CONFERENCE NOW LIVE: Threat Detection & Incident Response (TDIR) Summit - Join the Event In-Progress
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Cisco published 10 security advisories detailing over a dozen vulnerabilities, including two high-severity flaws in its Identity Services Engine (ISE) and Unified Intelligence Center.

GitLab and Atlassian have released patches for over a dozen vulnerabilities in their products, including high-severity bugs.

Russian military intelligence hackers intensify targeting of Western logistics and technology companies moving supplies into Ukraine. 

Redmond’s threat hunters found 394,000 Windows systems talking to Lumma controllers, a victim pool that included global manufacturers. 

More than 100 AutomationDirect MB-Gateway devices may be vulnerable to attacks from the internet due to CVE-2025-36535.

SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st.

A mandatory filing to the Maine Attorney General says 69,461 customers nationwide were affected and dates the breach back to last December.

Matthew Lane allegedly hacked PowerSchool using stolen credentials and admitted to extorting a telecoms provider.

Wireless carrier Cellcom has confirmed that a week-long widespread service outage is the result of a cyberattack.

Google DeepMind has developed an ongoing process to counter the continuously evolving threatIndirect prompt injection (IPI) attacks.

Wiz warns that threat actors are chaining two recent Ivanti vulnerabilities to achieve unauthenticated remote code execution.

People on the Move

Jeremy Koppen has left Mandiant after 13 years to become the CISO of Equifax.

Engineering and technology solutions provider Amentum has appointed Max Shier as its CISO.

PAM provider Keeper Security has appointed Shane Barney as its Chief Information Security Officer.

SpecterOps has appointed Tim Bender as CFO, Pat Sheridan as CRO, and Bryce Hein as CMO.

CISA has officially announced the appointment of Madhu Gottumukkala as its new deputy director.

More People On The Move
ICS honeypot scanning ICS honeypot scanning

Many of the industrial control system (ICS) instances seen in internet scanning are likely or possibly honeypots, not real devices.

Pwn2Own Berlin 2025 results Pwn2Own Berlin 2025 results

Pwn2Own participants demonstrated exploits against VMs, AI, browsers, servers, containers, and operating systems.

NATO Locked Shields NATO Locked Shields

The 15th edition of NATO’s Locked Shields cyber defense exercise brought together 4,000 experts from 41 countries.

Top Cybersecurity Headlines

American steel giant Nucor on Wednesday disclosed a cybersecurity incident that bears the hallmarks of a ransomware attack.

The China-linked hacking group Earth Ammit has launched multi-wave attacks in Taiwan and South Korea to disrupt the drone sector.

Google bundles multiple safeguards under a single Android toggle to protect high-risk users from advanced mobile malware implants.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Join this webinar for a fascinating discussion to understand why data in itself is not enough to make informed decisions for prioritization.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

We have an Entire Commercial Class of Security Professionals, but Few Hackers. Where are our Cyber Warriors? 

Gaining unauthorized Internet access and hiding your tracks have become common skills for a whole generation that feels information and communication should be free, even at work.Cisco recently released its 2011 Connected World Technology Report which surveyed the world’s next generation workforce, and included the views of approximately 3,000 college students and young professionals in response to the following two questions:

A Leaked FBI Warning about Doxing Somewhat Misses the Bigger Picture.An FBI intelligence bulletin released over the weekend by Anonymous, says that law enforcement personnel and other victims are at risk for identity theft due to the nature of doxing, or exposing personal information on a victim to the public.

Iran has captured an RQ-170 drone used by the CIA, and according to unconfirmed reports from the Christian Science Monitor (CSM), the Iranians were able to pull off such a feat by targeting the drone’s GPS systems.The CSM interviewed an Iranian engineer who is said to be working as part of a team assigned to study the remotely piloted aircraft (RPA). He explained that the process of capturing the drone centered on spoofing the communications signal used to manage GPS.

Let’s start with the visual image of one of those mechanical claw arcade machines – the one where you insert a few quarters and grab a toy with a mechanical claw. These can be addictive games for some of us.Let’s take that same visual image. But instead of a claw dropping down onto a pile of beanie babies, let’s visualize a hacker reaching through your login screen and feeling around for your database. Picture the hacker running impenetrable scripts instead...

Provider of Cloud-Based Email Security and Compliance Solutions Could Raise Approximately $50 Million Through IPOProofpoint Inc., a Sunnyvale, California based provider of cloud-based security and compliance solutions, filed an S-1 registration statement with the Securities and Exchange Commission this week for a proposed initial public offering.

In today’s digital world, trust is a critical component as consumers spend considerable amounts of time online and on mobile devices shopping, searching and communicating. While these consumers are increasingly becoming concerned with privacy, businesses may be surprised to find out who their customers actually trust, and what it takes to maintain their trust.

Hitachi-LG Data Storage Execs Pay Fines and Head to Prison After Conspiring to Fix the Bidding for Contracts with HP, Dell, and MicrosoftThree Hitachi-LG Data Storage Inc. (HLDS) executives have agreed to pay fines and serve seven to eight months in a U.S. prison, after reaching a plea agreement with the U.S. Department of Justice on price fixing conspiracy charges related to optical disk drives.

France based INSIDE Secure, a provider of semiconductor solutions for secure transactions and digital identity, today announced that it has entered into an agreement to provide Intel with INSIDE’s Near Field Communication (NFC) products and technologies.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Code quality and security firm CodeAnt has secured $2 million in seed funding and it has been valued at $20 million.

Cloud Security

Cloud Security

VMware patches flaws that expose users to data leakage, command execution and denial-of-service attacks. No temporary workarounds available. 

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.