Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Printers can sit in the corner for ten years or more, while quantum decryption is thought by many to be less than 10 years away.

AI and other technologies “are a catalyst for crime, and drive criminal operations’ efficiency by amplifying their speed, reach, and sophistication,” the report said.

A critical vulnerability affecting baseboard management controller (BMC) firmware made by AMI could expose many devices to remote attacks.

Google has integrated OSV-SCALIBR features into OSV-Scanner, its free vulnerability scanner for open source developers.

ZDI has uncovered 1,000 malicious .lnk files used by state-sponsored and cybercrime threat actors to execute malicious commands.

Google has confirmed reports that it’s buying cloud security giant Wiz and says it’s prepared to pay $32 billion in cash.

Exploit and vulnerability intelligence provider VulnCheck has raised $12 million in a Series A funding round.

Cloudflare launches Cloudforce Threat Events Feed, a service designed to provide security teams with real-time threat intelligence.

The personal information of 22,000 Western Alliance Bank customers was stolen in a data breach linked to Cl0p’s hacking of the Cleo file transfer tool.

US representatives and senators have reintroduced a bipartisan bill to support the cybersecurity of small water and wastewater utilities.

A year-old vulnerability in ChatGPT is being exploited against financial entities and US government organizations.

People on the Move

Cybersecurity firm Absolute Security announced Harold Rivas as its new CISO.

Simon Forster has been named the new General Manager of DNS security firm Quad9.

Cybersecurity training company Immersive has named Mark Schmitz as its new CEO.

ICS/OT security firm Claroty has appointed Amir Preminger as Chief Technology Officer.

Sasha Pailet Koff has been named Managing Director of the Cyber Readiness Institute.

More People On The Move
Google acquires Wiz Google acquires Wiz

Google has confirmed reports that it’s buying cloud security giant Wiz and says it’s prepared to pay $32 billion in cash.

ChatGPT attack ChatGPT attack

A year-old vulnerability in ChatGPT is being exploited against financial entities and US government organizations.

NVIDIA Vulnerabilities NVIDIA Vulnerabilities

Vulnerabilities in Nvidia Riva could allow hackers to abuse speech and translation AI services that are typically expensive. 

Top Cybersecurity Headlines

The tj-actions/changed-files GitHub Action, which is used in 23,000 repositories, has been targeted in a supply chain attack.

The newly discovered SuperBlack ransomware has been exploiting two vulnerabilities in Fortinet firewalls.

CISA, FBI, and MS-ISAC warn of Medusa ransomware attacks targeting critical infrastructure organizations.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this in-depth briefing on how to protect executives and the enterprises they lead from the growing convergence of digital, narrative, and physical attacks.

Register

This webinar will guide you in aligning your security testing strategy with the right tools, helping you move beyond identifying weaknesses to effectively validating your overall security posture.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 2025, Stay Tuned]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.(February 26, 2025)

Learn More

Supply Chain Security Summit
Join us as we explore the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects. (March 19, 2025)

Learn More

Vulnerabilities

Cybercrime

Earlier this month, SecurityWeek reported that NASA was investigating claims made by a group of Iranian hackers that an SSL certificate issued to its Research and Education Support Services (NRESS) group was compromised, and used in a Man-in-the-Middle attack.

McAfee recently released its quarterly threats report for Q1 2012, detailing the increase in malware across all platforms. According to the data, PC-based malware hit a new high during the quarter, making it the largest jump the segment has seen in four years.Within the first quarter of 2012, McAfee Labs detected 8 million new malware samples, Vincent Weafer, senior vice president of McAfee Labs said.

FBI Sends Warning to InfraGard Members of Possible Memorial Day Attacks On Thursday, the FBI issued an alert to InfraGard members, warning them about an alleged plot to launch a series of DDoS attacks against high profile corporations. The campaign, titled OpNewSon (Operation NewSon), was initially proposed in April by a group of Anonymous supporters using the name TheWikiBoat.

While it’s commonplace to share information online and via social media, we all want our information safe, and we want control over what we share. Unfortunately, control is becoming harder to establish and maintain. As much as I am a technogeek, I am also security and privacy paranoid. Social media exposes us. Technology itself exposes us. My biggest privacy worries are currently around social media, and the mobile use of private information supported by smartphones. Facebook

Researchers have submitted a draft proposal to Internet Engineering Taskforce about a way to catch forged SSL certificates and address challenges to the level of trust in certificate authorities. Two researchers have proposed an extension to TLS (transport layer security) as a solution to some of the security challenges facing the SSL certificate ecosystem.

Nominum, a vendor that focuses on DNS and security solutions for enterprises and service providers, announced a new addition to its Nominum Mobile Suite on Wednesday, the Mobile Network and User Security solution.According to the company, the goal of the newest addition is to reduce latency and network failure, and protect mobile networks from increasing attacks.

Yahoo has since released an updated extension to address the issue, which was discovered by a security researcher shortly after Yahoo announced Axis. When Yahoo released its new Axis extension for Google's Chrome browser Wednesday, the company accidentally disclosed a private signing key that could be abused by an attacker.

Protegrity, a provider of data security solutions, on Wednesday announced Protegrity Vaultless Tokenization, an offering designed to help payment processors and gateways cost-effectively provide tokenization services to their clients.That company says it can now support the largest companies in the payments industry with a lightweight tokenization solution that can scale to thousands of merchants, quickly, without the cost and complexity of backend database infrastructure.

The National Centers of Academic Excellence in Cyber Operations Program, an initiative of the National Security Agency, aims to increase the amount of professionals with expertise in this area. The program is designed to identify institutions that offer a deeply technical, interdisciplinary curriculum centered on fields such as computer science, computer engineering, and electrical engineering. In addition, it supports the government's work to better protect cyberspace.

Polytechnic Institute of New York University (NYU-Poly) is introducing a management track to its master’s degree in cyber security. The first classes begin this summer."We created the management track in response to calls from industry for highly qualified executives with strong technical knowledge," said NYU-Poly Computer Science and Engineering Professor Nasir Memon."It will prepare graduates to manage a team of cyber-security personnel as well as a command of the business acumen to secure information in line with company objectives."

Intel has released a single sign-on application that will enable enterprises to use Salesforce.com credentials on all of the Force.com applications, in addition to scores of others across the Web. More over, Intel’s Cloud SSO service offers two-factor authentication options and has detailed reporting implemented from the start.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Google has integrated OSV-SCALIBR features into OSV-Scanner, its free vulnerability scanner for open source developers.

Cloud Security

Artificial Intelligence

Google Cloud’s AI Protection helps discover AI inventory, secure AI assets, and manage threats with detect, investigate, and respond capabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.