Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

The Canadian government has recently been under cyber attack, resulting in foreign hackers gaining access to classified government information, according to a report from CBC News of Canada.

Smartphone security firm, Lookout, today released the findings of its second App Genome Report, based on an analysis of over 500,000 mobile apps across different device platforms and app markets. The results show that the Android Market is growing at a rate nearly three times faster than the Apple App Store.

In an interview earlier this year, Kristin Lovejoy, Vice President of Security Strategy at IBM, addressed growing security concerns across the North American business landscape. Lovejoy focused on global security threats facing organizations, unique challenges of managing security across IBM, and how security leaders can improve in 2011 and beyond.

“Quis custodiet ipsos custodes?” - Satires of Juvenal“Good, Bad, I’m the one with the gun” - Bruce Campbell as Ash in “Army of Darkness” (1992)

Websense today unveiled a new Mobile DLP solution to help prevent sensitive data loss via mobile devices, whether connected through cellular carriers or WiFi. The new solution, Websense Mobile DLP™, helps prevent the loss of confidential data on iPads, iPhones, Android, and other mobile devices by utilizing content security controls.

At the RSA Conference in San Francisco today, Scott Charney, corporate vice president of Microsoft Trustworthy Computing, urged public and private sectors to adopt a proposal for a global Internet health model. In his keynote address about Microsoft’s Collective Defense vision, Charney said that existing technology and organizational policies could be used to implement a device health model that promotes trusted online experiences.

RSA today announced a new solution designed to automate the identification, prioritization and resolution of enterprise security incidents and enabling CISOs to visualize and prioritize security threats while reducing the time-consuming investigation processes.

ipTrust today announced the availability of ipTrust Intelligence Service, a new service which enables technology, reseller and service provider partners to integrate ipTrust's reputation analytics into their solutions, adding a significant layer of protection against today's most sophisticated attacks.

Damballa Inc., at the RSA Conference in San Francisco today released its “Top 10 Botnet Threat Report - 2010” which revealed a dramatic increase in Internet crime and targeted botnet attacks. At its peak in 2010, the total number of unique botnet victims grew by 654 percent, with an average incremental growth of eight percent per week.

Tacoma, Washington based IID (Internet Identity), a provider of technology and services that help organizations secure Internet presence, today announced the availability of a new border gateway protocol (BGP) security solution for the extended enterprise designed to detect, diagnose and mitigate BGP security threats.

Led by the team behind ModSecurity, Qualys today announced an open source web application firewall project dubbed “IronBee,” with the goal of producing a web application firewall sensor that is secure, high-performing, portable, and freely available – even for commercial use.

SonicWALL, a provider of network security and data protection solutions, today announced its SuperMassive™ E10000 Series of Next-Generation Firewalls (NGFW) featuring a multi-core architecture that utilizes up to 96 cores of processing power and delivering more than 40 Gbps of firewall throughput and over 30 Gbps of application control and Intrusion Prevention Service (IPS).

Rapid7, a Boston-based provider of vulnerability management and penetration testing solutions, today announced that its NeXpose product now provides full Adobe® Flash decompilation and analysis support. With the new feature, Rapid7’s Web application scanning goes beyond basic Flash support with the ability to discover more vulnerabilities and improve intelligence in Flash analysis.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.