Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Sentra has now raised north of $100 million for controls technology to keep sensitive data out of misconfigured AI workflows.

DataKrypto’s FHEnom for AI combines real-time homomorphic encryption with trusted execution environments to protect enterprise data and models from leakage, exposure, and tampering.

The city of Abilene, Texas, is scrambling to restore systems that have been taken offline in response to a cyberattack.

A vulnerability in SSL.com has resulted in nearly a dozen certificates for legitimate domains being wrongly issued.

Hopper has emerged from stealth mode with a solution designed to help organizations manage open source software risk.

Security researchers detail various malware campaigns that use bulletproof services linked to Proton66 ASN.

A sophisticated phishing campaign abuses weakness in Google Sites to spoof Google no-reply addresses and bypass protections.

Transnational organized crime groups in East and Southeast Asia are spreading their lucrative scam operations across the globe, according to a UN report.

Bell Ambulance and Alabama Ophthalmology Associates have suffered data breaches affecting over 100,000 people after being targeted in ransomware attacks.

Microsoft security chief Charlie Bell says the SFI’s 28 objectives are “near completion” and that 11 others have made “significant progress.”

North Korean cryptocurrency thieves abusing Zoom Remote collaboration feature to target cryptocurrency traders with malware.

People on the Move

DARPA veteran Dan Kaufman has joined Badge as SVP, AI and Cybersecurity.

Kelly Shortridge has been promoted to VP of Security Products at Fastly.

After the passing of Amit Yoran, Tenable has appointed Steve Vintz and Mark Thurmond as co-CEOs.

Former Wiz executive Trish Cagliostro has joined Orchid Security as Chief Revenue Officer.

Transcend has named former UnitedHealth Group CISO Aimee Cardwell as CISO in Residence.

More People On The Move
Microsoft vulnerability Microsoft vulnerability

Microsoft security chief Charlie Bell says the SFI’s 28 objectives are “near completion” and that 11 others have made “significant progress.”

Privacy of Social Media and Internet Apps Privacy of Social Media and Internet Apps

With unapproved AI tools entrenched in daily workflows, experts say it’s time to shift from monitoring to managing Shadow AI use across the enterprise.

Windows vulnerability exploited Windows vulnerability exploited

A Windows NTLM vulnerability patched in March has been exploited in attacks targeting government and private institutions.

Top Cybersecurity Headlines

A SonicWall SMA 100 series vulnerability patched in 2021, which went unnoticed at the time of patching, is being exploited in the wild.

The vulnerabilities are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms.

The US government’s cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

This webinar will guide you in aligning your security testing strategy with the right tools, helping you move beyond identifying weaknesses to effectively validating your overall security posture.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Finnish security vendor F-Secure, along with the U.K.’s Sophos, have each pledged to detect a new backdoor, allegedly developed and used by the German government. The news comes via the Chaos Computer Club (CCC) in Germany, who released a report about the malware on Saturday.

Kaspersky Lab has released what it declared as the most significant “business related” products it has released in four years. Officially launched on Thursday, Kaspersky Endpoint Security 8 for Windows and Kaspersky Security Center include new multi-layer anti-malware protection, powered by Kaspersky’s intelligence network.

Three unencrypted backup tapes containing sensitive personal data have been reported missing by Nemours, a children's health care services provider.The tapes in question were reported missing from a facility in Wilmington, Delaware on September 8, 2011. The company believes they have been removed around August 10, 2011 during a renovation project.

Baltimore-based data protection vendor SafeNet, said on Friday that it has received baseline approval from the US Government for its new MDeX system.MDeX, or Multi-Domain eXchange, was designed to address cross domain data sharing between government organizations. Earning a Unified Cross Domain Management Office (UCDMO) Cross Domain Inventory, Version 4.0 baseline, means that SafeNet is now free to offer MDeX to departments such as Homeland Security, and other intelligence agencies.

The recent and ongoing Occupying Wall Street rally is an interesting and refreshing exercise in US democracy at its best. Starting out with just 200 protesters in mid-September, the New York City rally has grown to thousands of activists, with similar protests in 30 cities including Chicago, Boston and Denver. Initially scoffed at as being "leaderless" and "directionless", the Occupying Wall Street rally appears to be moving towards focusing on defining such lofty demands as ending the death penalty, ending...

After a relatively quiet Patch Tuesday in September, Microsoft is releasing fixes for 23 separate vulnerabilities in its security update next week.The patches will be spread across eight bulletins – two rated ‘Critical’, six designated ‘Important’ – and will touch Internet Explorer, Microsoft Windows, Microsoft Forefront Unified Access Gateway (UAG), Microsoft Host Integration Server, the .NET Framework and Silverlight.

Developers Leave Debug Tool Open for The World to Use, Including AttackersDevelopers from American Express have made somewhat of a big mistake recently, leaving an administration panel for Web site debugging wide open for anyone to access, providing a potential tool and avenue for attackers to target AMEX customers. (Update: Amex appears to finally have closed access to the admin panel within the past hour, as of 11:15AM EST on Oct 6.)

Before there was concern over VM stall, there was that of VM sprawl.VM sprawl had organizations worrying that so many virtual machines would be spun up (thanks to the ease of deploying them) that not only would management become an issue, but so, too, would performance, security, and IT staffing.

Update: NetQin Mobile reached out to SecurityWeek to let us know that they had previously identified the same malware under the name AnserverBot on September 19th. Dr. XuXian Jiang, Chief Scientist at NetQin’s US Security Research Center, offers a detailed report on how the malware works. - Editor

According to a recent report from the Government Accountability Office, despite efforts to implement stronger cybersecurity controls, several federal agencies remain in a weakened state. Since 2006, security incident reports have risen over 650-percent.

New Release Helps Protect Sensitive Data, Brings Centralized Management of Enterprise Wide Database Security MeasuresOn Monday at Oracle Open World, Oracle’s giant customer conference taking place this week in San Francisco, Oracle unveiled new and improved database security features in Oracle Enterprise Manager 12c.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Cloud Security

Cloud Security

The greatest security policies in the world are useless if enterprises don’t have a reasonable, consistent, and reliable way to implement them.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.