Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.

Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.

The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. 

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take.

Altman made a slew of product announcements and updates, including the company’s new agents, called Dots.

The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software.

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel

The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe.

AI code of conduct AI code of conduct

Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.

ShinyHunters hackers ShinyHunters hackers

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

White House cybersecurity White House cybersecurity

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take.

Top Cybersecurity Headlines

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

Upcoming Cybersecurity Events

ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

SecurityWeek’s 2026 Zero Trust Summit will deep-dive into the world of digital identity management and the role of zero-trust principles and associated technologies
[October 14, 2026 | Virtual]

Read More
CISO Forum Virtual Summit 2026

The 2026 Virtual CISO Forum brings together CISOs, senior cybersecurity executives, practitioners, industry experts, and other security leaders to share practical experience and examine the issues shaping enterprise cybersecurity strategy.
[November 11, 2026]

Read More

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[Originally August 19, 2026]

Learn More

Vulnerabilities

Cybercrime

Apple today announced the biggest software update yet for the iPhone. iPhone OS 4 will include over 100 new features for iPhone and iPod touch owners, including some much desired security features for the enterprise. Set to be released this summer for iPhone and iPod touch, the update will be available for the iPad in the fall. A version is currently available for developers.

Wolters Kluwer Financial Services announced today the launch of its Wiz Sentri™ Financial Crime Control platform. Utilizing real-time, continuous behavioral and transaction monitoring and analysis, the solution aims to help financial institutions predict and prevent financial crimes before they occur. 

Sybase, Inc. (NYSE:SY), today announced support for iPad and Android devices with the latest release of, Afaria, their mobile device management and security solution for the enterprise."The popularity of highly functional smart mobile devices, such as iPhone, Android and now the iPad, is significantly impacting enterprise mobility support requirements as these devices increasingly cross over from consumers into the corporate setting," said Jack Gold, president and principal analyst of J. Gold Associates, LLC.

Suppose a friend wants you to meet her cousin Bill at a black tie affair. You don’t have a photo of Bill to help you find him among the five hundred or so people in attendance—you only have your cousin’s description of Bill.

Sunbelt Software today announced the availability of Sunbelt CWSandbox 3.0, an upgraded version of their automated dynamic malware analysis tool. CWSandbox leverages unique behavior analysis technology for the identification of malicious threats like PDF exploits, fake media players and other socially engineered attacks against enterprise or government networks.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.

Cloud Security

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.