Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 59 min 55 sec ago

Google Ships Android ‘Advanced Protection’ Mode to Thwart Surveillance Spyware

3 hours 39 min ago

Google bundles multiple safeguards under a single Android toggle to protect high-risk users from advanced mobile malware implants.

The post Google Ships Android ‘Advanced Protection’ Mode to Thwart Surveillance Spyware appeared first on SecurityWeek.

Categories: SecurityWeek

Is AI Use in the Workplace Out of Control?

7 hours 8 min ago

Trying to block AI tools outright is a losing strategy. SaaS and AI are increasingly inseparable, and AI isn’t limited to tools like ChatGPT or Copilot anymore.

The post Is AI Use in the Workplace Out of Control? appeared first on SecurityWeek.

Categories: SecurityWeek

Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks

7 hours 29 min ago

Intel, AMD and Arm each published security advisories on Patch Tuesday, including for newly disclosed CPU attacks.

The post Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Kosovar Administrator of Cybercrime Marketplace Extradited to US

9 hours 52 min ago

Kosovo citizen Liridon Masurica has appeared in a US court, facing charges for his role in operating the cybercrime marketplace BlackDB.cc.

The post Kosovar Administrator of Cybercrime Marketplace Extradited to US appeared first on SecurityWeek.

Categories: SecurityWeek

EU Cybersecurity Agency ENISA Launches European Vulnerability Database

10 hours 11 min ago

Experts say the European Vulnerability Database, or EUVD, should be a good resource, but only if ENISA manages to maintain it properly.

The post EU Cybersecurity Agency ENISA Launches European Vulnerability Database appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerabilities Patched by Juniper, VMware and Zoom 

11 hours 19 min ago

Juniper Networks, VMware, and Zoom have announced patches for dozens of vulnerabilities across their products.

The post Vulnerabilities Patched by Juniper, VMware and Zoom  appeared first on SecurityWeek.

Categories: SecurityWeek

Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances

11 hours 58 min ago

Fortinet has patched a dozen vulnerabilities, including a critical flaw exploited in the wild against FortiVoice instances.

The post Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances appeared first on SecurityWeek.

Categories: SecurityWeek

Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers

14 hours 1 min ago

Ivanti has released patches for two EPMM vulnerabilities that have been chained in the wild for remote code execution.

The post Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers appeared first on SecurityWeek.

Categories: SecurityWeek

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact 

14 hours 25 min ago

Industrial giants Siemens, Schneider Electric and Phoenix Contact have released ICS security advisories on the May 2025 Patch Tuesday.

The post ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact  appeared first on SecurityWeek.

Categories: SecurityWeek

Adobe Patches Big Batch of Critical-Severity Software Flaws

Tue, 05/13/2025 - 3:36pm

Adobe Patch Tuesday headlined by a major Adobe ColdFusion update patching a wide swatch of code execution and privilege escalation attacks.

The post Adobe Patches Big Batch of Critical-Severity Software Flaws appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft to Lay Off About 3% of Its Workforce

Tue, 05/13/2025 - 3:24pm

The tech giant didn’t disclose the total amount of lost jobs but it will amount to about 6,000 people.

The post Microsoft to Lay Off About 3% of Its Workforce appeared first on SecurityWeek.

Categories: SecurityWeek

Zero-Day Attacks Highlight Another Busy Microsoft Patch Tuesday

Tue, 05/13/2025 - 2:13pm

Patch Tuesday: Microsoft patches at least 70 security bugs and flagged five zero-days in the “exploitation detected” category.

The post Zero-Day Attacks Highlight Another Busy Microsoft Patch Tuesday appeared first on SecurityWeek.

Categories: SecurityWeek

Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments

Tue, 05/13/2025 - 9:19am

CTI, digital brand protection and other cyber risk initiatives shouldn’t only be utilized by security and cyber teams.

The post Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments appeared first on SecurityWeek.

Categories: SecurityWeek

SAP Patches Another Critical NetWeaver Vulnerability

Tue, 05/13/2025 - 8:49am

SAP has released 16 new security notes on its May 2025 Security Patch Day, including a note dealing with another critical NetWeaver vulnerability.

The post SAP Patches Another Critical NetWeaver Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Radware Says Recently Disclosed WAF Bypasses Were Patched in 2023

Tue, 05/13/2025 - 8:29am

The Radware Cloud WAF product vulnerabilities disclosed by CERT/CC were addressed two years ago.

The post Radware Says Recently Disclosed WAF Bypasses Were Patched in 2023 appeared first on SecurityWeek.

Categories: SecurityWeek

Marks & Spencer Says Data Stolen in Ransomware Attack

Tue, 05/13/2025 - 7:19am

Marks & Spencer has confirmed that personal information was stolen in a recent cyberattack claimed by a ransomware group.

The post Marks & Spencer Says Data Stolen in Ransomware Attack appeared first on SecurityWeek.

Categories: SecurityWeek

Output Messenger Zero-Day Exploited by Turkish Hackers for Iraq Spying 

Tue, 05/13/2025 - 6:59am

A Turkey-affiliated espionage group has exploited a zero-day vulnerability in Output Messenger since April 2024.

The post Output Messenger Zero-Day Exploited by Turkish Hackers for Iraq Spying  appeared first on SecurityWeek.

Categories: SecurityWeek

Suspected DoppelPaymer Ransomware Group Member Arrested

Tue, 05/13/2025 - 6:03am

A 45-year-old individual was arrested in Moldova for his suspected involvement in DoppelPaymer ransomware attacks.

The post Suspected DoppelPaymer Ransomware Group Member Arrested appeared first on SecurityWeek.

Categories: SecurityWeek

Orca Snaps Up Opus in Cloud Security Automation Push

Tue, 05/13/2025 - 6:00am

Orca positioned the deal as an expansion of its capabilities into the realm of AI-based autonomous remediation and prevention. 

The post Orca Snaps Up Opus in Cloud Security Automation Push appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Warns of Flaw in TeleMessage App Used by Ex-National Security Advisor 

Tue, 05/13/2025 - 4:55am

An information exposure flaw in TeleMessage has been added to CISA’s Known Exploited Vulnerabilities catalog. 

The post CISA Warns of Flaw in TeleMessage App Used by Ex-National Security Advisor  appeared first on SecurityWeek.

Categories: SecurityWeek

Pages