Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities.

SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader.

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

Hasbro cyberattack Hasbro cyberattack

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Linux vulnerability Linux vulnerability

CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.

AI AI

Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. 

Top Cybersecurity Headlines

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Genesco Inc, a specialty retailer of branded footwear and other products, today announced that the computer network that processes its payment card transactions in the United States has been hacked, in what the company is calling a “criminal intrusion.” Genesco operates more than 2,225 footwear and headwear retail stores in the United States, Puerto Rico and Canada, principally under the names Journeys, Journeys Kidz, Shi by Journeys, Underground Station, Johnston & Murphy, Hatworld, Lids, Lids Kids, Hat Shack, Hat Zone,...

This week, the European Network and Information Security Agency (ENISA), Europe’s Cyber security agency, released a report identifying what it sees as the top security risks and opportunities of smartphone use and gives security advice for businesses, consumers and governments.The Agency considers spyware, poor data cleansing when recycling phones, accidental data leakage, and unauthorized premium-rate phonecalls and SMSs as the top risks.

Symantec today announced its predictions for what to expect in 2011 in the security and storage space. Hardly a surprise, the security giant says cloud, virtualization, mobile security and social media will be the hot topics and trends for the year. Here’s what Symantec Predicts for 2011:New Technologies, New Challenges

VASCO Data Security today launched “DIGIPASS Nano,” its latest mobile security offering which consists of a thin film that users place over the SIM card in their mobile device, turning it into a secure mobile device capable of generating one-time passwords and e-signatures.

A rapid shift in the prevalence of real-time attacks from online banking trojans, such as ZeuS, are now more common than password phishing attacks, according to PhoneFactor, a provider of phone-based multi-factor authentication solutions. Organizations lack understanding about what to do to protect against these threats according to the results of the “state of online banking security” survey released today by PhoneFactor.

Solution Enables Enterprises to Deploy Private Mobile App Stores for the EnterpriseMobileIron, a provider of mobile device management and security solutions, has updated its Virtual Smartphone Platform (VSP) with several new features including the ability to let businesses create private “Enterprise App Stores” and deliver in-house iPhone and iPad apps to their employees without having to post them publicly.

According to a recent study, over 50 percent of companies in the U.K. and U.S. have an Electronically Stored Information (ESI) Disclosure strategy in place, but most haven’t revisited policies to address new communication methods such as social networking (30 percent in the U.K. and 21 percent in the U.S.) and new storage technologies such as cloud computing (28 percent in the U.K. and 16 percent in the U.S.).

The day after Twin Towers fell, all kinds of security measures changed and new ones were implemented overnight. Is there a Web identity 911 equivalent wake-up call coming—a single event that will suddenly jolt us into enforced standards overnight?

Core Security Technologies, a Boston based provider of IT security testing and measurement solutions, today introduced the latest version of its automated penetration testing solution, CORE IMPACT Pro version 11.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.