Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Hundreds of companies are showcasing their products and services at the 2025 edition of the RSA Conference in San Francisco.

Jericho Security has raised $15 million in Series A funding for its AI-powered employee cybersecurity training platform.

The latest Verizon DBIR landed this week with a startling statistic about the security posture of VPNs and network edge devices.

Push Security has raised $30 million in Series B funding to scale its browser-based identity security platform.

AI-powered threat prevention company Augur (rebranded from SecLytics) has raised $7 million in seed funding.

Combined with AI, polymorphic phishing emails have become highly sophisticated, creating more personalized and evasive messages that result in higher attack success rates.

The FBI received roughly 860,000 complaints of malicious activity in 2024, with reported losses exceeding $16.6 billion.

Blue Shield of California says a website misconfiguration exposed the health information of its members to Google.

Cisco is investigating the impact of the Erlang/OTP remote code execution vulnerability CVE-2025-32433 on its products.

Yale New Haven Health System recently discovered that the personal information of millions of patients was stolen from its systems.

Identity protection startup AuthMind has announced raising $19.3 million in a seed funding round led by Cheyenne Ventures.

People on the Move

Raffi Joukhadarian has been named Managing Director and Chief Financial Officer at MorganFranklin Cyber.

Data security firm Rubrik has appointed Kavitha Mariappan as its Chief Transformation Officer.

DARPA veteran Dan Kaufman has joined Badge as SVP, AI and Cybersecurity.

Kelly Shortridge has been promoted to VP of Security Products at Fastly.

After the passing of Amit Yoran, Tenable has appointed Steve Vintz and Mark Thurmond as co-CEOs.

More People On The Move
Healthcare data breach Healthcare data breach

Yale New Haven Health System recently discovered that the personal information of millions of patients was stolen from its systems.

Marks&Spencer cyberattack Marks&Spencer cyberattack

British retailer Marks & Spencer has been experiencing certain service disruptions after falling victim to a cyberattack.

SK Telecom cyberattack SK Telecom cyberattack

SK Telecom, South Korea’s largest telecom company, disclosed a data leak involving a malware infection.

Top Cybersecurity Headlines

Microsoft security chief Charlie Bell says the SFI’s 28 objectives are “near completion” and that 11 others have made “significant progress.”

With unapproved AI tools entrenched in daily workflows, experts say it’s time to shift from monitoring to managing Shadow AI use across the enterprise.

A Windows NTLM vulnerability patched in March has been exploited in attacks targeting government and private institutions.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

This webinar will guide you in aligning your security testing strategy with the right tools, helping you move beyond identifying weaknesses to effectively validating your overall security posture.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Two USB drives containing personal information on 2.4 million voters residing in districts within the Waterloo region of Southern Ontario, Canada were lost three months ago, according to recent disclosures from the agency who oversees general elections in Canada. Offering an explanation as to why Elections Ontario waited so long to release word of the breach, Greg Essensa, their chief electoral officer, said, “I did not want to make an irresponsible public notification or worry Ontarians needlessly.”

Cloud storage provider Dropbox, has taken on outside help in order to investigate a potential breach, which is being blamed as the reason for a sudden spike in spam directed at the service’s users.On Wednesday, users who said that they used unique email addresses when associating with Dropbox were seeing a massive flux in spam.InBoxes targeted by the spammer are seeing advertisements for EU Dice, Euro Gaming Palace, Premier Players Club, Vegas Virtual, SP Casino, and Best2day Support, and this...

ITWallStreet.com, a job board for IT talent looking to work in the financial district, was hacked on Wednesday – leaving some 50,000 users exposed. The attacker, going by Masakaki and claiming roots with TeamGhostShell, said the breach was part of a larger effort that focuses on financial institutions.ITWallStreet.com allows users to “discreetly connect with Wall Street’s IT career community.”

The Department of Homeland Security, through its Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), issued a warning last Friday about security vulnerabilities in the Tridium Niagara AX Framework, a popular software platform that integrates various control systems and devices and allows them to be managed over the Internet.The scary part? The security flaws were reported months ago, and permanent a fix has not yet been created.

Zero-day disclosures, new tools and exploits abound in this year's Black Hat conference in Las Vegas. Next week, the Caesar's Palace hotel in Las Vegas will host the 15th annual gathering of the minds in the world of security known as Black Hat USA.

Armed with an extra $22.4 million in its pocket following a Series C financing round announced just over a week ago, AlienVault, the San Mateo, California-based company behind open source SIEM, OSSIM, and the AlienVault Open Threat Exchange, today announced the latest version of its suite of security management products.

Ever since the invention of the lock, someone (somewhere) has tried to defeat it, often going to extremely creative lengths to do so. Such is the case of Ray – a security researcher and law enforcement consultant from Germany– who used a 3D printer to generate copies of handcuff keys that are normally restricted to law enforcement; the Bonowi and Chubb.

CipherCloud, a provider of cloud encryption technologies, has launched a cloud encryption gateway for Office 365 that transparently encrypts all email, calendar, and contact data stored in Microsoft's cloud-based Exchange Online and third-party Hosted Exchange services.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Endor Labs has raised $93 million in a Series B funding round and announced a major expansion of its AppSec platform.

Cloud Security

Cloud Security

The greatest security policies in the world are useless if enterprises don’t have a reasonable, consistent, and reliable way to implement them.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.