Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

For twenty-five years, “data” in security meant logs and events. But logs are a lossy representation of reality.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

AI model AI model

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

Top Cybersecurity Headlines

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Few would doubt that insiders – those allowed access to certain IT resources within your organization – have the potential to wreak considerable damage. That's true whether they're scheming to physically damage IT systems, destroy the data held within them, or steal customer or corporate data to sell to criminals or competitors.

EMC today announced that it has acquired Virginia-based NetWitness Corporation, a privately-held provider of network security analysis solutions.

A report released this week coming from the largest association of data center professionals has suggested that with budget constraints and a tough economy, data center operators have been focused on immediate needs and paying less attention to disaster recovery planning and protecting against cyber attacks.

Bank of America announced this week that is has hired Patrick Gorman as chief information security officer and be responsible for the bank's information security strategy, policy and program.

Go ahead and click on the Viagra emails you’ve been warned about. Hackers don’t need to appeal to your libido to break into the company computer system. They have other compelling ways. These days they’ve been hanging around inside the network, building up profiles on company employees. By the time they have enough information and let loose their malware, you won’t even know that you were an unwilling accomplice in an advanced persistent threat.

A major milestone for DNSSEC has been reached today, as this morning DNSSEC was officially signed for the .Com TLD. Following several other Top Level Domains already supporting DNSSEC, the added level of security can now be enabled for the more than 90 million .Com names which have been registered according to VeriSign, the operator of .com.

Aggressive initiatives by the makers of popular Web browsers including Google, Microsoft, and Mozilla to improve the security of their Web browsers appear to be paying off.According to the Q3-Q4 Web Application Security Trends Report released today by Web application security firm Cenzic, the big Web browser companies seem to be paying very close attention to security, with many proactively seeking vulnerabilities by offering rewards or “bounties,” and seem to be efficient at fixing vulnerabilities in a timely manner.

Trustwave today announced updates and enhancements to ModSecurity, the open source web application firewall (WAF) engine for Apache, developed and managed by Trustwave's security team.ModSecurity enforces security policies to web transactions, reducing the risk of a web-based attack. As an open source technology, users and developers have been contributing to the community to help maintain the open source project that defends web applications.

Reports Show Significant Drops in Spam Levels Since Rustock Botnet Takedown - But Will Rustock Be Back?The Rustock Botnet was sending as many as 13.82 Billion spam emails each day before being taken down early this month by an effort headed by Microsoft in cooperation with authorities and the legal system.According to Symantec’s March 2011 MessageLabs Intelligence Report, the Rustock botnet had been responsible for an average of 28.5% of global spam sent from all botnets in March.

eBay announced today that it has agreed to acquire ecommerce and marketing services provider GSI Commerce for $2.4 billion in cash. It’s not a “done deal” yet, however, as under the terms of the merger agreement, GSI Commerce may solicit acquisition proposals from third parties for a 40-day “go-shop” period continuing through May 6, 2011.

NEI, a Canton, Massachusetts provider of solutions for software technology developers and OEMs, today announced that it has been awarded a US Patent for a technology that creates a new type of "digital fingerprint" that accurately validates software updates for physical and virtual servers and cloud-based application platforms.Patent #7900056 filed as "digital data processing methods and apparatus for management of software installation and execution," enables secure and reliable software update distribution.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.