Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Redmond’s AI Red Team says human involvement remains irreplaceable in addressing nuanced risks.

A fake proof-of-concept (PoC) exploit for a recent LDAP vulnerability distributes information stealer malware.

The US Justice Department has announced charges against three Russians for operating the Blender and Sinbad cryptocurrency mixers.

Developed with the help of AI, the emerging FunkSec ransomware claimed over 80 victims in December 2024.

Juniper Networks has patched multiple high-severity vulnerabilities in Junos OS and its third-party components.

Chinese cyberspies targeted offices dealing with foreign investments and sanctions in the recent US Treasury hack. 

If the deal is sealed, SpaceX would provide encryption services for the Italian government and communications infrastructure for the military and emergency services.

Noteworthy stories that might have slipped under the radar: 2025 trucking cybersecurity report, Bank of America discloses data breach, Silk Typhoon behind US Treasury hack.

The latest version of the Banshee macOS information stealer no longer checks if the infected systems have the Russian language installed.

Substance abuse treatment provider BayMark Health Services says patient personal information was compromised in a data breach.

Fortinet warns of a phishing campaign that uses legitimate links to take over the victims’ PayPal accounts.

People on the Move

Cloud security giant Wiz has named Fazal Merchant as President and Chief Financial Officer.

Cybersecurity and data protection company Acronis has appointed Gerald Beuchelt as CISO.

Adam Zoller has joined CrowdStrike as Chief Information Security Officer.

Ekta Singh-Bushell is the first COO of industrial cybersecurity company Dragos.

Threat intelligence firm Flashpoint has appointed David Lemon as President.

More People On The Move
Treasury Hacked by China Treasury Hacked by China

Chinese cyberspies targeted offices dealing with foreign investments and sanctions in the recent US Treasury hack. 

Streaming platform DRM hacking Streaming platform DRM hacking

A research project into vulnerabilities affecting Microsoft’s PlayReady DRM raises some questions on responsible disclosure.

Ivanti vulnerability exploited Ivanti vulnerability exploited

Google Cloud’s Mandiant has linked the exploitation of CVE-2025-0282, a new Ivanti VPN zero-day, to Chinese cyberspies.

Top Cybersecurity Headlines

Ivanti confirms zero-day exploitation of a remotely exploitable code execution flaw in its Connect Security product line.

After its CEO was arrested last summer, Telegram has been increasingly sharing user data at the request of authorities.

The insider threat problem will worsen, and the solutions will widen, in the age of generative-AI.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Explore trends and technologies that will shape the future of cybersecurity. Discover strategies for vendor selection, integration to minimize redundancies, and maximizing ROI from your cybersecurity investments. Gain actionable insights to ensure your stack is ready for tomorrow’s challenges.

Register

Dive into critical topics such as incident response, threat intelligence, and attack surface management. Learn how to align cyber resilience plans with business objectives to reduce potential impacts and secure your organization in an ever-evolving threat landscape.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 2025, Stay Tuned]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.(February 26, 2025)

Learn More

Supply Chain Security Summit
Join us as we explore the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects. (March 19, 2025)

Learn More

Vulnerabilities

Cybercrime

A survey conducted at the recent DEF CON Hacker conference in Las Vegas revealed that hackers see the cloud as an attractive hacking target.The survey, carried out amongst 100 of the IT professionals attending DEF CON, revealed that 96 percent think the cloud will open up more hacking opportunities for them.

Afilias, a global provider of Internet infrastructure services, today announced that it will deploy Domain Name System Security Extensions (DNSSECs) across its registry platforms, signing 13 more top-level domains (TLDs) and increasing the total number of DNSSEC deployments among domain registries to 39.

Autonomy today unveiled a new, end-to-end, “meaning-based” platform designed to automate many time-consuming tasks law firms must deal with in order to manage documents in electronic form. The Autonomy Risk Management platform leverages Autonomy's Intelligent Data Operating Layer (IDOL), already deployed today in over 2,000 law firms.

Social Media Acceptable Usage Policy - Why Allow Web 2.0 to Be Used in Business?The consumerization of IT is affecting all aspects of the way we work.  As Web 2.0 technologies continue to gain popularity amongst employees, IT departments are struggling to understand and manage the challenges.

Variant of Popular ZeuS Malware Targets U.S. Military Around the WorldMalware created with the ZeuS toolkit is targeting members of the U.S. military with an email asking them to update their account information online.Members of the U.S. Military have been receiving emails similar to the following: Targets of this scam will receive an email with the following text:Dear Bank of America Military Bank customer:

Do these firms really care about McAfee shareholders, or is this just an attempt to rake in some cash for the firms themselves?Intel, the world’s largest computer chipmaker, will pay $48 per share in cash for McAfee – a whopping 60 percent premium over McAfee's $29.93 closing price on Wednesday, and one that’s in line with other recent valuations in software and tech deals.

Intel on Thursday said it has entered into a definitive agreement to buy McAfee, the computer security software company, for $7.68 billion in cash, puchasing of all of the company’s common stock at $48 per share. McAfee shares closed at $29.93 at the end of trading on Wednesday.

Top 10 Most Dangerous Celebrities OnlineLooking for some hot photos or gossip on your favorite celebrity? Be careful. If you’re looking to dig up some dirt on Cameron Diaz there is a ten percent chance you’ll end up on a malicious site, according to McAfee.

The second quarter Phishing Trends Report from Internet security provider IID  (Internet Identity) indicates that there has been a significant switch in the tactics of cyber criminals, with at least one major gang shifting its entire focus away from phishing to Zeus malware, often referred to as man-in-the-browser malware.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Cloud Security

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.