CONFERENCE NOW LIVE: Threat Detection & Incident Response (TDIR) Summit - Join the Event In-Progress
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

GitLab and Atlassian have released patches for over a dozen vulnerabilities in their products, including high-severity bugs.

Russian military intelligence hackers intensify targeting of Western logistics and technology companies moving supplies into Ukraine. 

Redmond’s threat hunters found 394,000 Windows systems talking to Lumma controllers, a victim pool that included global manufacturers. 

More than 100 AutomationDirect MB-Gateway devices may be vulnerable to attacks from the internet due to CVE-2025-36535.

SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st.

A mandatory filing to the Maine Attorney General says 69,461 customers nationwide were affected and dates the breach back to last December.

Matthew Lane allegedly hacked PowerSchool using stolen credentials and admitted to extorting a telecoms provider.

Wireless carrier Cellcom has confirmed that a week-long widespread service outage is the result of a cyberattack.

Google DeepMind has developed an ongoing process to counter the continuously evolving threatIndirect prompt injection (IPI) attacks.

Wiz warns that threat actors are chaining two recent Ivanti vulnerabilities to achieve unauthenticated remote code execution.

Many of the industrial control system (ICS) instances seen in internet scanning are likely or possibly honeypots, not real devices.

People on the Move

Jeremy Koppen has left Mandiant after 13 years to become the CISO of Equifax.

Engineering and technology solutions provider Amentum has appointed Max Shier as its CISO.

PAM provider Keeper Security has appointed Shane Barney as its Chief Information Security Officer.

SpecterOps has appointed Tim Bender as CFO, Pat Sheridan as CRO, and Bryce Hein as CMO.

CISA has officially announced the appointment of Madhu Gottumukkala as its new deputy director.

More People On The Move
ICS honeypot scanning ICS honeypot scanning

Many of the industrial control system (ICS) instances seen in internet scanning are likely or possibly honeypots, not real devices.

Pwn2Own Berlin 2025 results Pwn2Own Berlin 2025 results

Pwn2Own participants demonstrated exploits against VMs, AI, browsers, servers, containers, and operating systems.

NATO Locked Shields NATO Locked Shields

The 15th edition of NATO’s Locked Shields cyber defense exercise brought together 4,000 experts from 41 countries.

Top Cybersecurity Headlines

American steel giant Nucor on Wednesday disclosed a cybersecurity incident that bears the hallmarks of a ransomware attack.

The China-linked hacking group Earth Ammit has launched multi-wave attacks in Taiwan and South Korea to disrupt the drone sector.

Google bundles multiple safeguards under a single Android toggle to protect high-risk users from advanced mobile malware implants.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Join this webinar for a fascinating discussion to understand why data in itself is not enough to make informed decisions for prioritization.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [August 19-20, 2025 | Ritz-Carlton, Half Moon Bay]

Learn More

SecurityWeek’s CISO Forum Summer Summit & Golf Classic will take place August 19-20 at the Ritz-Carlton, Half Moon Bay, CA. (www.cisoforum.com)

Learn More

The Threat Detection & Incident Response Summit delves into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. [May 21, 2025 – Virtual]

Learn More

SecurityWeek’s Cloud and Data Security Summit returns with a deliberate focus on exposed attack surfaces and weaknesses in public cloud infrastructure and APIs. [July 16, 2025 – Virtual]

Learn More

Vulnerabilities

Cybercrime

Snoop Dogg’s partnership with Symantec isn’t off to a great start. Just two days after announcing the “Hack is Wack” rap competition, the HackIsWack.com Web site was attacked. At the time of publishing, the site seems to be offline, likely to protect users from a reported cross site scripting attack discovered on Friday.

HP has won the heated bidding war for storage company 3Par, but Dell will take home $72 million from a break-up fee upon the termination of its merger agreement.Dell announced today that it will not increase its most recent proposal to acquire 3PAR, and that Dell has ended its discussions regarding a potential acquisition.

Heartland Payment Systems quietly issued a press release late Wednesday afternoon, announcing a settlement agreement with Discover Financial Services related to a 2008 data breach.Heartland will pay Discover $5 million as part of the settlement and the case is officially closed.On January 20, 2009 Heartland announced that a security breach had occurred in 2008, involving malicious software that compromised data within Heartland's network.

Verizon and VMware to Launch Enterprise-Class Hybrid Cloud Solution Verizon Business and VMware have announced a new enterprise-class hybrid cloud solution which the two claim will enable enterprises with vCloud-based infrastructure to move their applications to the cloud using existing IT configurations and applications, with no compromise in security or performance.

Fortinet released its August 2010 Threat Landscape report showing some interesting changes and shifts from previous months, with an interesting trend in “Do-It-Yourself” Botnet Kits gaining momentum and becoming a serious threat.

QualysGuard PCI 5.0 - New Dashboard and Interactive Workflows to Support New Approved Scanning Vendor Requirements Qualys upgraded its PCI compliance suite today with the release of QualysGuard PCI 5.0. The upgraded solution provides customers a simplified way to meet the latest Payment Card Industry Data Security Standard (PCI DSS) compliance requirements.

Snoop Dogg and Norton Announce 'Hack is Wack' Video Contest To Raise Cybercrime Awareness Think you can bust out some silly fresh rhymes on the subjects of hacking, identity theft and computer viruses?

Wyse Technology today announced an expanded strategy involving thin and zero client computing, desktop virtualization, unified communications, and mobile access to virtual environments. Wyse will work with key partners including Citrix, IBM, Microsoft, VMware and others, along with its resellers, to deploy what the company characterizes as “a broader set of options for government, business and education.”

HP Launches CloudStart to Fast Track Customers to Private Clouds HP wants to take customers on a flight to the private cloud – and get them there quickly. HP says that with its HP CloudStart solution, it can deploy an open and flexible private cloud environment within 30 days.

.LNK Exploits - Shortcuts to InsecurityThe vulnerability in Windows Shell’s parsing of .LNK (shortcut) files presents some interesting and novel features in terms of its media lifecycle as well as its evolution from zero-day to patched vulnerability. For most of us, the vulnerability first came to light in the context of Win32/Stuxnet, malware that in itself presents some notable quirks.

Fake TweetDeck Updates Being Spread via Hacked Twitter AccountsCybercriminals are using hacked/compromised Twitter accounts to spread malicious links pointing to a fake update to TweetDeck, a popular client used to access Twitter.Some of the messages (tweets) that users may see include ones such as:• Hurry up for tweetdeck update!• Update TweetDeck! Bank Holiday• Critical tweetdeck update Bank Holiday• Sorry for offtopic, but it is a critical TweetDeck update. It won't work tomorrow!

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Code quality and security firm CodeAnt has secured $2 million in seed funding and it has been valued at $20 million.

Cloud Security

Cloud Security

VMware patches flaws that expose users to data leakage, command execution and denial-of-service attacks. No temporary workarounds available. 

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.