Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Zscaler, a provider of cloud-based security services, has hired Dr. Amit Sinha who will join the company as Chief Technology Officer to lead research and development initiatives of the company's emerging technologies.

Comprehensive Full-Disk Encryption Solution Helps Organizations Deploy, Maintain and Manage Data Security Protection Transparently Across Multiple PlatformsFull-disk encryption software provider WinMagic today launched the latest release of its full-disk encryption solution that helps organizations seamlessly data protection with existing security policies on Windows 7 (32 and 64 bit)/Vista/XP, Mac OS X Tiger/Leopard/Snow Leopard and/or Linux platforms.

Sourcefire Acquires Immunet Adding Cloud-Based Anti-Malware Technology to its PortfolioSourcefire announced late today that is has acquired Immunet, a cloud-based anti-malware technology company. Under the agreement, Sourcefire will pay $21 million in cash for Immunet, including $17 million up front and $4 million over the next 18 months upon achievement of delivery milestones.

Device Fingerprinting and Mobile Transactions Were on the Rise in 2010; What's in Store for Fraud Prevention in 2011?As companies continue to conduct more transactions online, they need tools to stop online fraud while protecting customer privacy without the use of cookies and cookie equivalents such as local stored objects.

BeyondTrust, a provider of privilege delegation and authorization management solutions, has joined forces with IT security risk and compliance solutions provider, Qualys, on a technology partnership that will enable customers to manage user access and privileges while expanding the coverage of security scans for a more complete view of IT security and compliance.

Acquisition will Expand Dell’s Services Portfolio with Security-as-a-Service Solutions Dell today announced it has signed a definitive agreement to acquire Atlanta based SecureWorks Inc., a provider of information-security services. SecureWorks provides Security-as-a-Service solutions including Managed-Security Services, Security and Risk Consulting Services and Threat Intelligence.

Managing PCI Compliance -  How to Improve Your PCI Compliance This YearSurvive the holidays? How about your company’s PCI compliance? It seems that for many businesses, the first thing that suffers during the holiday crunch is anything that doesn’t bring in additional sales and revenues. Among them, maintaining PCI compliance.

Samsung this week announced three new lines of external hard disk drives, including two new portable drives and a new desktop drive targeted to the consumer market, but also ideal for small businesses. Each new drive features "SuperSpeed USB 3.0" interfaces that provide data transfer rates of up to 5 gigabits per second, and 1TB, 1.5TB and 2TB storage capacities.

As the year comes to a close, we thought it would be appropriate to highlight some of the best stories and columns for 2010. Here is a selection of top picks for the year, based on several factors including number of reads, inbound links, tweets, and SecurityWeek staff selections. Enjoy this selection of top picks for 2010, listed in no particular order. Happy New Year!

Ohio Man Sentenced to 30 Months in Prison for Selling More Than 35,000 Illegally Copied Video Games Over the InternetThe FBI reported this week that Qiang “Michael” Bi of Powell, Ohio was sentenced to 30 months in prison for selling more than 35,000 illegally copied computer games over the Internet between 2005 and 2009.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.