Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Israel-linked Predatory Sparrow hackers torched more than $90 million at Iran’s largest cryptobank as Israel-Iran cyberwar escalates.

Trend Micro and ReversingLabs uncovered over 100 GitHub accounts distributing malware embedded in open source hacking tools.

A ransomware group has claimed the theft of millions of files from procurement service provider Chain IQ and 19 other companies.

After decades of failed attempts to access encrypted communications, governments are shifting from persuasion to coercion—security experts say the risks are too high.

Krispy Kreme is sending notifications to thousands of people impacted by the data breach that came to light at the end of 2024.

In a rapidly changing AI environment, CISOs are worried about investing in the wrong solution or simply not investing because they can’t decide what the best option is.

Cisco has resolved a high-severity vulnerability in Meraki MX and Meraki Z devices. Atlassian pushed patches for multiple third-party dependencies.

A hacker is selling allegedly valuable data stolen from Scania, but the truck maker believes impact is very limited.

Russian hackers posed as US State Department staff and convinced targets to generate and give up Google app-specific passwords.

Misconfigured permissions in Google’s Gerrit code collaboration platform could have led to the compromise of ChromiumOS and other Google projects.

Citrix has released patches for critical- and high-severity vulnerabilities in NetScaler and Secure Access Client and Workspace for Windows.

People on the Move

Checkmarx has appointed Scott Gainey as Chief Marketing Officer.

Jason Hogg has been named Executive Chairman of CYPFER.

HUB Cyber Security has appointed former PayPal and American Express executive Paul Parisi as its Global Chief Revenue Officer.

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

More People On The Move
Encryption backdoor debate Encryption backdoor debate

After decades of failed attempts to access encrypted communications, governments are shifting from persuasion to coercion—security experts say the risks are too high.

Scania hack Scania hack

A hacker is selling allegedly valuable data stolen from Scania, but the truck maker believes impact is very limited.

Gmail E2EE encryption Gmail E2EE encryption

Russian hackers posed as US State Department staff and convinced targets to generate and give up Google app-specific passwords.

Top Cybersecurity Headlines

OpenAI has been awarded a $200 million contract for AI capabilities to help the Defense Department address national security challenges.

Hackers have stolen personal and health information belonging to the customers of healthcare organizations served by Episource.

Google is warning insurance companies that Scattered Spider appears to have shifted its focus from the retail sector. 

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Backupify, a provider of online backup services for cloud application data, today announced that it has secured $9 million in series C funding that will be used to accelerate further development and adoption of its backup tools.

Researchers have uncovered a new Web-based exploit that targets Windows, Linux, and Mac OS X computers.Users visiting a specially crafted website are prompted to run a Java applet that hasn't been signed by a trusted certificate authority, Karmina Aquino, a senior analyst at F-Secure, wrote in a blog post July 10. If allowed to run, the applet checks the user's operating system and delivers a payload customized for that platform, whether it's Windows, Mac OS X, or Linux.

Symantec found two malicious apps on Google Play that may have infected up to 100,000 users before it was removed by Google. The malware posed as two apps, "Super Mario Bros." and "GTA3 Moscow City," and used a remote payload technique to avoid detection, Irfan Asrar, a security researcher from Symantec, wrote on the Symantec Connect blog July 10. Both apps appeared on Google Play on June 24, and racked up between 50,000 to 100,000 downloads in less than two...

Email messaging and Web security solutions firm AppRiver, its mid-year Threat and Spamscape report, noted a significant uptick in malware-laden messages during the first half of this year. The report, which focuses on spam and malware trends, showed strong continued appearances of popular malware including Zeus, SpyEye, and the Blackhole toolkit, and a rise in mobile malware—echoing other recent vendor reports.

Plesk, a popular Web hosting control panel – second to cPanel in the hosting market – was recently updated in order to address Remote File Inclusion vulnerabilities. This flaw is being blamed for a rash of website compromises, which successfully targeted some 50,000 domains.

After detecting an increase in malicious attempts to access user accounts, the retail giant Best Buy is alerting customers to reset their passwords. However, it appears that the warning is confusing some users. The letter starts as one would expect; “Dear Valued Best Buy Customer.” From there, the message to customers says that the company is investigating increased attempts from attackers around the globe, who appear to be targeting BestBuy.com and other e-commerce sites.

Formspring, the Social Q&A portal focused on conversations and personal interests, admitted to being breached on Tuesday. The compromise led to the loss of 420,000 hashed passwords, forcing the website to reset the passwords used by every member.

Websense announced a number of enhancements today to the latest version of its TRITON Web, email and data security product to help customers fight off attackers.Websense's Advanced Classification Engine (ACE) has been armed with 10 new defenses in TRITON 7.7, including: detecting criminal encrypted uploads, optical character recognition of text within images for data-in-motion and geo-location awareness.

Attackers are increasingly shifting their focus on smaller businesses when crafting targeted attacks, according to Symantec's monthly threat report. The June 2012 Symantec Intelligence Report found that 36 percent of all targeted attacks that were detected over the last six months were directed at businesses with 250 or fewer employees. In comparison, a mere 18 percent of targeted attacks went after small businesses in December 2011.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Security researchers uncover critical flaws and widespread misconfigurations in Salesforce’s industry-specific CRM solutions.

Cloud Security

Cloud Security

Cloud security startup Circumvent has raised $6 million to develop a network of agents for autonomous prioritization and remediation.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.