Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Aflac said that it’s in the early stages of a review of the incident, and so far is unable to determine the total number of affected individuals.

Noteworthy stories that might have slipped under the radar: China’s Salt Typhoon targeted Viasat, Washington Post emails compromised in hack, Rowhammer attack named Crowhammer.

Cloudflare has blocked yet another record-breaking DDoS attack, which delivered the equivalent of 9,000 HD movies in just 45 seconds.

The Godfather Android trojan uses on-device virtualization to hijack legitimate applications and steal users’ funds.

Threat actors are exploiting a critical-severity vulnerability in Motors theme for WordPress to change arbitrary user passwords.

WhatsApp told SecurityWeek that it linked the exploited FreeType vulnerability CVE-2025-27363 to a Paragon exploit.

A threat actor is abusing Cloudflare Tunnels for the delivery of a Python loader as part of a complex infection chain.

Krispy Kreme is sharing more information on the data breach resulting from the ransomware attack targeting the company in 2024. 

Personal data of former and current council workers, including election staff, may have been accessed by hackers.

Israel-linked Predatory Sparrow hackers torched more than $90 million at Iran’s largest cryptobank as Israel-Iran cyberwar escalates.

Trend Micro and ReversingLabs uncovered over 100 GitHub accounts distributing malware embedded in open source hacking tools.

People on the Move

Checkmarx has appointed Scott Gainey as Chief Marketing Officer.

Jason Hogg has been named Executive Chairman of CYPFER.

HUB Cyber Security has appointed former PayPal and American Express executive Paul Parisi as its Global Chief Revenue Officer.

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

More People On The Move
WhatsApp Zero-Day Exploit WhatsApp Zero-Day Exploit

WhatsApp told SecurityWeek that it linked the exploited FreeType vulnerability CVE-2025-27363 to a Paragon exploit.

Encryption backdoor debate Encryption backdoor debate

After decades of failed attempts to access encrypted communications, governments are shifting from persuasion to coercion—security experts say the risks are too high.

Scania hack Scania hack

A hacker is selling allegedly valuable data stolen from Scania, but the truck maker believes impact is very limited.

Top Cybersecurity Headlines

Russian hackers posed as US State Department staff and convinced targets to generate and give up Google app-specific passwords.

OpenAI has been awarded a $200 million contract for AI capabilities to help the Defense Department address national security challenges.

Hackers have stolen personal and health information belonging to the customers of healthcare organizations served by Episource.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Sophos, with dual headquarters in Boston, MA and Oxford, UK, today said that Kris Hagerman has been appointed as chief executive officer of the company, effective immediately. Hagerman, who will also join the company's board, succeeds Steve Munford who will become non-executive chairman of the board.

STOCKHOLM - Several Swedish official websites were knocked offline Monday, although no one has claimed responsibility for the attacks. "I can confirm that the government site had problems today, but for security reasons, I cannot say more," Anna Dahlen, a government spokeswoman, told AFP adding that she did not know when the site would be back online.

JERUSALEM - (AFP) - A reporter with Israel's Haaretz newspaper, Uri Blau, was sentenced to four months of community service under a plea bargain for possessing classified military documents, the court said on Monday. "I accept the the plea bargain reached by the parties, and sentence the accused to a single term of four months' jail which may be served by means of community service... starting from 11 September 2012," wrote the judge at Tel Aviv Magistrates Court.

Adobe has released a security update for Adobe Photoshop CS6 (13.0) for Windows and Mac OS X to address two security vulnerabilities that, if exploited, could let an attacker take over a system. Both flaws (CVE-2012-4170 and CVE-2012-0275) stem from buffer overflow vulnerabilities that could lead to code execution. At the time of publishing, Adobe said they have not seen any exploits in the wild related to the issues addressed in this security fix.

I made a mistake the other day, a horrible mistake. I let my kid use my computer.My once perfect computer now has a life of its own, a malware bot that nests firmly in a place that I not only can’t see, but never even suspected until it took up with a malware handler that taught it some very bad habits.

PHNOM PENH - (AFP) - A co-founder of top Swedish filesharing site The Pirate Bay, who is on an international wanted list, has been arrested in the Cambodian capital at Stockholm's request, police said Sunday.Gottfrid Svartholm Warg was handed a one-year prison sentence by a Swedish court in 2009 for promoting copyright infringement but failed to show up to serve his term at the start of this year. He was detained in Phnom Penh on Thursday, Cambodia's national police spokesman...

Taipei - (AFP) - Taiwan plans to beef up its cyberwar capabilities to counter a perceived threat from Chinese hackers targeting government and security websites, local media reported Sunday. Taiwan will expand its cyberwar units next year while scaling back military spending due to budget constraints, the Taipei-based Liberty Times reported, citing a 2013 budget plan submitted by the National Security Bureau to parliament for approval.

SAN FRANCISCO - (AFP) - Facebook ramped up efforts Friday to get rid of "Likes" that aren't from people genuinely interested in giving a virtual thumbs up to pages at the world's leading social network. "We have recently increased our automated efforts to remove Likes on pages that may have been gained by means that violate our Facebook terms" of service, the Facebook security team said in a blog post.

I was talking with a coworker a couple weeks back, and in the course of our conversation one of us mentioned the concept of perimeter security. That simple statement struck me then, and strikes me even more now: What is perimeter security?

It seems that Russia's defense ministry has little faith in Google's operating systems: it has just unveiled its own encrypted version that has the remarkably familiar feel of an Android. Russia's very first smart prototype was presented on the sidelines of a Berlin electronics show this week to Deputy Prime Minister Dmitry Rogozin -- an avowed nationalist who oversees the military's technological innovation.

Earlier this month, the world’s largest oil production company, Aramco, was attacked by the Shamoon virus. On Monday, a second attack forced one of Qatar's two main LNG (Liquid Natural Gas) production and export companies offline as well. Speculation has it that Shamoon is responsible for this as well.

WASHINGTON - (AFP) - A former civilian guard at a US consulate in China pleaded guilty Thursday to charges that he planned to sell secrets to Chinese security officials, the US Justice Department said. Bryan Underwood, a 32-year-old American who worked at the US consulate in the southeastern Chinese city of Guangzhou, pleaded guilty to "attempting to communicate national defense information to a foreign government."

It's almost as though the criminal hackers will be soon able to read your mind. And new research suggests that maybe they will be able to do so. Personal information, such as “bank cards, PIN numbers, area of living, the knowledge of the known persons,” might be inadvertently leaked through the use of brain-computer interface (BCI) devices used in high-end gaming consoles.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Security researchers uncover critical flaws and widespread misconfigurations in Salesforce’s industry-specific CRM solutions.

Cloud Security

Cloud Security

Cloud security startup Circumvent has raised $6 million to develop a network of agents for autonomous prioritization and remediation.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.