Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Sophos has completed its acquisition of network security vendor Astaro, a deal that will enable Sophos to deliver endpoint protection combined with Unified Threat Management solutions.The acquisition, which was announced on May 6, 2011, will enable Sophos to:

Oracle Virtual Desktop Client App for iPad Brings Highly Secure and Mobile Access to Virtual Desktops and Enterprise Applications Oracle today announced the availability of Oracle Virtual Desktop Client App for iPad that enables secure access to virtual desktops managed by Oracle's Sun Ray Software and Oracle Virtual Desktop Infrastructure.

In a talk at last year’s EuroSecWest conference, researcher Andrei Costin presented several vulnerabilities he found within commercial printers.

Last month, the FBI announced that violent crime rates had fallen dramatically in 2010 despite a tough economy. The Wall Street Journal explained this seemingly counterintuitive situation away with a list of factors. But none of those factors seem to have caused a drop in cyber-crime, as the Verizon Data Breach Investigations Report (DBIR) showed. All this poses a question – can we apply any of these factors to reduce the rate of cyber-crime?

Adrian Ghighina, 33, of Bucharest, Romania, was sentenced to 48 months in prison last week by U.S. District Judge Matthew F. Kennelly in Chicago after he pleaded guilty in February 2011 to one count each of wire fraud and conspiracy.

Domain name registrar and Web hosting provider GoDaddy, announced it has agreed to receive a strategic investment from private equity firms KKR, Silver Lake and Technology Crossover Ventures.The terms of the transaction were not disclosed, but the Wall Street Journal reported people familiar with the deal saying it could be worth approximately $2.25 billion. Its likely that founder Bob Parsons has cashed out a large chunk of his shares in the company, and kept a minority stake.

With all the daily reports on how companies are experiencing security breaches in their networks, it would appear hackers are taking over. Since January of this year, those in the security business believe that hacking big companies is now in the norm. NASDAQ, HP, Sony and governments agencies, as examples, are not weathering hacker intrusions any better.

Unlike my daughter’s second grade piano review, sincerity in the world of secure web application development means very little. Development of secure Web applications and the effort to maintain their security is hard work, requiring a holistic approach and a long-term perspective that web application is essential. Security is not achieved by simply demanding it of your staff; you need the correct staff to demand it of, continuous manual and automated vulnerability testing, and code reviews by security experts.

Cybercriminals Favoring Targeted Attacks over Mass SpamIn a continuing trend, new research released by Cisco today further confirms that cybercriminals have made a fundamental shift in strategy, abandoning traditional mass spam attacks in favor of personalized attacks with a greater financial impact on targeted organizations.

Kaspersky Lab, in its most recent spam report for May 2011, revealed that across its user base, Russia has taken the number one position in terms of the quantity of malware detected in emails by antivirus software. According to Kaspersky’s data, Russia overtook the United States, where the quantity of malware infected emails received fell by 3.5 percent. The most widespread malware distributed via email was the Trojan-Spy program Trojan-Spy.HTML.Fraud.gen.

Symantec this week published "A Window Into Mobile Device Security: Examining the security approaches employed in Apple's iOS and Google's Android", an in-depth, technical evaluation of Apple's iOS and Google's Android mobile platforms, to help organizations understand the security risks of deploying these devices in the enterprise.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.