Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Report Finds Serious Disconnect Between Businesses and Mobile Users. Half of Lost or Stolen Devices Contain Business Critical DataIn collaboration with Carnegie Mellon University, McAfee today released “Mobility and Security: Dazzling Opportunities, Profound Challenges”, a report focusing on the consumerization of IT and its impact on security.

A former Bank of America (BOA) computer programmer was sentenced to 27 months in federal prison, after he installed malware on Bank of America ATMs that allowed him to suck out large amounts of cash from the machines. He pleaded guilty on April 13, 2011 and was sentenced this week.

In Boston, an employee of an MBTA subcontractor has been arrested in connection with an alleged scheme to produce millions of dollars’ worth of fake MBTA monthly passes and sell them directly to riders.Andres Townes, age 27, of Revere, MA, was arrested and charged with Larceny over $250 and Conspiracy to Commit Larceny over $250.

Security standards exist because someone recognized a need. HIPAA, for example, was created to protect sensitive healthcare data. All information security regulations were created for a reason. Healthcare organizations are required to comply with HIPAA and HITECH. HIPAA and HITECH define a standard that should be placed on certain healthcare data. While they might give us a sense of security, do HIPAA and HITECH really make us more secure?

NetIQ Corporation, a business unit of The Attachmate Group, this week announced it will take over the complete portfolio of identity and security solutions from sister company Novell. (Both are units of Attachmate) In addition, certain Novell data center solutions will be added to the NetIQ business unit solution portfolio.Novell product lines now operating under the Houston, Texas based NetIQ business unit include:

A joint study released this week by ThreatMetrix and the Ponemon Institute, looks at the increase in mobile commerce activity, and how this trend plays a role in the prominence of fraudulent mobile transactions. The study examined how comfortable consumers are with sharing their mobile location with a company. More than half of respondents said they would be willing to share this information if it meant protecting against online fraud.

In early May, the Michaels art supply chain reported that 90 PIN pads within some of its 995 stores nationwide had been compromised, with victims reporting fraudulent withdrawals of up to $500 made from ATMs on the West Coast against their credit and debit card accounts. While 90 units represents less than 1 percent of the total, Michaels took the extraordinary precaution of removing the approximately 7,200 comparable PIN pads from all its US stores. The company was also monitoring...

Red Hat today announced the availability of Red Hat Enterprise Linux 6.1, the first update to the platform since the delivery of Red Hat Enterprise Linux 6 in November 2010. With Red Hat Enterprise Linux 6.1, Red Hat continues to set the standard in flexibility, performance and quality that customers around the world rely on for their open source enterprise environments, spanning physical, virtual and cloud deployments.

According to recent survey findings coming from CyberSource, a Visa company, airlines lost an estimated $1.4 billion due to online payment fraud in 2010. But with so many security checks that come along with air travel, how is this possible? A typical fraud scenario in the airline industry plays out like this:

In February 2011, the clock finally ran out on IPv4, the trusty Internet Protocol that has been used to connect networked computers for the last 30 years. The Internet Assigned Numbers Authority (IANA), which manages the master pool of IP addresses, assigned its last five blocks of IPv4 space to the world's five Regional Internet Registries.

BeyondTrust today announced the acquisition of Lumigent Technologies, a Massachusetts-based provider of database security and activity monitoring solutions.As a result of the acquisition, BeyondTrust today announced PowerBroker Database, a solution that provides IT security departments with the ability to closely monitor database activity of privileged users, assess system configurations, and capture, alert, and report on changes to critical system configuration and business data.

Threats to our networks are faster, smarter, more prevalent, more targeted, and more elusive than ever before. At the same time, the number and types of operating systems, applications and services running on the network continue to grow. Gaining visibility into different user types – remote, mobile, third-parties, and by job function – and accommodating their unique requirements adds even greater complexity when it comes to protecting our IT infrastructure.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.