Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Earlier this week, several news outlets reported that the 20-year-old son of Kaspersky Lab CEO, Eugene Kaspersky, had gone missing, with kidnappers said to be demanding €3m (about US$4.4) for his release.Today, several Russian news outlets are reporting that the kidnappers requested ransom had been paid and that his son, Ivan Kaspersky, has been returned safely.Eugene Kaspersky, who started Kaspersky Lab, was recently ranked high on Forbes' list of wealthiest people in Russia.

iOS and Android Continue to Dominate - Verizon iPhone Launch Pumps iPhone Enterprise Adoption Rate in Q1 2011A report out today coming from Good Technology, a provider of secure and managed enterprise mobility solutions, revealed that the trend of personal smartphones infiltrating the workplace, sometimes referred to as “consumerization”, continues to be led by both Apple's iOS and Google's Android smartphone platforms.

We all have compliance issues. Compliance with HIPAA. Compliance with HITECH. Compliance with PCI. These are all well-defined regulations and standards that we should be able to understand quite easily. Compliance is easy.Yeah, and I have a bridge I could sell you. Cheap.But, compliance is not really hard per se. It is, however, tedious, time-consuming, and expensive. There are plenty ways to describe compliance efforts. But what does compliance really require?

While mobile devices aren't yet direct targets for enterprise attacks, they are at least conduits, able to siphon vast amounts of data nonetheless, according to the 2011 Verizon Data Breach Investigation Report. Mobile devices used to commit data breaches increased significantly in cases closed in 2010. Leading the way were compromised POS terminals, pay-at-the-pump terminals, and ATMs.

Chicago based Trustwave Holdings, a provider of security and compliance solutions, is hoping to raise as much as $100 million in an IPO, according to a filing with the SEC yesterday. The prospectus provides a detailed look at the company’s finances and operations.

A Michigan woman pleaded guilty today to selling counterfeit computer software which reportedly earned her over $400,000. Jacinda Jones, 31, of Ypsilanti, Michigan pleaded guilty to one count of willful copyright infringement before a judge in Detroit. According to court documents, between July 2008 and January 2010, Jones sold more than 7,000 copies of pirated business software at discounted prices through the website cheapdl(dot)com. The software, published by several companies including Microsoft, Adobe, Intuit and Symantec had a retail value...

What motivates an organization to secure data? For one, there is the cost or impact of a breach, which spans from the losses the business incurs while resources are shut down to investigate the attack to the potential damage to a company’s brand. Not all retailers, however, find the prospect of a hefty price tag reason enough to invest in securing customer data (emails, addresses, identification numbers, credit card numbers, etc.). Luckily for consumers, there is an even more compelling...

Protected Mobility, a Virginia-based mobile security company, announced the release of ProtectedSMS™ for Android smartphones today, a handset-to-handset solution enabling mobile users to exchange secure, encrypted text messages with individuals who have installed the software. This adds to an existing solution that was already available for BlackBerry smartphones and allows BlackBerry and Android to exchange messages.

The Air Force Association today announced that registration for CyberPatriot IV is now open, and is inviting students from all high schools or accredited home school programs in the United States to participate. No need to rush, however, as registration will be open through October 8, 2011, though space is limited.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.