Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

IT Security and data protection company Sophos today announced the availability of a number of new and enhanced mobile management and protection products for enterprises.

For nearly a year, 22 year-old Lucas Henderson of Texas has been creating and distributing fake coupons, resulting in hundreds of thousands of dollars lost by retailers and manufacturers. He surrendered in federal court last week.

A group of security and privacy researchers from the Institute of Media Informatics at Ulm University in Germany, is claiming to have discovered a serious security vulnerability in Google's ClientLogin protocol.In a recent analysis of the Android platform, the group discovered that when Android users are connected to an unencrypted open Wifi network, an attacker could both read transmitted synchronization data of Google Contacts, Calendar and Picasa Web Albums, and capture the authToken that’s user for authentication.

Autonomy Corporation, with dual headquarters in Cambridge, England and San Francisco, California, announced that it would acquire certain assets from Iron Mountain's digital division including archiving, eDiscovery, and online backup for $380 million in cash.The acquisition of assets will bring over six petabytes of data under management and more than 6,000 customers to Autonomy's customer base, bringing its private cloud data to over 25 petabytes and total customer base to over 25,000.

Over the weekend Sony began a phased restoration by region of PlayStation Network and Qriocity Services, but the company’s work is not done just yet.Following cyber attack on its data center in San Diego, California, Sony shut down the PlayStation Network and Qriocity services on April 20, to conduct an investigation and make enhancements to its security. Since then, the company has been working with several outside security firms, and says it has implemented new and additional security measures that...

Rogue antivirus (AV) attacks are showing no signs of slowing anytime soon. According to recent statistics coming from GFI Software, April saw a continued increase in the volume of detected malware, with 73,000 new variants of threats being released daily — a 26 percent increase over the same period last year.

During my high school years, in a time of dial-up modems and Windows 98, I was a huge computer geek (shocking, isn’t it?). One day, I received an e-mail from a friend, which had a small executable as an attachment. The e-mail contained a personal note from the sender, so I did not suspect it to be malicious. When I opened the executable, a small game of whack-a-mole opened up, with Bill Gates face in the role of the mole.

Symantec (NASDAQ: SYMC) on Wednesday reported the results of its fourth quarter and the fiscal year 2011, ended April 1, 2011. The company reported GAAP revenue for the fiscal fourth quarter of $1.67 billion, up 9 percent year-over-year and up 8 percent after adjusting for currency.

Tripwire, Inc., a provider of IT Security and compliance solutions, today announced it has agreed to be acquired by private equity firm Thoma Bravo. The firms have entered into a definitive agreement in which Thoma Bravo would purchase Tripwire, Inc. for an undisclosed sum.

The Unisys Security Index (USI) provides insight into consumers’ general security concerns. One of the index measurements is online security, and although this survey is conducted world-wide, the latest U.K. and U.S. results presented a similar finding: roughly half of the respondents are “seriously concerned” about malware, shopping or banking online. Furthermore, the stats show a 35% increase compared to last year’s U.S. stats.

Juniper Networks released the results of a global mobile threat study this week, showing a significant rise in threats to mobile devices. The report highlighted a record number of mobile security threats, including a 400 percent increase in malware targeting the Android operating system, as well as highly targeted Wi-Fi attacks.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.