Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Misconfigured permissions in Google’s Gerrit code collaboration platform could have led to the compromise of ChromiumOS and other Google projects.

Citrix has released patches for critical- and high-severity vulnerabilities in NetScaler and Secure Access Client and Workspace for Windows.

Qualys has disclosed two Linux vulnerabilities that can be chained for full root access, and CISA added a flaw to its KEV catalog.

Adopting a layered defense strategy that includes human-centric tools and updating security components.

OpenAI has been awarded a $200 million contract for AI capabilities to help the Defense Department address national security challenges.

Google has released a Chrome 137 update to resolve two memory bugs in the browser’s V8 and Profiler components.

Veeam and BeyondTrust have resolved several vulnerabilities that could be exploited for remote code execution.

Hackers have stolen personal and health information belonging to the customers of healthcare organizations served by Episource.

Researchers identify a previously unknown ClickFix variant exploiting PowerShell and clipboard hijacking to deliver the Lumma infostealer via a compromised travel site.

GreyNoise warns of a spike in exploitation attempts targeting a two-year-old vulnerability in Zyxel firewalls.

Google is warning insurance companies that Scattered Spider appears to have shifted its focus from the retail sector. 

People on the Move

Jason Hogg has been named Executive Chairman of CYPFER.

HUB Cyber Security has appointed former PayPal and American Express executive Paul Parisi as its Global Chief Revenue Officer.

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

Cybersecurity training and simulations provider SimSpace has appointed Peter Lee as Chief Executive Officer.

More People On The Move
OpenAI DoD cyber defense contract OpenAI DoD cyber defense contract

OpenAI has been awarded a $200 million contract for AI capabilities to help the Defense Department address national security challenges.

Episource data breach Episource data breach

Hackers have stolen personal and health information belonging to the customers of healthcare organizations served by Episource.

Insurance sector targeted by Scattered Spider Insurance sector targeted by Scattered Spider

Google is warning insurance companies that Scattered Spider appears to have shifted its focus from the retail sector. 

Top Cybersecurity Headlines

According to reports, the US Department of Justice will assess whether the deal would harm competition in the cybersecurity market.

A cybersecurity incident at WestJet resulted in users experiencing interruptions when accessing the company’s application and website.

Industry professionals comment on the Trump administration’s new executive order on cybersecurity. 

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Register

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

With the vast amount of data stored on the public cloud, how do you know if your data is truly secure?  What steps can you take to ensure you make the right choice when transitioning to the cloud?The market for cloud infrastructure, platforms and applications is growing at a rapid pace; in fact, AMI research estimates that SMB cloud spending alone will reach $100B by 2014. It’s no surprise then that many, if not most organizations are looking to the...

Lookout Mobile, a provider of smartphone security solutions has raised $19.5 million in a Series C round of funding. The round was led by new investor, Index Ventures, and also includes Accel Partners and Khosla Ventures. 

According to a memo issued by Kevin Sellers, Intel's Vice President of Investor Relations, the Federal Trade Commission has concluded its review of the proposed McAfee transaction and has cleared it.

Minnesota Man Stops Trial to Plead Guilty to Hacking Neighbor’s Internet to Email Threats against the Vice PresidentBarry Vincent Ardolf of Blaine, Minnesota pleaded guilty to hacking into his neighbor’s wireless Internet system and posing as the neighbor to make threats to kill the Vice President of the United States. Just two days into his federal trial in St. Paul, Ardolf stopped the trial to plead guilty.

Data Protection for iPads, iPhones and Macs Added in Latest Release of Data Protection SuiteThe rapid rise of mobile computing devices such as iPhones and iPads as the preferred medium for connecting to private corporate networks has led to an increase in risks including breaches of security and data loss.

Prevalent Networks, a provider of information security and regulatory compliance solutions, this week launched a cloud-based services delivery platform and managed service for Symantec Control Compliance Suite, a solution that helps organizations manage IT risk and compliance.The company also introduced its Cloud Service Aggregation Platform for integration of Prevalent managed and cloud delivered services with third-party services such as Symantec Managed Security Services.The initial launch of Prevalent Compliance as a Service (PCaaS) includes:

Why Cloud Tenancy and Apartments Have More in Common Than You ThinkOne of the most common questions about cloud security is around privacy and regulatory compliance. Questions around government mandates and industry requirements abound from IT managers considering a shift to the cloud—most of which relate to multi-tenancy.Since there’s been so much discussion about multi-tenancy in the cloud lately, I thought I’d explain what it means for both cloud providers and cloud customers.But first, a tangent:

Awareness Technologies, a provider of “Insider Threat” security solutions, today announced enhancements to its InterGuard Software, allowing organizations to monitor all emails sent to and from BlackBerry devices and enabling employers to help prevent sensitive information from leaking accidentally or maliciously.

BitTorrent adds Ability to Scan Torrent Files for Malware Using BitDefender's TechnologyBitTorrent has partnered with Internet security software provider BitDefender to help prevent BitTorrent users from inadvertently downloading malware when downloading media files from the Internet.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Security researchers uncover critical flaws and widespread misconfigurations in Salesforce’s industry-specific CRM solutions.

Cloud Security

Cloud Security

Cloud security startup Circumvent has raised $6 million to develop a network of agents for autonomous prioritization and remediation.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.