Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Coralogix offers a full-stack observability platform that unifies logs, metrics, traces, security, and AI observability.

Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites.

The AI Risk Quadrant evaluates AI agents based on three factors: how vulnerable they are to compromise, the potential impact of a breach, and the strength of their security defenses.

The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months.

The affected individuals’ personal information was stolen from a legacy server managed by a third party.

An improper authentication bug allows attackers to escalate their privileges and escape containers.

The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.

Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.

The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.

As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control.

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.

Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.

HTTP HTTP

The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold.

Zero-day vulnerability Zero-day vulnerability

Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.

Whitehouse Cybersecurity Whitehouse Cybersecurity

The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.

Top Cybersecurity Headlines

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.

Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

Upcoming Cybersecurity Events

CISO Forum 2026 Mid-Year Review Roundtable

SecurityWeek’s CISO Forum 2026 Mid-Year Review is a virtual roundtable to evaluate the year’s most pressing challenges and share critical updates shaping the 2026 security landscape.
[June 10, 2026 | Virtual]

Read More
Cloud Security Summit 2026

SecurityWeek’s 2026 Cloud Security Summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments.
[July 15, 2026 | Virtual]

Read More
AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More

Vulnerabilities

Cybercrime

Suppose a friend wants you to meet her cousin Bill at a black tie affair. You don’t have a photo of Bill to help you find him among the five hundred or so people in attendance—you only have your cousin’s description of Bill.

Sunbelt Software today announced the availability of Sunbelt CWSandbox 3.0, an upgraded version of their automated dynamic malware analysis tool. CWSandbox leverages unique behavior analysis technology for the identification of malicious threats like PDF exploits, fake media players and other socially engineered attacks against enterprise or government networks.

PhoneGuard, a provider of mobile security services, today announced availability of its anti-virus software for Android smartphones. Partnering with China based NetQin Technology, PhoneGuard provides a defense against threats including viruses, spyware and malware that target mobile devices.

Anti-virus products scan for malware in two ways. They look for sequences of bits that are found in programs that are known to be “evil” (but which are not commonly found in “good” programs). And they run programs in sandboxes and look for known malicious actions. The first approach only catches known malware instances, while the second can also catch variants of these. Still, many malware agents slip through the cracks undetected...

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control.

Cloud Security

ICS/OT

ICS/OT

Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.