CONFERENCE Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit - Join the Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A mandatory filing to the Maine Attorney General says 69,461 customers nationwide were affected and dates the breach back to last December.

Matthew Lane allegedly hacked PowerSchool using stolen credentials and admitted to extorting a telecoms provider.

Wireless carrier Cellcom has confirmed that a week-long widespread service outage is the result of a cyberattack.

Google DeepMind has developed an ongoing process to counter the continuously evolving threatIndirect prompt injection (IPI) attacks.

Wiz warns that threat actors are chaining two recent Ivanti vulnerabilities to achieve unauthenticated remote code execution.

SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st.

Many of the industrial control system (ICS) instances seen in internet scanning are likely or possibly honeypots, not real devices.

Kettering Health has canceled inpatient and outpatient procedures as it deals with a system-wide outage caused by a ransomware attack.

An OpenPGP.js vulnerability tracked as CVE-2025-47934 allows message signature verification to be spoofed. 

VMware patches flaws that expose users to data leakage, command execution and denial-of-service attacks. No temporary workarounds available. 

The Likely Exploited Vulnerabilities (LEV) equations can help augment KEV- and EPSS-based remediation prioritization. 

People on the Move

PAM provider Keeper Security has appointed Shane Barney as its Chief Information Security Officer.

SpecterOps has appointed Tim Bender as CFO, Pat Sheridan as CRO, and Bryce Hein as CMO.

CISA has officially announced the appointment of Madhu Gottumukkala as its new deputy director.

Cloud and cybersecurity MSP Ekco has appointed Ben Savage as UK CEO.

Shane Barney has been appointed CISO of password management and PAM solutions provider Keeper Security.

More People On The Move
TDIR Virtual Summit TDIR Virtual Summit

SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st.

ICS honeypot scanning ICS honeypot scanning

Many of the industrial control system (ICS) instances seen in internet scanning are likely or possibly honeypots, not real devices.

Pwn2Own Berlin 2025 results Pwn2Own Berlin 2025 results

Pwn2Own participants demonstrated exploits against VMs, AI, browsers, servers, containers, and operating systems.

Top Cybersecurity Headlines

The 15th edition of NATO’s Locked Shields cyber defense exercise brought together 4,000 experts from 41 countries.

American steel giant Nucor on Wednesday disclosed a cybersecurity incident that bears the hallmarks of a ransomware attack.

The China-linked hacking group Earth Ammit has launched multi-wave attacks in Taiwan and South Korea to disrupt the drone sector.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Join this webinar for a fascinating discussion to understand why data in itself is not enough to make informed decisions for prioritization.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Last December, train service and rail schedules were disrupted, according to a TSA memo, after intruders managed to access the network of a rail company in the Pacific Northwest. Initially, the incident was thought to be a targeted attack, but further investigation shows that wasn’t the case.

Microsoft is not just taking down botnets; it is taking them down and naming names.In an amended complaint filed Monday in U.S. District Court for the Eastern District of Virginia, Microsoft named Andrey N. Sabelnikov of St. Petersburg, Russia, as the alleged head of the notorious Kelihos botnet.

AlertEnterprise, a Freemont, California-based provider of security, risk, and compliance management software, today launched AlertEnterprise Compliance Express, a NERC Critical Infrastructure Protection (CIP) compliance solution designed for smaller organizations such as Cooperative and Municipal Utilities.

New Solution Helps Enterprises Discover, Understand and Block Malware Utilizing Big Data AnalyticsSourcefire today introduced a new malware protection and analysis solution designed to work alongside traditional endpoint security solutions and help discover malware threats that may have been missed by existing endpoint defenses.

New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E) today disclosed that they have suffered from a data breach, including unauthorized access to customer records which include customer names, Social Security numbers, dates of birth and, in some cases, financial institution account numbers.

The European Commission stated that on January 25, it will propose several changes to the data protection and privacy rules put into place over 15-years ago. The changes, the commission said, focus on reinforcing individuals’ rights, strengthening the EU market, and ensuring a high level of data protection.The proposed changes will streamline the existing policies and rules currently used by the 27 countries that make up the European Union. While there is plenty of overlap in the EU, there are...

The U.S. Air Force says it knows what caused an RQ-170 drone to crash in Iran, but will not release specific details. What’s certain, Air Force Chief of Staff General Norton Schwartz told Reuters, is that Iran had nothing to do with it.

Research In Motion Names Thorsten Heins as President & CEOBlackBerry maker Research In Motion on Sunday announced that it has named Thorsten Heins as President and Chief Executive Officer of the struggling mobile device maker.

On Thursday, Rapid7 announced that a new Metasploit module, designed to target the GE D20 PLC, was ready for use. The SCADA focused addition is part of Project Basecamp, which seeks to prove the flexibility of the Metasploit framework.

I am a millionaire. Actually, I’m a multi-millionaire. Or rather I could be if I helped the honorable Mr. Nagumba get his money out of Nigeria, or helped Barbara get her money out of Brazil, or picked up my unclaimed lottery winnings, or helped another half dozen people in the last month.

Anonymous Launches #OpMegaupload, Launches Massive DDoS Attacks Against Multiple Targets in Retaliation for Action Against Megaupload.ComThe Anonymous collective moved swiftly today, in response to actions taken by the Justice Department against operators of Megaupload.com, a wildly popular file sharing and online storage service.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Code quality and security firm CodeAnt has secured $2 million in seed funding and it has been valued at $20 million.

Cloud Security

Cloud Security

VMware patches flaws that expose users to data leakage, command execution and denial-of-service attacks. No temporary workarounds available. 

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.