Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 8 min 2 sec ago

Google Targets SOC Overload With Automated AI Alert and Malware Analysis Tools

Wed, 04/09/2025 - 1:49pm

Google plans to unleash automated AI agents into overtaxed SOCs to reduce the manual workload for cybersecurity investigators.

The post Google Targets SOC Overload With Automated AI Alert and Malware Analysis Tools appeared first on SecurityWeek.

Categories: SecurityWeek

Groucho’s Wit, Cloud Complexity, and the Case for Consistent Security Policy

Wed, 04/09/2025 - 1:30pm

The greatest security policies in the world are useless if enterprises don’t have a reasonable, consistent, and reliable way to implement them.

The post Groucho’s Wit, Cloud Complexity, and the Case for Consistent Security Policy appeared first on SecurityWeek.

Categories: SecurityWeek

AI Now Outsmarts Humans in Spear Phishing, Analysis Shows

Wed, 04/09/2025 - 1:01pm

Agentic AI has improved spear phishing effectiveness by 55% since 2023, research shows.

The post AI Now Outsmarts Humans in Spear Phishing, Analysis Shows appeared first on SecurityWeek.

Categories: SecurityWeek

Qevlar AI Raises $10 Million for Autonomous Investigation Platform

Wed, 04/09/2025 - 8:21am

French cybersecurity startup Qevlar AI has raised $10 million in a funding round led by EQT Ventures and Forgepoint Capital International.

The post Qevlar AI Raises $10 Million for Autonomous Investigation Platform appeared first on SecurityWeek.

Categories: SecurityWeek

Treasury’s OCC Says Hackers Had Access to 150,000 Emails

Wed, 04/09/2025 - 7:38am

The Office of the Comptroller of the Currency (OCC) has disclosed an email security incident in which 100 accounts were compromised for over a year. 

The post Treasury’s OCC Says Hackers Had Access to 150,000 Emails appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days

Wed, 04/09/2025 - 7:20am

CISA has added fresh CentreStack and Windows CLFS vulnerabilities to the Known Exploited Vulnerabilities catalog.

The post CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerabilities Patched by Ivanti, VMware, Zoom 

Wed, 04/09/2025 - 6:50am

Ivanti, VMware, and Zoom released fixes for dozens of vulnerabilities in their products on April 2025 Patch Tuesday.

The post Vulnerabilities Patched by Ivanti, VMware, Zoom  appeared first on SecurityWeek.

Categories: SecurityWeek

Fortinet Patches Critical FortiSwitch Vulnerability

Wed, 04/09/2025 - 6:30am

Fortinet fixes a critical-severity bug in FortiSwitch that could allow an attacker to modify administrative passwords.

The post Fortinet Patches Critical FortiSwitch Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Oracle Faces Mounting Criticism as It Notifies Customers of Hack

Wed, 04/09/2025 - 6:10am

Oracle is sending out written notifications to customers over the recent hack after it initially appeared to completely deny a data breach.

The post Oracle Faces Mounting Criticism as It Notifies Customers of Hack appeared first on SecurityWeek.

Categories: SecurityWeek

ICS Patch Tuesday: Vulnerabilities Addressed by Rockwell, ABB, Siemens, Schneider

Wed, 04/09/2025 - 4:54am

Industrial giants Siemens, Rockwell, Schneider and ABB have released their March 2025 Patch Tuesday ICS security advisories.

The post ICS Patch Tuesday: Vulnerabilities Addressed by Rockwell, ABB, Siemens, Schneider appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day

Tue, 04/08/2025 - 2:41pm

Patch Tuesday: Microsoft ships urgent cover for another WIndows CLFS vulnerability already exploited in the wild.

The post Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day appeared first on SecurityWeek.

Categories: SecurityWeek

Adobe Calls Urgent Attention to Critical ColdFusion Flaws

Tue, 04/08/2025 - 1:46pm

The Adobe Patch Tuesday rollout covers 54 vulnerabilities, including code execution issues in the oft-targeted Adobe ColdFusion software.

The post Adobe Calls Urgent Attention to Critical ColdFusion Flaws appeared first on SecurityWeek.

Categories: SecurityWeek

Network Access Vendor Portnox Secures $37.5 Million Investment

Tue, 04/08/2025 - 12:13pm

Texas network access control startup closes a Series B round led by Updata Partners and brings the total raised to $60 million.

The post Network Access Vendor Portnox Secures $37.5 Million Investment appeared first on SecurityWeek.

Categories: SecurityWeek

Octane Raises $6.75M for Smart Contract Security Tech

Tue, 04/08/2025 - 11:36am

San Francisco smart contract security startup closes a $6.75 million seed funding round led by Archetype and Winklevoss Capital.

The post Octane Raises $6.75M for Smart Contract Security Tech appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerability Management Firm Spektion Emerges From Stealth With $5 Million in Funding

Tue, 04/08/2025 - 11:28am

Spektion has emerged from stealth mode with $5 million in seed funding for its vulnerability management solution.

The post Vulnerability Management Firm Spektion Emerges From Stealth With $5 Million in Funding appeared first on SecurityWeek.

Categories: SecurityWeek

DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks

Tue, 04/08/2025 - 10:38am

While often relegated to a purely functional role, DNS offers unparalleled opportunities for preemptive defense against cyberattacks.

The post DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks appeared first on SecurityWeek.

Categories: SecurityWeek

Anecdotes Raises $30 Million for Enterprise GRC Platform

Tue, 04/08/2025 - 10:35am

Anecdotes has raised $55 million in an extended Series B funding round that brings the total raised by the company to $85 million. 

The post Anecdotes Raises $30 Million for Enterprise GRC Platform appeared first on SecurityWeek.

Categories: SecurityWeek

SAP Patches Critical Code Injection Vulnerabilities

Tue, 04/08/2025 - 9:22am

SAP released 20 security notes on April 2025 patch day, including three addressing critical code injection and authentication bypass flaws.

The post SAP Patches Critical Code Injection Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Aurascape Banks Hefty $50 Million to Mitigate ‘Shadow AI’ Risks

Tue, 04/08/2025 - 9:00am

Silicon Valley startup secures big investment from Menlo Ventures and Mayfield Fund to solve the “shadow AI” security problem.

The post Aurascape Banks Hefty $50 Million to Mitigate ‘Shadow AI’ Risks appeared first on SecurityWeek.

Categories: SecurityWeek

WhatsApp Vulnerability Could Facilitate Remote Code Execution

Tue, 04/08/2025 - 8:50am

An update for the WhatsApp desktop app for Windows patches CVE-2025-30401, a spoofing vulnerability that could be used to trick users.

The post WhatsApp Vulnerability Could Facilitate Remote Code Execution appeared first on SecurityWeek.

Categories: SecurityWeek

Pages