Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Since August 2015, Google has delivered a constant stream of monthly security patches for Android. Until July 2025.

Researchers demonstrated GPUHammer — a Rowhammer attack against GPUs — by degrading the accuracy of machine learning models.

Details have been disclosed for an eSIM hacking method that could impact many, but the industry is taking action.

Ingram Micro has restored operations across all countries and regions after disconnecting systems to contain a ransomware attack.

Three teens and a woman have been arrested by the UK’s NCA over the hacking of M&S, Co-op and Harrods.

Hackers compromised names, addresses, email address, phone numbers, and other information pertaining to Qantas customers.

‘Machine identities’, often used interchangeably with ‘non-human identities’ (NHIs), have been increasing rapidly since the start of digital transformation.

PCA Cyber Security has discovered critical vulnerabilities in the BlueSDK Bluetooth stack that could have allowed remote code execution on car systems.

AI-made decisions are in many ways shaping and governing human lives. Companies have a moral, social, and fiduciary duty to responsibly lead its take-up.

AI-powered MDR provider AirMDR has raised $15.5 million in funding (seed and infusion investment) to support its R&D efforts.

Nippon Steel Solutions has disclosed a data breach that resulted from the exploitation of a zero-day in network equipment.

People on the Move

Jessica Newman has joined Sophos as General Manager of Global Cyber Insurance.

Breach and attack simulation solutions provider AttackIQ has appointed Pete Luban as Field Chief Information Security Officer.

Matthew Cowell has assumed the role of VP of Strategic Alliances at Nozomi Networks. He previously served in the same role at Dragos.

Bret Arsenault is retiring from his full-time role after 35 years at Microsoft.

Social engineering defense platform Doppel has appointed Bobby Ford as Chief Strategy and Experience Officer.

More People On The Move
eSIM hacking eSIM hacking

Details have been disclosed for an eSIM hacking method that could impact many, but the industry is taking action.

Car hacking Car hacking

PCA Cyber Security has discovered critical vulnerabilities in the BlueSDK Bluetooth stack that could have allowed remote code execution on car systems.

Nippon Steel data breach Nippon Steel data breach

Nippon Steel Solutions has disclosed a data breach that resulted from the exploitation of a zero-day in network equipment.

Top Cybersecurity Headlines

Xu Zewei has been arrested on charges that he is a member of the Chinese state-sponsored hacking group Hafnium (Silk Typhoon).

As organizations rush to adopt agentic AI, security leaders must confront the growing risk of invisible threats and new attack vectors.

Researchers released technical information and exploit code targeting a critical vulnerability (CVE-2025-5777) in Citrix NetScaler.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

This online session will explore resilience planning in response to geopolitical tensions and help CISOs navigate the current state of federal cybersecurity initiatives.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

On Friday, Mozilla issued another security fix for issues discovered after the release of Firefox 16.0.1, which if exploited, would allow Cross-Site Scripting (XSS) or code execution. The latest release is available now in the update channel and for direct download. Friday’s release marks the third time this month that security issues needed to be addressed. It’s also the 14th critical fix released for version 16.

WASHINGTON - It is expected to be the mother of all cyber diplomatic battles. When delegates gather in Dubai in December for an obscure UN agency meeting, fighting is expected to be intense over proposals to rewrite global telecom rules to effectively give the United Nations control over the Internet.

WatchGuard Technologies, a Seattle, Washington-based IT security solutions vendor, said early this week that its UTM security appliances will soon be able to configure themselves, thanks to “RapidDeploy”, a new cloud-based configuration utility.

ISLAMABAD - Pakistan will block mobile phone networks in several cities early Saturday over security fears during the Muslim festival of Eid al-Adha, Interior Minister Rehman Malik said. The decision "based on intelligence reports" has been taken to prevent attacks by Taliban and Al-Qaeda-linked militants on Muslim congregations in several cities including parts of the capital Islamabad, he said Friday.

I don’t play poker well. I donate money to my friends every few weeks because I like to eat junk food, breathe bad cigar smoke and hang with the guys. I’m so easy to read; when I get a good hand I stare at my opponents’ chips, willing them into the pot. When I’m bluffing, I fidget. Take my money, just invite me back; my ‘tells’ are legendary amongst my friends.

OTTAWA - Canada and the United States announced Friday they were launching a joint cybsersecurity plan to protect their digital infrastructure from online threats. The action plan, under the auspices of the US Department of Homeland Security and Public Safety Canada, aims to better protect critical digital infrastructure and improve the response to cyber incidents.

After enterprise software firm Sybase released patches to address critical vulnerabilities in its relational database management system over the summer, it turned out the security holes had not been completely closed. Months later, the flaws still remain, database security experts said.

Symantec recently published a blog post detailing two new methods being deployed to avoid malware detection and analytics. According to research, criminals are taking a low-cost / low-tech approach and using sleep loops along with basic monitoring to avoid getting caught.

SAN FRANCISCO - A New York man with a shady past was arrested on Friday for using a forged contract with Facebook co-founder Mark Zuckerberg to lay claim to half of the world's leading online social network. Paul Ceglia, 39, faces a pair of fraud charges that each carries a maximum sentence of 20 years in prison, according to federal prosecutors.

Rapid7, the Boston-based security firm behind the popular Metasploit and Nexpose testing frameworks, today announced tha Mike Tuchen has stepped down from his role as CEO and will be replaced by Corey Thomas who will serve as President and CEO of the company.

Stoke-on-Trent City Council (UK) has been smacked with a £120,000 fine for failing to secure sensitive information that was being transmitted electronically. The data, child protection documents, was accidentally delivered to a person not related to the case, and wasn’t properly encrypted the Information Commissioner’s Office (ICO) said, posing a significant breach of the Data Protection Act.

WASHINGTON - Defense Secretary Leon Panetta on Thursday demanded Congress take action after November elections to ensure stable funding for the US military and to break a partisan deadlock over the country's budget deficit. "When Congress returns to town after the election, there is a great deal of critical work that needs to be done," Panetta told a news conference.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

RevEng.ai has raised $4.15 million in seed funding for an AI platform that automatically detects malicious code and vulnerabilities in software.

Cloud Security

Cloud Security

Founded in 2015, the Tel Aviv based company has now raised more than $1 billion and claims more than 3,500 customers.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.