Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry.

Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains.

The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.

Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices.

Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.

OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in.

The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.

$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and AI infrastructure and coding tools.

Researchers from George Washington University have published a paper examining whether the time and cause of AI going rogue can be predicted.

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.

All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable.

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.

Hackers Hackers

$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and AI infrastructure and coding tools.

AI hacking AI hacking

Researchers from George Washington University have published a paper examining whether the time and cause of AI going rogue can be predicted.

Security awareness training Security awareness training

All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable.

Top Cybersecurity Headlines

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

Upcoming Cybersecurity Events

ICS Cybersecurity Conference 2026

SecurityWeek’s ICS Cybersecurity Conference celebrates its 25th anniversary in Nashville. Join the largest and longest-running event series focused on industrial cybersecurity.
[October 6-8, 2026 | In-Person]

Learn More

SecurityWeek’s 2026 Zero Trust Summit will deep-dive into the world of digital identity management and the role of zero-trust principles and associated technologies
[October 14, 2026 | Virtual]

Read More
CISO Forum Virtual Summit 2026

The 2026 Virtual CISO Forum brings together CISOs, senior cybersecurity executives, practitioners, industry experts, and other security leaders to share practical experience and examine the issues shaping enterprise cybersecurity strategy.
[November 11, 2026]

Read More

SecurityWeek’s CodeSecCon 2026 will bring together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
[Originally August 19, 2026]

Learn More

Vulnerabilities

Cybercrime

Suppose a friend wants you to meet her cousin Bill at a black tie affair. You don’t have a photo of Bill to help you find him among the five hundred or so people in attendance—you only have your cousin’s description of Bill.

Sunbelt Software today announced the availability of Sunbelt CWSandbox 3.0, an upgraded version of their automated dynamic malware analysis tool. CWSandbox leverages unique behavior analysis technology for the identification of malicious threats like PDF exploits, fake media players and other socially engineered attacks against enterprise or government networks.

PhoneGuard, a provider of mobile security services, today announced availability of its anti-virus software for Android smartphones. Partnering with China based NetQin Technology, PhoneGuard provides a defense against threats including viruses, spyware and malware that target mobile devices.

Anti-virus products scan for malware in two ways. They look for sequences of bits that are found in programs that are known to be “evil” (but which are not commonly found in “good” programs). And they run programs in sandboxes and look for known malicious actions. The first approach only catches known malware instances, while the second can also catch variants of these. Still, many malware agents slip through the cracks undetected...

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in.

Cloud Security

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.