saying it has signed definitive agreements to acquire PGP Corporation and GuardianEdge Technologies, Inc., two privately-held leaders in the email and data encryption market. 

Hewlett-Packard Co. has agreed to acquire struggling smart phone maker Palm Inc. for over $1 billion in cash. The companies announced Wednesday they had agreed to the deal, which will see HP pay $5.70 for every Palm common share. With debt included, the deal values Palm at $1.2 billion. The transaction has been approved by the HP and Palm boards of directors.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Aikido Security has raised €5 million (~$5.4 million) in seed funding for an all-in-one application security platform.

Cloud Security