Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Noteworthy stories that might have slipped under the radar: Cloudflare outage not caused by cyberattack, Dutch police identified 126 users of Cracked.io, the Victoria’s Secret cyberattack has cost $10 million. 

Threat actors have abused the TeamFiltration pentesting framework to target over 80,000 Entra ID user accounts.

Industry professionals comment on the Trump administration’s new executive order on cybersecurity. 

CISA warns that vulnerable SimpleHelp RMM instances have been exploited against a utility billing software provider’s customers.

Multiple legitimate, unusual tools were used in a Fog ransomware attack, including one employed by Chinese hacking group APT41.

Mitel has announced patches for a MiCollab path traversal vulnerability that can be exploited remotely without authentication.

Trend Micro patches critical-severity Apex Central and Endpoint Encryption PolicyServer flaws leading to remote code execution.

ZeroRISC has raised $10 million in seed funding for production-grade open source silicon security, built on OpenTitan designs.

Citizen Lab publishes forensic proof that spyware maker Paragon can compromise up-to-date iPhones. Journalists in Europe among victims.

AI-generated voice deepfakes have crossed the uncanny valley, fueling a surge in fraud that outpaces traditional security measures. Detection technology is racing to keep up.

Hirundo tackles AI hallucinations and bias by making trained models “forget” poisoned, malicious, and confidential data.

People on the Move

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

Cybersecurity training and simulations provider SimSpace has appointed Peter Lee as Chief Executive Officer.

Orchid Security has appointed a new Chief Product Officer and three advisors.

Kaseya has appointed Rania Succar as Chief Executive Officer.

More People On The Move
Trump Cybersecurity Executive Order Trump Cybersecurity Executive Order

Industry professionals comment on the Trump administration’s new executive order on cybersecurity. 

Mitel MiCollab vulnerabilities Mitel MiCollab vulnerabilities

Mitel has announced patches for a MiCollab path traversal vulnerability that can be exploited remotely without authentication.

Deepfake voice Deepfake voice

AI-generated voice deepfakes have crossed the uncanny valley, fueling a surge in fraud that outpaces traditional security measures. Detection technology is racing to keep up.

Top Cybersecurity Headlines

The new attack technique uses smartwatches to capture ultrasonic covert communication in air-gapped environments and exfiltrate data.

Interpol has announced a crackdown on infostealer malware in Asia as part of an effort called Operation Secure.

Series E funding round brings Cyera’s total funding to over $1.3 billion and values the data security firm at $6 billion.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Former Iron Mountain CEO Joins Cloud-Based Application Security Provider Veracode, a provider of application security testing technology, today announced that it has appointed Bob Brennan as CEO of the Burlington, Massachusetts based company.

Undercover Agents Made Online Purchases to Identify Sellers of Counterfeit Goods, Leading to Seizure of 150 Domain NamesAs part of an effort to combat the growing number of domestic and international intellectual property crimes and defend against those who seek to profit illegally from American creativity, innovation and work, U.S. Federal authorities seized 150 domain names of websites involved in the illegal sale and distribution of counterfeit goods.

Delta Air Lines today announced that David DeWalt, former president, chief executive officer and director at McAfee, has joined the company’s board of directors.DeWalt served as president, chief executive officer and director of McAfee from April 2007 until February 2011, after Intel’s surprise $7.68 billion acquisition of McAfee. DeWalt resigned from his role as President at McAfee in July 2011. 

The Philippines Criminal Investigation and Detection Group (CIDG) said on Saturday that with the help of the FBI, four people have been arrested and stand accused of running remote toll scam in order to fund terrorism.

The Minister for the Cabinet Office and Paymaster General, Francis Maude, published a set of plans on Friday outlining the UK’s goals over the next four years that will introduce sweeping changes to the nation’s cyber security posture.In all, Maude said that the plan is to spend £650m GBP over the next four year on a National Cyber Security Program (NCSP), designed to make the UK, “one of the most secure places in the world to do business.”

Hungarian Hacker Pleads Guilty After Hacking into Marriott Computers and Extorting Job in Company's IT DepartmentA tough global economy has certainly created challenges for many people looking for jobs, but one Hungarian man took things to another level in an effort to gain employment at hotel giant Marriott International.

With Cyber Monday just days away, online shopping will surge, and with that will come a jump in online fraud attacks, causing problems for both consumers and merchants. According to Shop.org, more than half of all workers plan to shop online on Cyber Monday while on the clock, and are predicted to spend $1.2 billion, up from $1 billion in 2010, according to ComScore.

About 200 customers of the Central Maine Power Company recently noticed something odd after the utility installed smart meters in their homes: in some cases other wireless devices stopped working, or behaved erratically.

The inevitable has happened. Pornographic and violent images, many including gore and abuse, some even photo shopped to look like your friends, appeared on users’ profile pages on Facebook last Monday. While the true numbers and how it happened probably won’t be known for some time, experts in the field of Internet security are calling it a “widespread” spam attack and one of the worst security breaches in social media to date.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Security researchers uncover critical flaws and widespread misconfigurations in Salesforce’s industry-specific CRM solutions.

Cloud Security

Artificial Intelligence

Maze and its investors are betting on finding profits in software that uses AI-powered agents to automate critical parts of the process.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.