CONFERENCE NOW LIVE: Threat Detection & Incident Response (TDIR) Summit - Join the Event In-Progress
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Akamai documents a privilege escalation flaw in Windows Server 2025 after Redmond declines to ship an immediate patch.

Marlboro-Chesterfield Pathology has been targeted by the SafePay ransomware group, which stole personal information from its systems.

UK retailer Marks & Spencer expects the disruptions caused by the recent cyberattack to continue through July. 

In the end, cybersecurity isn’t just about collecting data. It’s about proving that your defenses actually work.

Despite massive investment, the explosion of sophisticated malware and deepfake attacks persists because organizations struggle to verify digital identities and establish fundamental trust.

Cisco published 10 security advisories detailing over a dozen vulnerabilities, including two high-severity flaws in its Identity Services Engine (ISE) and Unified Intelligence Center.

GitLab and Atlassian have released patches for over a dozen vulnerabilities in their products, including high-severity bugs.

Russian military intelligence hackers intensify targeting of Western logistics and technology companies moving supplies into Ukraine. 

Redmond’s threat hunters found 394,000 Windows systems talking to Lumma controllers, a victim pool that included global manufacturers. 

More than 100 AutomationDirect MB-Gateway devices may be vulnerable to attacks from the internet due to CVE-2025-36535.

SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st.

People on the Move

Jeremy Koppen has left Mandiant after 13 years to become the CISO of Equifax.

Engineering and technology solutions provider Amentum has appointed Max Shier as its CISO.

PAM provider Keeper Security has appointed Shane Barney as its Chief Information Security Officer.

SpecterOps has appointed Tim Bender as CFO, Pat Sheridan as CRO, and Bryce Hein as CMO.

CISA has officially announced the appointment of Madhu Gottumukkala as its new deputy director.

More People On The Move
Marks&Spencer cyberattack Marks&Spencer cyberattack

UK retailer Marks & Spencer expects the disruptions caused by the recent cyberattack to continue through July. 

ICS honeypot scanning ICS honeypot scanning

Many of the industrial control system (ICS) instances seen in internet scanning are likely or possibly honeypots, not real devices.

Pwn2Own Berlin 2025 results Pwn2Own Berlin 2025 results

Pwn2Own participants demonstrated exploits against VMs, AI, browsers, servers, containers, and operating systems.

Top Cybersecurity Headlines

The 15th edition of NATO’s Locked Shields cyber defense exercise brought together 4,000 experts from 41 countries.

American steel giant Nucor on Wednesday disclosed a cybersecurity incident that bears the hallmarks of a ransomware attack.

The China-linked hacking group Earth Ammit has launched multi-wave attacks in Taiwan and South Korea to disrupt the drone sector.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Join this webinar for a fascinating discussion to understand why data in itself is not enough to make informed decisions for prioritization.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

The ZeroAccess rootkit used to be a problematic kernel-mode family of malware that was hard to remove; new versions of the malware itself have dropped the kernel-mode aspects. Now it operates entirely in user-mode memory. This shift in development has led Sophos researchers to dig deeper, and they found some interesting things.

The U.S. Attorney’s Office said on Wednesday that a former software engineer working for Chicago-based CME Group pleaded guilty to theft of trade secrets after he stole source code and other proprietary information from the company.

LOS ANGELES  — A 21-year-old man whose alleged Internet rant about killing children alarmed law enforcement authorities, leading them to knock down his door and arrest him, is being described by his own attorney as "just a dumb kid."

BEIJING - Despite several years of escalating diplomacy and warnings, the U.S. is making little headway in its efforts to tamp down aggressive Chinese cyberattacks against American companies and the government. U.S. Defense Secretary Leon Panetta, who is wrapping up three days of meetings with military and civilian leaders, said he has brought the issue up at every session and come away with little more than agreements to talk again.

Cyber Espionage Attacks Hit Philippine Oil Company and Canadian Energy FirmResearchers from Dell SecureWorks’ Counter Threat Unit say they have discovered yet another cyber espionage campaign targeting oil and energy companies. 

Employees are increasingly turning to web-based or web-enabled applications to help get their jobs done. To combat the risks associated with these applications, one of the most significant evolutions in network security over the last few years has been the advent of application control. This technology gives administrators visibility and control over each application that is allowed to communicate on the network.

IBM's X-Force 2012 mid-year report found a sharp increase in browser-related exploits, Mac-based attacks, and SMS related scams. Since its last Trend and Risk Report, released at the beginning of the year, IBM's X-Force has seen an increase in malware and malicious Web activities, a disconnect in how corporations implement "bring your own device" (BYOD) programs, and increased concern in how users are selecting passwords to protect their various Web accounts.

MANILA - The Philippines said Thursday it had deported 279 Taiwanese accused of running a multi-million-dollar online scam that prompted stepped-up airport screening to guard against criminal gangs. The Taiwanese were put on two chartered flights on Wednesday to Taipei, where they face prosecution, immigration spokeswoman Antonette Mangrobang said.

On Wednesday, Microsoft released a FixIt tool for those wanting some automated protection from the latest Zero-Day for Internet Explorer. However, if users at home are using caution as they surf the Web, and organizations are being proactive, it might be easier to wait until Friday, when Microsoft will issue an out-of-band security update to their browser, fully addressing the problem.

Veracode Launches Vendor Application Security Testing ProgramApplication security testing firm Veracode on Wednesday launched an automated program to help businesses evaluate security risks associated with third-party software.

According to security vendor Incapsula, August was a busy month for Web Application attacks. The company's latest "attack heat map report" shows some interesting snapshots of the Web, including an overall attack level in Denmark of 0.74 percent, which was launched from a single source.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Code quality and security firm CodeAnt has secured $2 million in seed funding and it has been valued at $20 million.

Cloud Security

Cloud Security

VMware patches flaws that expose users to data leakage, command execution and denial-of-service attacks. No temporary workarounds available. 

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.