Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Coralogix offers a full-stack observability platform that unifies logs, metrics, traces, security, and AI observability.

Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.

The AI Risk Quadrant evaluates AI agents based on three factors: how vulnerable they are to compromise, the potential impact of a breach, and the strength of their security defenses.

The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months.

The affected individuals’ personal information was stolen from a legacy server managed by a third party.

An improper authentication bug allows attackers to escalate their privileges and escape containers.

The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.

Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.

The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.

As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control.

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.

Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.

HTTP HTTP

The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.

Zero-day vulnerability Zero-day vulnerability

Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.

Whitehouse Cybersecurity Whitehouse Cybersecurity

The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.

Top Cybersecurity Headlines

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.

Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

Upcoming Cybersecurity Events

CISO Forum 2026 Mid-Year Review Roundtable

SecurityWeek’s CISO Forum 2026 Mid-Year Review is a virtual roundtable to evaluate the year’s most pressing challenges and share critical updates shaping the 2026 security landscape.
[June 10, 2026 | Virtual]

Read More
Cloud Security Summit 2026

SecurityWeek’s 2026 Cloud Security Summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments.
[July 15, 2026 | Virtual]

Read More
AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More

Vulnerabilities

Cybercrime

IT management software provider, CA (NASDAQ: CA), today announced the results of a European IT Security study revealing that organizations across several European countries are not utilizing Data Loss Prevention (DLP) technology.The survey revealed that 64% of organizations in the UK are not using Data Loss Prevention technology and other countries such as France (23%), Ireland (50%), and Italy (60%) report low utilization.

Symantec Corp. (Nasdaq: SYMC) today announced it would be making two key acquisitions, saying it has signed definitive agreements to acquire PGP Corporation and GuardianEdge Technologies, Inc., two privately-held leaders in the email and data encryption market. 

Hewlett-Packard Co. has agreed to acquire struggling smart phone maker Palm Inc. for over $1 billion in cash. The companies announced Wednesday they had agreed to the deal, which will see HP pay $5.70 for every Palm common share. With debt included, the deal values Palm at $1.2 billion. The transaction has been approved by the HP and Palm boards of directors.

Vice President of Technology and Innovation at Verizon, Peter Tippett, speaking at the Infosecurity Europe trade show in London this week, made an interesting prediction, stating "While we can never fully forecast the future, we certainly have a good glimpse into what security will be like 10 years from now, based on all the data we have amassed over the last several years for our Data Breach Investigations Reports. For starters, we know successful security breaches are leveling off, and...

Verizon and Novell have teamed up to provide “Secure Access Services from Verizon” – an on-demand identity and access management service providing enterprise clients more control and stronger security when accessing cloud based applications.The service, powered by Novell technology, will enable enterprise clients to outsource the infrastructure and expertise required to extend and manage user access to cloud-based resources while maintaining control over policies and governance.

Recent reports are showing that cybercriminals are targeting the abuse departments within financial institutions. Reports from a number of financial institutions show emails being sent to their abuse departments reporting a fake phishing email and hoping to have fraud analysts click on the click to investigate, when an attempt is then made to install malware on the users computer.

Beijing based mobile security service provider, NetQin Mobile Inc., announced it has received a third round of investor funding of $20 million. NetQin provides mobile security solutions- including anti-virus, anti-spam SMS/telephone, and privacy protection services. With this latest injection of cash in hand, the company has a goal to become the largest mobile security service provider worldwide.

Cellcrypt, a provider of secure mobile voice calling technologies, today launched Cellcrypt Enterprise Gateway, enabling business users secure calls to office landlines from mobile phones. The enterprise solution is targeted to executives traveling to hostile countries where phone interception is prevalent.

PGP Corporation today announced that Stuart Hopper has joined the company as its new Director of EMEA Channels. Hopper will be responsible for leading PGP Corporation's channel program and team in EMEA as the company looks to expand its footprint across the region.

Botnets, Trojans and Phishing…Oh my! The dedicated researchers at Symantec are at it again, scaring the living daylights out of companies and consumers with overwhelming evidence that the web is indeed a dark and foreboding place.

NETGEAR, Inc. (NASDAQ:NTGR), a networking solutions provider, today announced the first business class firewall that provides in excess of 1 Gigabit per second (Gbps) performance for under $500. NETGEAR claims the new ProSafe Quad WAN Gigabit SSL VPN Firewall (SRX5308) delivers up to 1 Gbps of firewall throughput -- faster than competing solutions in its price class.

Swiss information security and identity management solutions provider, WISeKey, announced today that it has secured $20 million in pre-IPO financing. The investment values the company at $200 million and was led by a group of USA, European and Swiss institutional and private investors.

As the number of cyber attacks against businesses increases, the majority of small and medium-sized businesses (SMBs) are not familiar with many of the online threats they face. A recent study of executives and finance professionals from SMBs across 38 industry sectors in the United States showed that 63 percent worry about cyber theft, yet lack knowledge on how to protect their businesses.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control.

Cloud Security

ICS/OT

ICS/OT

Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.