Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Enterprises running SharePoint servers should not wait for a fix for CVE-2025-53770 and should commence threat hunting to search for compromise immediately.

Noteworthy stories that might have slipped under the radar: powerful US law firm hacked by China, Symantec product flaw, $10,000 Meta AI hack, cryptocurrency thieves bypassing FIDO keys. 

AI-native email security firm StrongestLayer has emerged from stealth mode with $5.2 million in seed funding.

Dozens of FortiWeb instances have been hacked after PoC targeting a recent critical vulnerability was shared publicly.

Radiology Associates of Richmond has disclosed a data breach impacting protected health and personal information. 

With generative AI enabling fraud-as-a-service at scale, legacy defenses are crumbling. The next wave of cybercrime is faster, smarter, and terrifyingly synthetic.

The CitrixBleed 2 vulnerability in NetScaler may expose organizations to compromise even if patches have been applied.

Google has filed a lawsuit against the Badbox 2.0 botnet operators, after identifying over 10 million infected Android devices.

Wiz researchers discovered NVIDIAScape, an Nvidia Container Toolkit flaw that can be exploited for full control of the host machine.

Anne Arundel Dermatology said hackers had access to its systems for three months and may have stolen personal and health information. 

A settlement has been reached in the class action brought by investors against Meta over the Cambridge Analytica incident, but details have not been shared.

People on the Move

Coro, a provider of cybersecurity solutions for SMBs, has appointed Joe Sykora as CEO.

SonicWall has hired Rajnish Mishra as Senior Vice President and Chief Development Officer.

Kenna Security co-founder Ed Bellis has joined Empirical Security as Chief Executive Officer.

Robert Shaker II has joined application security firm ActiveState as Chief Product and Technology Officer.

MorganFranklin Cyber has promoted Nick Stallone and Ferdinand Hamada into newly created roles.

More People On The Move
SharePoint Vulnerability CVE-2025-53770 SharePoint Vulnerability CVE-2025-53770

Enterprises running SharePoint servers should not wait for a fix for CVE-2025-53770 and should commence threat hunting to search for compromise immediately.

AI use in Fraud AI use in Fraud

With generative AI enabling fraud-as-a-service at scale, legacy defenses are crumbling. The next wave of cybercrime is faster, smarter, and terrifyingly synthetic.

Badbox 2 botnet lawsuit by Google Badbox 2 botnet lawsuit by Google

Google has filed a lawsuit against the Badbox 2.0 botnet operators, after identifying over 10 million infected Android devices.

Top Cybersecurity Headlines

Wiz researchers discovered NVIDIAScape, an Nvidia Container Toolkit flaw that can be exploited for full control of the host machine.

Oracle’s July 2025 Critical Patch Update contains 309 security patches that address approximately 200 unique CVEs.

Cyberattack disrupted UNFI’s operations in June; company estimates $50–$60 million net income hit but anticipates insurance will cover most losses.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

This online session will explore resilience planning in response to geopolitical tensions and help CISOs navigate the current state of federal cybersecurity initiatives.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

A digital publisher said Monday it was likely the source of a data breach which resulted in the leak of personal data from as many as 12 million Apple iPhone and iPad users. Hackers initially claimed the data containing Apple identification codes known as UDIDs was stolen from an FBI computer, but the US law enforcement agency claimed this was incorrect.

On Sunday, after dealing with an attack on their website earlier in the week, Qatar-based news organization Al Jazeera suffered another attack at the hands of pro-Syrian hackers. The news agency said on Twitter that their SMS news service was compromised, and used to spread propaganda. In a message posted to Twitter on Sunday, Al Jazeera Arabic said that their SMS service was compromised by “pirates” who used the hijacked access to “send fake news with no basis.”

Tenable Network Security, makers of vulnerability scanners and software solutions that helps find network security gaps, this week announced that it has raised $50 million in its first-round funding from Accel Partners. The company said it would use the cash boost to expand its security offerings and accelerate global growth, as well as deepening its research into threats.

Back in early 2010, Google announced it had been a victim of a persistent and sophisticated attack conducted over a sustained period of time. According to Google, the attackers behind "Operation Aurora" were from China and had the backing of the Chinese government.

Google Broadens Its Security Insight With Acquisition of VirusTotalGoogle has acquired VirusTotal, the popular service that lets users analyze suspicious files and URLs to help facilitate the detection of malware.

Last month, an (electronic) age old debate was rekindled by an article penned by Dave Aitel titled “Why you shouldn't train employees for security awareness”. His basic argument is that the money and time invested in Security Awareness Training is better spent elsewhere to better effect.

Reuters is reporting that sources close to the investigation efforts in the Aramco attack are reporting that insiders are partly responsible. In August, Aramco, Saudi Arabia’s national oil company – and the world’s largest oil producer – had to contend with a malware outbreak that hit 30,000 systems in a single go.

On Thursday, Joshua Schichtel was sentenced to 30 months in prison, and ordered to three years of supervised release. The sentence comes after he pled guilty to selling access to botnets last August. Schichtel, 30, of Phoenix, Arizona, pled guilty to one count of attempting to cause damage to multiple computers without authorization by the transmission of programs, codes or commands. 

Analyzing data collected and categorized by the Privacy Rights Clearinghouse, researchers at Rapid7 crunched the numbers and determined that over the last three years, more than 94 million records containing personally identifiable information (PII) were exposed due to data breaches in the government sector.

NEW YORK, NY - Netherlands-based AVG Technologies, maker of popular free and premium Internet security software, this week officially launched its 2013 product line. The AVG 2013 lineup includes new versions of the company’s free and paid products, and additional enhancements to its security and performance optimization products.

The US Secret Service is investigating claims that someone has stolen the Mitt Romney’s tax returns, with plans to release them of their demands are not met. News of the extortion broke late Wednesday, after the discovery of a post on Pastebin with the claims. As it turns out, campaign offices for both the Democrats and Republicans had received the extortion demands late last week.

Huawei, the Chinese telecom giant subject to an investigation on Capitol Hill looking into their alleged ties to the PLA, has published a report on cyber security perspectives. The report is a mix of company promotion, as well as an indirect answer to Congress’ claims.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

RevEng.ai has raised $4.15 million in seed funding for an AI platform that automatically detects malicious code and vulnerabilities in software.

Cloud Security

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.