Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Guardrail specialist releases new products to aid the development and use of secure gen-AI apps.

San Francisco startup secures $8.5 million in seed funding led by Valley Capital Partners to tackle browser-based malware attacks.

Financial software firm Finastra is notifying individuals whose personal information was stolen in a recent data breach.

A critical vulnerability tracked as CVE-2025-21589 has been patched in Juniper Networks’ Session Smart Router.

Singulr AI announced its launch with $10 million in seed funding raised for an enterprise AI security and governance platform. 

A newly discovered Golang backdoor is abusing Telegram for communication with its command-and-control (C&C) server.

Microsoft has observed a new variant of the XCSSET malware being used in limited attacks against macOS users.

Palo Alto Networks has confirmed that a recently patched firewall vulnerability tracked as CVE-2025-0108 is being actively exploited.

Israeli cybersecurity startup Dream has raised $100 million in Series B funding and is now valued at $1.1 billion.

A newly identified malware family abuses the Outlook mail service for communication, via the Microsoft Graph API.

Russian hackers have been targeting government, defense, telecoms, and other organizations in a device code phishing campaign.

People on the Move

The US arm of networking giant TP-Link has appointed Adam Robertson as Director of Information and Security.

Raj Dodhiawala has been named Chief Product Officer at Eclypsium.

Cyber exposure management firm Armis has promoted Alex Mosher to President.

Software giant Atlassian has named David Cross as its new CISO.

Dan Pagel has been named the new CEO of risk management and remediation firm Brinqa.

More People On The Move
Palo Alto firewall vulnerabilities Palo Alto firewall vulnerabilities

Palo Alto Networks has confirmed that a recently patched firewall vulnerability tracked as CVE-2025-0108 is being actively exploited.

Windows vulnerability exploited Windows vulnerability exploited

ClearSky Cyber Security says it has seen a new Windows zero-day being exploited by a Chinese APT named Mustang Panda. 

zero-day flaw zero-day flaw

Rapid7 finds a new zero-day vulnerability in PostgreSQL and links it to chain of attacks against a BeyondTrust Remote Support product.

Top Cybersecurity Headlines

An analysis conducted by SecurityWeek shows that 405 cybersecurity-related mergers and acquisitions were announced in 2024.

A subgroup of the Russia-linked Seashell Blizzard is tasked with broad initial access operations to sustain long-term persistence.

The Microsoft Patch Tuesday machine hummed loudly this month with urgent fixes for a pair of already-exploited Windows zero-days.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Examine the state of cybersecurity in the context of quantum computing and artificial intelligence. Discuss the implications of the new White House administration’s cybersecurity policies and how they will influence the industry’s direction in 2025 and beyond.

Register

Dive into critical topics such as incident response, threat intelligence, and attack surface management. Learn how to align cyber resilience plans with business objectives to reduce potential impacts and secure your organization in an ever-evolving threat landscape.

Watch Now

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 2025, Stay Tuned]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.(February 26, 2025)

Learn More

Supply Chain Security Summit
Join us as we explore the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects. (March 19, 2025)

Learn More

Vulnerabilities

Cybercrime

In Australia, the local police will be informing businesses and residents that their wireless signal is unprotected and therefore open for criminal activity.According to the Sydney Morning Herald, police in Queensland will be the first to provide the new service. It is hoped that securing wireless in the area will help cut down on the number of cases of fraud, however, this is still just an informational campaign with no fines for non-compliance.

Dell SecureWorks recently published a report on the Waledac / Kelihos botnet and its role in a recent takedown operation. Unfortunately, while the initial efforts were successful, the controllers of the botnet have moved on and resumed operations.

Lookout Mobile Security has discovered a new variant of the Legacy Native (LaNa) malware for Android which opens a backdoor to the device. Unlike previous versions of LaNa, where the device had to first be rooted and depended on user interaction, this new variant doesn’t require the user at all, and will work on non-rooted devices.

McAfee today launched a new agentless AntiVirus (AV) solution for its McAfee Management for Optimized Virtual Environments (MOVE) platform that provides protection against various physical and virtual attacks through a single console.Designed to integrate with VMware vShield™ Endpoint, the solution offers customers standardized security across all major hypervisor vendors and addresses the challenges of protecting virtual environments in order to keep them malware-free.

TIBCO Software, a publicly traded (NASDAQ: TIBX) provider of infrastructure software solutions, on Tuesday night said that it has entered into a definitive agreement to acquire San Jose California-based LogLogic, a provider of and log management and security intelligence solutions, for an undisclosed sum.

Security firm Sophos today announced its intent to acquire DIALOGS, a small European mobile device management firm.Privately-held DIALOGS is headquartered in Germany and counts companies including BMW AG, Daimler AG, Siemens AG and ThyssenKrupp as customers.

Adobe Systems recently released an open source tool to help security pros in the fight against malware.According to the company, the Adobe Malware Classifier is a command-line tool aimed to help antivirus analysts, IT administrators and security researchers determine if a binary file contains malware so they can develop malware detection signatures faster. The tool uses machine-learning algorithms to categorize Win32 binaries – exe and DLL files – into three classes: 0, representing clean; 1, representing malicious; and unknown.

Pastebin.com has become a popular place for stolen data as well as boasts from hackers associated with Anonymous and other groups. The site’s status as a home for hackers may soon be in jeopardy however.In an interview with BBC, Pastebin owner Jeroen Vader stated that the site is looking to hire additional people to monitor the website’s content.

RIM Launches BlackBerry Mobile FusionIn November 2011, BlackBerry maker Research In Motion (RIM) announced that it would enter the multi-platform Mobile Device Management (MDM) market with the introduction of BlackBerry Mobile Fusion, the company’s next-generation enterprise mobility solution.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

San Francisco startup secures $8.5 million in seed funding led by Valley Capital Partners to tackle browser-based malware attacks.

Cloud Security

Application Security

APIs are easy to develop, simple to implement, and frequently attacked. They are  prime and lucrative targets for cybercriminals. 

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.