Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

San Francisco identity security play Veza closes a Series D fund round led by New Enterprise Associates (NEA).

Threat actors have exploited a zero-day vulnerability in Craft CMS to execute PHP code on hundreds of websites.

VeriSource Services says the personal information of 4 million people was compromised in a February 2024 cyberattack.

Planet Technology industrial switches and network management products are affected by several critical vulnerabilities. 

Hundreds of companies are showcasing their products and services this week at the 2025 edition of the RSA Conference in San Francisco.

MTN Group says the personal information of certain customers was compromised in a cybersecurity incident.

Oregon’s environmental agency won’t say if a group of hackers stole data in a cyberattack that was first announced earlier this month.

Cynomi announced a new $37 million Series B funding to grow its AI-powered vCISO platform for MSPs and MSSPs.

SquareX offers what it has dubbed a “Browser Detection and Response (BDR)” solution.

Venables has served as CISO and security executive across several large organizations, including Google Cloud, Goldman Sachs, Deutsche Bank.

Lattica has raised $3.25 million in pre-seed funding for a platform that uses FHE to enable AI models to process encrypted data. 

People on the Move

Wendi Whitmore has taken the role of Chief Security Intelligence Officer at Palo Alto Networks.

Phil Venables, former CISO of Google Cloud, has joined Ballistic Ventures as a Venture Partner.

David Currie, former CISO of Nubank and Klarna, has been appointed CEO of Vaultree.

Chris Burger has been named Chief Information Security Officer at F5.

Bedrock Security has appointed George Gerchow as Chief Security Officer.

More People On The Move
RSA Conference 2025 RSA Conference 2025

Hundreds of companies are showcasing their products and services this week at the 2025 edition of the RSA Conference in San Francisco.

SAP zero-day exploited SAP zero-day exploited

A zero-day vulnerability in SAP NetWeaver potentially affects more than 10,000 internet-facing applications.

Healthcare data breach Healthcare data breach

Yale New Haven Health System recently discovered that the personal information of millions of patients was stolen from its systems.

Top Cybersecurity Headlines

British retailer Marks & Spencer has been experiencing certain service disruptions after falling victim to a cyberattack.

SK Telecom, South Korea’s largest telecom company, disclosed a data leak involving a malware infection.

Microsoft security chief Charlie Bell says the SFI’s 28 objectives are “near completion” and that 11 others have made “significant progress.”

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

This webinar will guide you in aligning your security testing strategy with the right tools, helping you move beyond identifying weaknesses to effectively validating your overall security posture.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

The recent and ongoing Occupying Wall Street rally is an interesting and refreshing exercise in US democracy at its best. Starting out with just 200 protesters in mid-September, the New York City rally has grown to thousands of activists, with similar protests in 30 cities including Chicago, Boston and Denver. Initially scoffed at as being "leaderless" and "directionless", the Occupying Wall Street rally appears to be moving towards focusing on defining such lofty demands as ending the death penalty, ending...

After a relatively quiet Patch Tuesday in September, Microsoft is releasing fixes for 23 separate vulnerabilities in its security update next week.The patches will be spread across eight bulletins – two rated ‘Critical’, six designated ‘Important’ – and will touch Internet Explorer, Microsoft Windows, Microsoft Forefront Unified Access Gateway (UAG), Microsoft Host Integration Server, the .NET Framework and Silverlight.

Developers Leave Debug Tool Open for The World to Use, Including AttackersDevelopers from American Express have made somewhat of a big mistake recently, leaving an administration panel for Web site debugging wide open for anyone to access, providing a potential tool and avenue for attackers to target AMEX customers. (Update: Amex appears to finally have closed access to the admin panel within the past hour, as of 11:15AM EST on Oct 6.)

Before there was concern over VM stall, there was that of VM sprawl.VM sprawl had organizations worrying that so many virtual machines would be spun up (thanks to the ease of deploying them) that not only would management become an issue, but so, too, would performance, security, and IT staffing.

Update: NetQin Mobile reached out to SecurityWeek to let us know that they had previously identified the same malware under the name AnserverBot on September 19th. Dr. XuXian Jiang, Chief Scientist at NetQin’s US Security Research Center, offers a detailed report on how the malware works. - Editor

According to a recent report from the Government Accountability Office, despite efforts to implement stronger cybersecurity controls, several federal agencies remain in a weakened state. Since 2006, security incident reports have risen over 650-percent.

New Release Helps Protect Sensitive Data, Brings Centralized Management of Enterprise Wide Database Security MeasuresOn Monday at Oracle Open World, Oracle’s giant customer conference taking place this week in San Francisco, Oracle unveiled new and improved database security features in Oracle Enterprise Manager 12c.

McAfee today announced that it has agreed to acquire NitroSecurity, a privately held provider of high-performance security information and event management (SIEM) solutions.The company’s founders and roots come from the U.S. Department of Energy’s Idaho National Laboratory, giving it extensive experience with critical infrastructures in the energy sector, creating a sweet spot for the Portsmouth, NH-based company in a sector that has come into the spotlight following Stuxnet and a general rise in concern over critical infrastructure security.

SIEM vendors are all jumping on the Security Intelligence tag line, but what does it really mean? The bad guys are getting more sophisticated and the quality and breadth of intelligence is crucial to early identification and thwarting attacks. Can SIEM bring the analog of human intelligence (aka, espionage) to cyber threats and the security visibility of business intelligence to the executive boardroom?Defining the threat landscape:

VASCO Data Security, parent of recently “hacked out of business” Certificate Authority (CA), DigiNotar, has shared additional information on the expected losses surrounding the recent cyber attack that forced the company into bankruptcy.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Software and AI supply chain transparency firm Manifest has raised $15 million in a Series A funding round led by Ensemble VC.

Cloud Security

Cloud Security

San Francisco identity security play Veza closes a Series D fund round led by New Enterprise Associates (NEA).

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.