Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop.

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.

Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration.

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation.

The company, previously known as ActiveFence, has raised a total of $280 million from investors.

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.

When Android users get a call from a non-contact, they will see more information about the caller, including their country.

Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.

Malware Malware

Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.

Water system vulnerabilities Water system vulnerabilities

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

AI security alliance AI security alliance

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation.

Top Cybersecurity Headlines

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Upcoming Cybersecurity Events

AI Risk Summit: Aug 11-12, 2026 (In-Person)

SecurityWeek’s AI Risk Summit is the leading conference where technology, security, and risk leaders converge with AI researchers, developers, and policy makers shaping the future of enterprise AI.
[August 11-12, 2026 | In-Person]

Learn More
CodeSecCon 2026

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[August 19, 2026 | Virtual]

Read More
Attack Surface Management Summit 2026

SecurityWeek’s 2026 Attack Surface Management Summit will evaluate how organizations can protect corporate assets and reduce their attack surface in a modern security program.
[September 16, 2026 | Virtual]

Read More
ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

Vulnerabilities

Cybercrime

Visa (NYSE:V) has announce that it will acquire online electronic payment and risk management provider, CyberSource Corporation, (NASDAQ:CYBS) in an approximately $2.0 billion cash transaction valuing CyberSource shares at $26.00 per share.

Symantec (Nasdaq: SYMC) today unveiled beta versions of the Norton 2011 AntiVirus and Norton 2011 Internet Security, available now as free download. With performance being a key objective in the latest releases, both products will include “System Insight 2.0” which alerts users when applications are significantly impacting their system resources.

Affinion Security Center, announced enhancements to its BreachShield service, aimed at preventing, detecting and resolving Identity Theft resulting from data breaches. The updates are focused on helping customers at risk for medical identity theft but available for all types of organizations that could experience a data breach.

Cyber warfare is a hot topic in the security industry, but what does this term actually mean? At what point does a cyber conflict become a cyber war? Are cyber threats, cyber attacks and cyber espionage acts of cyber war? Many of these questions need to be discussed – and that discussion is about to take place.

Updated Mac Forensic Suite Features Improved Performance, Enhanced User Interface, and Support for Snow Leopard MacForensicsLab Inc. announced the release of their computer forensic suite, MacForensicsLab 3.0. The new version adds new features along with enhanced stability and speed improvements.

When a new disease surfaces among humans or animals, the first thing we notice are the patterns of spread – not the structure of its DNA.  

As anticipated, Adobe has released security updates for Acrobat and Acrobat Reader Products. These updates are classified as critical as the vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.Adobe recommends users of Adobe Reader 9.3.1 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.3.2. (For Adobe Reader users on Windows and Macintosh, who cannot update to Adobe Reader 9.3.2

DNS is the address book for the Internet. It’s the way for users, customers and partners to find your online presence and communicate and transact with it. Without DNS, the Web, e-mail, hosted applications, and virtually every mission-critical thing done online would become unusable.

We are barely four months into the year, and 2010 has already proved itself a dream for scammers and fraudsters around the world, filled with opportunity and prosperity. They have had many events working to their advantage, helping them prey on and exploit innocent victims.

On April 13th, Adobe plans to release updates for Acrobat Reader for Windows, Mac and UNIX to resolve critical security issues. The new update, Adobe says, will fix several vulnerabilities and include an improved version of the software that Adobe uses to deliver its updates, helping end-users stay up-to-date in a much more streamlined and automated way. For the latest information, visit the Adobe Product Security Incident Response Team blog at: http://blogs.adobe.com/psirt

Apple today announced the biggest software update yet for the iPhone. iPhone OS 4 will include over 100 new features for iPhone and iPod touch owners, including some much desired security features for the enterprise. Set to be released this summer for iPhone and iPod touch, the update will be available for the iPad in the fall. A version is currently available for developers.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.