Latest Cybersecurity News
Rapid7 says attackers are targeting a critical pre-authentication flaw in Progress Software’s WS_FTP server just days after disclosure.
Hackers stole a database containing the list of the European Telecommunications Standards Institute’s online users.
The number of internet-exposed ICS has dropped below 100,000, a significant decrease from the 140,000 in 2019.
DHS is reportedly investigating the impact of the recent Johnson Controls ransomware attack on its systems and facilities.
Patches are being developed for serious Exim vulnerabilities that could expose many mail servers to attacks.
CISA has announced the Secure Our World cybersecurity awareness program, targeting both businesses and end users.
In-the-wild exploitation of a critical vulnerability in the TeamCity CI/CD server started shortly after a patch was released by developers.
Silverfort has released the source code for its lateral movement detection tool LATMA, to help identify and analyze intrusions.
Bankrupt and out of financing options, IronNet has terminated all employees and plan to file for Chapter 7 protection.
AWS says an internal threat intel decoy system called MadPot has successfully trapped nation state-backed APTs like Volt Typhoon and Sandworm.
Nexusflow scores funding to build an open-source LLM that can deliver high accuracy when retrieving data from multiple security sources.
Noteworthy stories that might have slipped under the radar: new RSA encryption attack, Meta’s AI privacy safeguards, and ShinyHunters hackers’ guilty plea.
A group of academic researchers devised a technique to extract sounds from still images captured using smartphone cameras with rolling shutter and movable lens structures.
Top Cybersecurity Headlines
Rapid7 says attackers are targeting a critical pre-authentication flaw in Progress Software’s WS_FTP server just days after disclosure.
Hackers stole a database containing the list of the European Telecommunications Standards Institute’s online users.
The number of internet-exposed ICS has dropped below 100,000, a significant decrease from the 140,000 in 2019.
DHS is reportedly investigating the impact of the recent Johnson Controls ransomware attack on its systems and facilities.
SecurityWeek Industry Experts
Trending
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Webinar: Beyond VPN Replacement: Other ZTNA superpowers CISOs Should Know
Join security experts as they discuss ZTNA’s untapped potential to both reduce cyber risk and empower the business.
RegisterWebinar: Scaling Software Supply Chain Security: Driving Actionable SBOM Management with the OpenSSF S2C2F OSS Specification
Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.
RegisterUpcoming Virtual Events

Zero Trust is more than a marketing buzzword. In this event, security experts will decipher the confusing world of Zero Trust, and share war stories on securing organizations by eliminating implicit trust and continuously validating every stage of digital interaction.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence. (May 24, 2023)

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place in 2023 as a virtual event. (June 13-14, 2023)

As CISOs and corporate defenders grapple with the intricacies of securing sensitive data passing through multi-cloud deployments and APIs, the importance of frameworks, tools, controls and design models have surfaced to the front burner. (July 19, 2023)