Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.

The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.

Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.

Signal has also made a security announcement: an automatic key verification feature to complement its safety number system.

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution.

LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.

CISA has also published several advisories describing vulnerabilities in ICS and other OT products.

The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Ceva Logistics cyberattack Ceva Logistics cyberattack

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

supply chain threat supply chain threat

LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.

Cisco vulnerability exploited Cisco vulnerability exploited

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.

Top Cybersecurity Headlines

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.

OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

When a new disease surfaces among humans or animals, the first thing we notice are the patterns of spread – not the structure of its DNA.  

As anticipated, Adobe has released security updates for Acrobat and Acrobat Reader Products. These updates are classified as critical as the vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.Adobe recommends users of Adobe Reader 9.3.1 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.3.2. (For Adobe Reader users on Windows and Macintosh, who cannot update to Adobe Reader 9.3.2

DNS is the address book for the Internet. It’s the way for users, customers and partners to find your online presence and communicate and transact with it. Without DNS, the Web, e-mail, hosted applications, and virtually every mission-critical thing done online would become unusable.

We are barely four months into the year, and 2010 has already proved itself a dream for scammers and fraudsters around the world, filled with opportunity and prosperity. They have had many events working to their advantage, helping them prey on and exploit innocent victims.

On April 13th, Adobe plans to release updates for Acrobat Reader for Windows, Mac and UNIX to resolve critical security issues. The new update, Adobe says, will fix several vulnerabilities and include an improved version of the software that Adobe uses to deliver its updates, helping end-users stay up-to-date in a much more streamlined and automated way. For the latest information, visit the Adobe Product Security Incident Response Team blog at: http://blogs.adobe.com/psirt

Apple today announced the biggest software update yet for the iPhone. iPhone OS 4 will include over 100 new features for iPhone and iPod touch owners, including some much desired security features for the enterprise. Set to be released this summer for iPhone and iPod touch, the update will be available for the iPad in the fall. A version is currently available for developers.

Wolters Kluwer Financial Services announced today the launch of its Wiz Sentri™ Financial Crime Control platform. Utilizing real-time, continuous behavioral and transaction monitoring and analysis, the solution aims to help financial institutions predict and prevent financial crimes before they occur. 

Sybase, Inc. (NYSE:SY), today announced support for iPad and Android devices with the latest release of, Afaria, their mobile device management and security solution for the enterprise."The popularity of highly functional smart mobile devices, such as iPhone, Android and now the iPad, is significantly impacting enterprise mobility support requirements as these devices increasingly cross over from consumers into the corporate setting," said Jack Gold, president and principal analyst of J. Gold Associates, LLC.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.

Cloud Security

Artificial Intelligence

Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries...

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.