Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.

The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.

Security teams must treat autonomous agents as highly privileged identities.

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.

Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.

The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.

FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.

The ruling is part of Anthropic’s legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year.

The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578.

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

Berlin ransomware data breach Berlin ransomware data breach

The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

PaperCut zero-day exploited PaperCut zero-day exploited

PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Top Cybersecurity Headlines

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

NATO Hacked By Anonymous: Claims SQL Injection Attack Yielded 1GB of Restricted Data Highly flying, and highly visible hacktivist group Anonymous, is claiming it has hacked into a NATO system, and is sitting on approximately a gigabyte of NATO restricted data. Interestingly, the group is saying they probably won’t publish the data, as it would be “irresponsible,” as the group described it.

We’re seeing a fast-growing trend in the hacking community that, sadly, many aren’t noticing: search engines can be turned into tools for attackers in numerous ways. What can businesses do to fight back?The Basics: Exploiting Hot Topics

Following yesterday's announcement of record quarterly revenue of $28.57 billion and record quarterly profit of $7.31 billion, Apple today launched Mac OS X Lion, the eighth major release of its operating system.While OS X Lion flaunts more than 250 new features, we thought it would be appropriate to run through them and highlight some of the security and privacy related features that would be of interest to our security-minded audience.

Skydera C3 Developer Edition Enables Cloud Command & Control for Amazon AWS, RackSpace, GoGrid, SliceHost Skydera, a provider of cross-cloud IT automation solutions, today launched Skydera C3 Developer Edition, a solution that brings developers enterprise-grade security to public cloud and hybrid cloud environments, and true developer self-service.

Have you considered how you’ll secure your IPv6 infrastructure? Even if you aren’t implementing an IPv6 network, you still need to be concerned about the transition. Here is how can you be sure your network remains protected as the industry moves towards IPv6.

RedSeal Systems, Inc., a provider of network security optimization solutions that help companies identify holes in their security infrastructure, announced that it has appointed existing board member and security industry expert Parveen Jain as the company's new chief executive officer.

The Pennsylvania Department of Banking today warned the public about an advance fee loan scam being carried out on the Internet under the name Ridley Creek Financing Group.According to the Department of Banking, the company's Web site solicits personal loans and asks for personal financial information, such as Social Security numbers, which could be used to commit identity fraud and drain victim's accounts. The company also asks for funds to be wired to process the loan.

Survey Reveals That IT Security Personnel Are Making Dangerous Security Trade-OffsWith the significant spike in recent data breaches and cyber attacks, organizations around the world are scrambling to implement additional security measures to help develop a strong security posture.

Recovering from a breach can be expensive, just ask Sony or any other company that has fallen victim to a cyber attack recently. Not only are the costs stemming from investigations, breach notifications and fines expensive for organizations, the damage done to a brand and loss of customer confidence can be incredibly costly.

Seattle based WatchGuard Technologies, on Monday announced that it has extended its next-generation firewall (NGFW) capabilities, including advanced firewalling, application control, and intrusion prevention system (IPS), to its XTM 8 Series of security appliances, making enterprise-class NGFW features available to businesses that perhaps aren’t big enough to justify the investment in a typical enterprise-class firewall.

Google today said it had acquired the domain name “G.CO”, a name that the company says it will use exclusively to link to official Google products and services, helping users be more confident that when they click on a "G.CO" link, they are taken what should be a safe URL, operated by Google.

The battle for top talent in the tech industry isn’t limited to Facebook, Apple and Google quarreling to hire and retain top talent. Splunk, a provider of operational intelligence software, today announced that it has hired David Conte as the company’s first Chief Financial Officer.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.