SecurityWeek

AI Now Outsmarts Humans in Spear Phishing, Analysis Shows

Security Week - Wed, 04/09/2025 - 1:01pm

Agentic AI has improved spear phishing effectiveness by 55% since 2023, research shows.

The post AI Now Outsmarts Humans in Spear Phishing, Analysis Shows appeared first on SecurityWeek.

Categories: SecurityWeek

Qevlar AI Raises $10 Million for Autonomous Investigation Platform

Security Week - Wed, 04/09/2025 - 8:21am

French cybersecurity startup Qevlar AI has raised $10 million in a funding round led by EQT Ventures and Forgepoint Capital International.

The post Qevlar AI Raises $10 Million for Autonomous Investigation Platform appeared first on SecurityWeek.

Categories: SecurityWeek

Treasury’s OCC Says Hackers Had Access to 150,000 Emails

Security Week - Wed, 04/09/2025 - 7:38am

The Office of the Comptroller of the Currency (OCC) has disclosed an email security incident in which 100 accounts were compromised for over a year. 

The post Treasury’s OCC Says Hackers Had Access to 150,000 Emails appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days

Security Week - Wed, 04/09/2025 - 7:20am

CISA has added fresh CentreStack and Windows CLFS vulnerabilities to the Known Exploited Vulnerabilities catalog.

The post CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerabilities Patched by Ivanti, VMware, Zoom 

Security Week - Wed, 04/09/2025 - 6:50am

Ivanti, VMware, and Zoom released fixes for dozens of vulnerabilities in their products on April 2025 Patch Tuesday.

The post Vulnerabilities Patched by Ivanti, VMware, Zoom  appeared first on SecurityWeek.

Categories: SecurityWeek

Fortinet Patches Critical FortiSwitch Vulnerability

Security Week - Wed, 04/09/2025 - 6:30am

Fortinet fixes a critical-severity bug in FortiSwitch that could allow an attacker to modify administrative passwords.

The post Fortinet Patches Critical FortiSwitch Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Oracle Faces Mounting Criticism as It Notifies Customers of Hack

Security Week - Wed, 04/09/2025 - 6:10am

Oracle is sending out written notifications to customers over the recent hack after it initially appeared to completely deny a data breach.

The post Oracle Faces Mounting Criticism as It Notifies Customers of Hack appeared first on SecurityWeek.

Categories: SecurityWeek

ICS Patch Tuesday: Vulnerabilities Addressed by Rockwell, ABB, Siemens, Schneider

Security Week - Wed, 04/09/2025 - 4:54am

Industrial giants Siemens, Rockwell, Schneider and ABB have released their March 2025 Patch Tuesday ICS security advisories.

The post ICS Patch Tuesday: Vulnerabilities Addressed by Rockwell, ABB, Siemens, Schneider appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day

Security Week - Tue, 04/08/2025 - 2:41pm

Patch Tuesday: Microsoft ships urgent cover for another WIndows CLFS vulnerability already exploited in the wild.

The post Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day appeared first on SecurityWeek.

Categories: SecurityWeek

Adobe Calls Urgent Attention to Critical ColdFusion Flaws

Security Week - Tue, 04/08/2025 - 1:46pm

The Adobe Patch Tuesday rollout covers 54 vulnerabilities, including code execution issues in the oft-targeted Adobe ColdFusion software.

The post Adobe Calls Urgent Attention to Critical ColdFusion Flaws appeared first on SecurityWeek.

Categories: SecurityWeek

Network Access Vendor Portnox Secures $37.5 Million Investment

Security Week - Tue, 04/08/2025 - 12:13pm

Texas network access control startup closes a Series B round led by Updata Partners and brings the total raised to $60 million.

The post Network Access Vendor Portnox Secures $37.5 Million Investment appeared first on SecurityWeek.

Categories: SecurityWeek

Octane Raises $6.75M for Smart Contract Security Tech

Security Week - Tue, 04/08/2025 - 11:36am

San Francisco smart contract security startup closes a $6.75 million seed funding round led by Archetype and Winklevoss Capital.

The post Octane Raises $6.75M for Smart Contract Security Tech appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerability Management Firm Spektion Emerges From Stealth With $5 Million in Funding

Security Week - Tue, 04/08/2025 - 11:28am

Spektion has emerged from stealth mode with $5 million in seed funding for its vulnerability management solution.

The post Vulnerability Management Firm Spektion Emerges From Stealth With $5 Million in Funding appeared first on SecurityWeek.

Categories: SecurityWeek

DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks

Security Week - Tue, 04/08/2025 - 10:38am

While often relegated to a purely functional role, DNS offers unparalleled opportunities for preemptive defense against cyberattacks.

The post DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks appeared first on SecurityWeek.

Categories: SecurityWeek

Anecdotes Raises $30 Million for Enterprise GRC Platform

Security Week - Tue, 04/08/2025 - 10:35am

Anecdotes has raised $55 million in an extended Series B funding round that brings the total raised by the company to $85 million. 

The post Anecdotes Raises $30 Million for Enterprise GRC Platform appeared first on SecurityWeek.

Categories: SecurityWeek

SAP Patches Critical Code Injection Vulnerabilities

Security Week - Tue, 04/08/2025 - 9:22am

SAP released 20 security notes on April 2025 patch day, including three addressing critical code injection and authentication bypass flaws.

The post SAP Patches Critical Code Injection Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Aurascape Banks Hefty $50 Million to Mitigate ‘Shadow AI’ Risks

Security Week - Tue, 04/08/2025 - 9:00am

Silicon Valley startup secures big investment from Menlo Ventures and Mayfield Fund to solve the “shadow AI” security problem.

The post Aurascape Banks Hefty $50 Million to Mitigate ‘Shadow AI’ Risks appeared first on SecurityWeek.

Categories: SecurityWeek

WhatsApp Vulnerability Could Facilitate Remote Code Execution

Security Week - Tue, 04/08/2025 - 8:50am

An update for the WhatsApp desktop app for Windows patches CVE-2025-30401, a spoofing vulnerability that could be used to trick users.

The post WhatsApp Vulnerability Could Facilitate Remote Code Execution appeared first on SecurityWeek.

Categories: SecurityWeek

ESET Vulnerability Exploited for Stealthy Malware Execution

Security Week - Tue, 04/08/2025 - 8:29am

A sophisticated APT tracked as ToddyCat has exploited an ESET DLL search order hijacking vulnerability for malware delivery.

The post ESET Vulnerability Exploited for Stealthy Malware Execution appeared first on SecurityWeek.

Categories: SecurityWeek

Corsha Raises $18 Million to Enhance and Extend Machine-to-Machine Security

Security Week - Tue, 04/08/2025 - 8:00am

The new funds will be used to extend Corsha’s reach into critical infrastructure and further improve its own use of AI.

The post Corsha Raises $18 Million to Enhance and Extend Machine-to-Machine Security appeared first on SecurityWeek.

Categories: SecurityWeek

Pages