Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Although it’s a little early for the “what did you do on your summer vacation?” essay, I have mine done. I vacationed in Orlando with my family last week. We did the whole Universal Studios/Disney thing, and had a blast. Although my kids called me a geek for doing so, I pondered the meaning of various happenings and observations that week. Here’s my attempt to unpack the significance of these events.

International Operation Targeted Two Cybercriminal Rings That Caused More than $74 million in losses The Department of Justice and the FBI, along with other law enforcement agencies around the world, announced the indictment of two individuals from Latvia as part of Operation Trident Tribunal, an ongoing operation targeting international cyber crime.

It’s rare that a day goes by without seeing news of another breach or other form of cyber attack in the news headlines. According to a recent survey, organizations are currently experiencing multiple breaches, with more than half (59 percent) of respondents citing two or more breaches in the past 12 months.

Do you allow your employees to surf using open wireless networks from their phones or laptops? What are the easiest ways that attackers can sniff email or gain access to corporate information from these devices? What are the best ways to protect corporation information on the go?

RSA, the Security Division of EMC, has been in the news lately, and not in a good way. The first shoe dropped in March, when the company disclosed via press release that an unknown attacker, likely a state-sponsored actor, stole certain unidentified assets related to its SecurID product.

McAfee announced enhancements to its security management solution today, adding automated and real-time security and risk analytics to help customers proactively identify, assess, manage and report on enterprise security.The McAfee Security Management solution delivers complete integration between its McAfee® ePolicy Orchestrator® platform, McAfee® Risk Advisor, and McAfee endpoint products to enable organizations to gain visibility of security and risk events across on-premise or hosted desktop, network, or server.Enhancements to the updated soution include:

TLS, Transport Layer Security, is a means of securing the transmission of email between two MTAs (mail transfer agents). It prevents an eavesdropper from capturing the headers and body of an email in clear text. TLS is a near-universal feature of MTAs (there are some MTAs that privilege speed over security that lack the feature), and mail administrators usually have it enabled such that anyone attempting to send an email can request its use and negotiate a TLS session.

Skype allows customers to communicate over Voice over Internet Protocol (VoIP) platforms. And because it is encrypted, Skype, which was recently purchased by Microsoft for $8.5 Billion, is used by many businesses today for their international phone calls. What researchers have found, however, is a novel way to decrypt those conversations without ever knowing the encryption key.

Not a week goes by without Web hacking – Sony (again!), FBI, Citibank, ADP, and many others that we don’t even hear about. At best, companies are tinkering with their Web security issues instead of attacking them head-on.

HR and Payroll outsourcing giant Automatic Data Processing, Inc., (ADP) experienced a system intrusion, that as of now, has affected one client. In an announcement this afternoon, ADP said that it was investigating and taking measures to address the impact of a system intrusion that occurred with a client at Workscape, a benefits administration provider that ADP acquired in August 2010. Though the incident is limited to a single client, ADP didn't say if and how many records from the...

Mobile devices bring incredible benefits in terms of productivity and efficiency in the workplace and for personal use. But there’s a catch: "The ways smart phones, laptops and tablets interconnect work life and personal life raise serious security challenges for organizations—and the stakes are high,” according to Alastair MacWillson, global managing director of Accenture’s global security practice and SecurityWeek columnist.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.