Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The latest release of the xAI LLM, Grok-4, has already fallen to a sophisticated jailbreak.

Noteworthy stories that might have slipped under the radar: Microsoft shows attack against AMD processors, SentinelOne details latest ZuRu macOS malware version, Indian APT DoNot targets governments. 

With IPOs taking longer than ever, the venture firm’s fund aims to keep startup veterans motivated while staying private.

The EU code is voluntary and complements the EU’s AI Act, a comprehensive set of regulations that was approved last year and is taking effect in phases.

Two vulnerabilities in an internal API allowed unauthorized access to contacts and chats, exposing the information of 64 million McDonald’s applicants.

Wing FTP Server vulnerability CVE-2025-47812 can be exploited for arbitrary command execution with root or system privileges.

The Irish Data Privacy Commission announced that TikTok is facing a new European Union privacy investigation into user data sent to China.

Since August 2015, Google has delivered a constant stream of monthly security patches for Android. Until July 2025.

Researchers demonstrated GPUHammer — a Rowhammer attack against GPUs — by degrading the accuracy of machine learning models.

Details have been disclosed for an eSIM hacking method that could impact many, but the industry is taking action.

Ingram Micro has restored operations across all countries and regions after disconnecting systems to contain a ransomware attack.

People on the Move

Jessica Newman has joined Sophos as General Manager of Global Cyber Insurance.

Breach and attack simulation solutions provider AttackIQ has appointed Pete Luban as Field Chief Information Security Officer.

Matthew Cowell has assumed the role of VP of Strategic Alliances at Nozomi Networks. He previously served in the same role at Dragos.

Bret Arsenault is retiring from his full-time role after 35 years at Microsoft.

Social engineering defense platform Doppel has appointed Bobby Ford as Chief Strategy and Experience Officer.

More People On The Move
Grok-4 Falls to a Jailbreak Two Days After Its Release

The latest release of the xAI LLM, Grok-4, has already fallen to a sophisticated jailbreak.

Android vulnerability patch Android vulnerability patch

Since August 2015, Google has delivered a constant stream of monthly security patches for Android. Until July 2025.

eSIM hacking eSIM hacking

Details have been disclosed for an eSIM hacking method that could impact many, but the industry is taking action.

Top Cybersecurity Headlines

PCA Cyber Security has discovered critical vulnerabilities in the BlueSDK Bluetooth stack that could have allowed remote code execution on car systems.

Nippon Steel Solutions has disclosed a data breach that resulted from the exploitation of a zero-day in network equipment.

Xu Zewei has been arrested on charges that he is a member of the Chinese state-sponsored hacking group Hafnium (Silk Typhoon).

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

This online session will explore resilience planning in response to geopolitical tensions and help CISOs navigate the current state of federal cybersecurity initiatives.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

According to IDG News, who spoke to Adam Gowdiak, the founder and CEO of Polish security firm Security Explorations, Oracle was told about the issues currently leaving Java users exposed to attack back in April. In response, US-CERT has come forward in order to urge users and IT teams to disable Java.

NEW DELHI - (AFP) - India ended its ban on bulk text messages Thursday, two weeks after imposing restrictions to halt the spread of threats and rumours that sparked an exodus of migrants fearing attack.

Enterprises Experience 643 “Advanced Malware” Infections Each WeekAccording to FireEye’s most recent threat report released today, organizations are seeing a massive increase in advanced malware that is working its way inside enterprise walls by bypassing traditional IT security defenses.

In my previous SecurityWeek column, I wrote about how information is at the heart of most U.S. bills to secure the Internet. From CISPA to CSA to SECURE IT, all of these bills have one common tactic they are looking to tap: information sharing. My colleagues and I have a more descriptive saying for exactly what this is.

The zero-day in Java that SecurityWeek reported on Monday has gotten worse, as it can be targeted from within the Blackhole Exploit Kit and Metasploit. While this means good guys can use Metasploit as a means to proactive protection, the bad guys now have a way to automate victim collection.

Raynaldo Rivera, a 20 year-old from Tempe, Arizona, surrendered to authorities in Phoenix on Tuesday. Rivera stands accused of being a member of LulzSec and taking part in their attack on Sony last year. If true, he would be the second member of the group arrested in connection to the attack.

VMworld 2012 - HP announced on Tuesday that it would integrated their own portfolio of cloud-based services introduced in April, with VMware’s newest suite, vCloud 5.1. HP’s Converged Cloud enables customers to integrate various combinations of private, managed, and public cloud deployments, in addition to traditional IT, from an offering built on a single open architecture.

FORT MEADE, Maryland - (AFP) - Lawyers for the US soldier charged with passing a trove of classified documents to WikiLeaks accused the military Tuesday of withholding hundreds of emails over fears of a publicity nightmare. The defense team for Private Bradley Manning, who could be jailed for life for "aiding the enemy" over the massive security breach, alleged that more than 1,300 messages were ignored by prosecutors for at least six months.

VMworld 2012 – NetApp has announced a new integration between their Data ONTAP 8 software and VMware’s vSphere 5.1 in order to offer customers the ability to deliver and manage data migration between hundreds of virtual machines at once.

Intel and VMware are partnering to bring more security into the cloud using hardware-based security technologies. The two companies announced this week that VMware's vSphere 5.1 platform will support Intel's Trusted Execution Technology (TXT). The integration will provide a hardened platform for organizations to run their business-critical applications in both private and public clouds.

Radware Discovers “Admin.HLP” - A New Keylogger Used in Targeted Attack Security researchers from Radware have discovered a new Trojan Key Logger named “Admin.HLP” that they say captures sensitive user information and attempts to export it to a server in a remote location.

Splunk, the recently gone public provider of software that helps organizations gather and make use of machine data from a diverse set of sources, today launched Splunk Storm, a cloud service based on its flagship Splunk software.

As you are likely aware, the number of generic top-level domains (gTLDs) is about to increase dramatically. In June, the Internet Corporation for Assigned Names and Numbers (ICANN) announced that 1,930 applications were filed for New gTLDs (and although six applications were recently withdrawn, that leaves 1,924 applications in play). Domains that might go live in the months and years ahead include .CLOUD, .BUY, .BOOK and .APP, which received 13 separate requests to be delegated as a gTLD.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

RevEng.ai has raised $4.15 million in seed funding for an AI platform that automatically detects malicious code and vulnerabilities in software.

Cloud Security

Cloud Security

Founded in 2015, the Tel Aviv based company has now raised more than $1 billion and claims more than 3,500 customers.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.