Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Last week at the Black Hat Conference in Las Vegas, SaaS-based IT security solution provider Qualys, made several announcements including a new QualysGuard Consultant Edition, a revamped user interface for its QualysGuard Security and Compliance SaaS Suite, and availability of the latest version of its Web Application Scanning solution.

Microsoft released 13 security bulletins today as part of Patch Tuesday, including two rated “critical” – its highest security rating. But according to some security pros, companies would be wise to not give some of the non-critical bulletins short-thrift when it’s time to prioritize patches.

After announcing they had defaced Websites belonging to more than 70 different law enforcement agencies across the U.S., hacktivist collective Anonymous, as part of the AntiSec movement, declared in a statement posted online that they had released roughly 10GB of data stolen during the compromise, including “hundreds of private email spools, password information, address and social security numbers, credit card numbers, snitch informa

Operation Shady RAT: Peeling Through the LayersNew details have emerged about a stealthy attack campaign that security pros say struck more than 70 organizations around the world.

Facebook Privacy - Steps You Can take to Protect your Privacy While Using the World's Largest Social Networking SiteFacebook is ubiquitous. But it is also anathema to privacy. My daughter tells me that if I am so paranoid about my privacy that I should not have a Facebook account.

Security was a key part of the pitch around Chrome OS when Google started revealing details of the operating system back in 2009. Fast forward to August 2011 – Google Chrome OS is a reality on the market and its security is on the menu at the annual Black Hat security conference in Las Vegas.

Enterprise and ICS networks should at least be separated at layer 3, so it’s probably more accurate to say that we’ve routed the air gap, but I didn’t want to give up the double entendre of bridging the gap. Terrible network jokes aside, the simple truth is that digital networking has displaced the air gap, blowing it into the distant places of legend. It is a myth. It does not exist.

Microsoft today announced “BlueHat Prize,” a contest designed to generate new ideas for defensive approaches to support computer security. Microsoft’ goals is to inspire security researchers to develop innovative solutions intended to address serious security threats, and ones that could potentially block entire classes of vulnerabilities.

The specter of advanced persistent threats (APTs) hangs over a growing number of conversations these days about enterprise security, and has prompted businesses to take a closer look at how they can make their environments less vulnerable.

Surrounding the Black Hat Conference set to take place this week in Las Vegas, Veracode, a provider of cloud-based application risk management solutions, today announced Veracode DynamicMP, an on demand solution that combines the power of automated web application vulnerability scanning with the power of cloud computing to provide a scalable vulnerability detection service that can simultaneously test application security across thousands of

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.