Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 3 min 9 sec ago

In Other News: 4chan Hacked, Android Auto-Reboot, Nemesis Admin Charged

Fri, 04/18/2025 - 7:30am

Noteworthy stories that might have slipped under the radar: 4chan hacked, auto-reboot security feature coming to Android, Iranian administrator of Nemesis charged in US.

The post In Other News: 4chan Hacked, Android Auto-Reboot, Nemesis Admin Charged appeared first on SecurityWeek.

Categories: SecurityWeek

Cy4Data Labs Raises $10 Million to Secure Data in Use

Fri, 04/18/2025 - 7:00am

Data protection firm Cy4Data Labs has raised $10 million in a Series A funding round led by Pelion Venture Partners.

The post Cy4Data Labs Raises $10 Million to Secure Data in Use appeared first on SecurityWeek.

Categories: SecurityWeek

Events Giant Legends International Hacked

Fri, 04/18/2025 - 6:40am

Legends International says the personal information of employees and customers was compromised as a result of a cyberattack.

The post Events Giant Legends International Hacked appeared first on SecurityWeek.

Categories: SecurityWeek

Ahold Delhaize Confirms Data Stolen in Ransomware Attack

Fri, 04/18/2025 - 6:10am

Ahold Delhaize has confirmed that data was stolen from its systems in November 2024 after a ransomware group claimed the attack.

The post Ahold Delhaize Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek.

Categories: SecurityWeek

Fresh Windows NTLM Vulnerability Exploited in Attacks

Fri, 04/18/2025 - 4:26am

A Windows NTLM vulnerability patched in March has been exploited in attacks targeting government and private institutions.

The post Fresh Windows NTLM Vulnerability Exploited in Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Man Helped Chinese Nationals Get Jobs Involving Sensitive US Government Projects

Thu, 04/17/2025 - 11:55am

Minh Phuong Ngoc Vong pleaded guilty to defrauding US companies of roughly $1 million in a fake IT worker scheme.

The post Man Helped Chinese Nationals Get Jobs Involving Sensitive US Government Projects appeared first on SecurityWeek.

Categories: SecurityWeek

Demystifying Security Posture Management

Thu, 04/17/2025 - 8:57am

While the Security Posture Management buzz is real, its long-term viability depends on whether it can deliver measurable outcomes without adding more complexity.

The post Demystifying Security Posture Management appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerabilities Patched in Atlassian, Cisco Products

Thu, 04/17/2025 - 8:28am

Atlassian and Cisco have released patches for multiple high-severity vulnerabilities, including remote code execution bugs.

The post Vulnerabilities Patched in Atlassian, Cisco Products appeared first on SecurityWeek.

Categories: SecurityWeek

Critical Erlang/OTP SSH Flaw Exposes Many Devices to Remote Hacking

Thu, 04/17/2025 - 8:14am

Servers exposed to complete takeover due to CVE-2025-32433, an unauthenticated remote code execution flaw in Erlang/OTP SSH.

The post Critical Erlang/OTP SSH Flaw Exposes Many Devices to Remote Hacking appeared first on SecurityWeek.

Categories: SecurityWeek

Why ‘One Community’ Resonates in Cybersecurity

Thu, 04/17/2025 - 7:41am

Our collective voices and one community will provide the intelligence we need to safeguard our businesses in today’s modern digital environment.

The post Why ‘One Community’ Resonates in Cybersecurity appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Issues Guidance After Oracle Cloud Hack

Thu, 04/17/2025 - 7:00am

CISA is making recommendations for organizations and users in light of the recent Oracle legacy cloud environment hack.

The post CISA Issues Guidance After Oracle Cloud Hack appeared first on SecurityWeek.

Categories: SecurityWeek

Chinese APT Mustang Panda Updates, Expands Arsenal

Thu, 04/17/2025 - 6:40am

The Chinese state-sponsored group Mustang Panda has used new and updated malicious tools in a recent attack.

The post Chinese APT Mustang Panda Updates, Expands Arsenal appeared first on SecurityWeek.

Categories: SecurityWeek

SonicWall Flags Old Vulnerability as Actively Exploited

Thu, 04/17/2025 - 6:10am

A SonicWall SMA 100 series vulnerability patched in 2021, which went unnoticed at the time of patching, is being exploited in the wild.

The post SonicWall Flags Old Vulnerability as Actively Exploited appeared first on SecurityWeek.

Categories: SecurityWeek

MITRE Hackers’ Backdoor Has Targeted Windows for Years

Thu, 04/17/2025 - 4:51am

Windows versions of the BrickStorm backdoor that the Chinese APT used in the MITRE hack last year have been active for years.

The post MITRE Hackers’ Backdoor Has Targeted Windows for Years appeared first on SecurityWeek.

Categories: SecurityWeek

Krebs Exits SentinelOne After Security Clearance Pulled

Wed, 04/16/2025 - 5:39pm

Chris Krebs has resigned from SentinelOne after security clearance withdrawn and an order to review CISA’s conduct under his leadership.

The post Krebs Exits SentinelOne After Security Clearance Pulled appeared first on SecurityWeek.

Categories: SecurityWeek

Apple Quashes Two Zero-Days With iOS, MacOS Patches

Wed, 04/16/2025 - 4:32pm

The vulnerabilities are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms.

The post Apple Quashes Two Zero-Days With iOS, MacOS Patches appeared first on SecurityWeek.

Categories: SecurityWeek

MITRE CVE Program Gets Last-Hour Funding Reprieve

Wed, 04/16/2025 - 12:25pm

The US government's cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational.

The post MITRE CVE Program Gets Last-Hour Funding Reprieve appeared first on SecurityWeek.

Categories: SecurityWeek

Many Mobile Apps Fail Basic Security—Posing Serious Risks to Enterprises

Wed, 04/16/2025 - 10:01am

Top-ranked mobile apps found using hardcoded keys and exposed cloud buckets.

The post Many Mobile Apps Fail Basic Security—Posing Serious Risks to Enterprises appeared first on SecurityWeek.

Categories: SecurityWeek

Pillar Security Banks $9M for AI Security Guardrails

Wed, 04/16/2025 - 9:39am

Shield Capital leads a $9 million seed-stage funding round for Israeli startup building technologies for AI security and privacy guardrails.

The post Pillar Security Banks $9M for AI Security Guardrails appeared first on SecurityWeek.

Categories: SecurityWeek

Ransomware Group Claims Hacking of Oregon Regulator After Data Breach Denial

Wed, 04/16/2025 - 8:21am

The Rhysida ransomware gang claims to have stolen 2.5 Tb of files from the Oregon Department of Environmental Quality.

The post Ransomware Group Claims Hacking of Oregon Regulator After Data Breach Denial appeared first on SecurityWeek.

Categories: SecurityWeek

Pages