Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 35 min 50 sec ago

Bybit Hack Drains $1.5 Billion From Cryptocurrency Exchange

2 hours 2 min ago

Over 400,000 ETH and stETH worth more than $1.5 billion were stolen from the Bybit cryptocurrency exchange.

The post Bybit Hack Drains $1.5 Billion From Cryptocurrency Exchange appeared first on SecurityWeek.

Categories: SecurityWeek

Freelance Software Developers in North Korean Malware Crosshairs

Fri, 02/21/2025 - 10:58am

ESET says hundreds of freelance software developers have fallen victim to North Korean hackers posing as recruiters.

The post Freelance Software Developers in North Korean Malware Crosshairs appeared first on SecurityWeek.

Categories: SecurityWeek

Apple Pulls Advanced Data Protection for New UK Users Amid Backdoor Demand

Fri, 02/21/2025 - 10:56am

Apple says it can no longer offer end-to-end encrypted cloud backups in the UK and insists it will never build a backdoor or master key.

The post Apple Pulls Advanced Data Protection for New UK Users Amid Backdoor Demand appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Details ‘Salt Typhoon’ Network Hopping, Credential Theft Tactics

Fri, 02/21/2025 - 9:54am

Cisco Talos observed Chinese hackers pivoting from a compromised device operated by one telecom to target a device in another telecom.

The post Cisco Details ‘Salt Typhoon’ Network Hopping, Credential Theft Tactics appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Black Basta Chats Leaked, New SEC Cyber Unit, DOGE Site Hacked

Fri, 02/21/2025 - 8:35am

Noteworthy stories that might have slipped under the radar: Black Basta ransomware chat logs leaked, SEC launches new cyber unit, DOGE website hacked.

The post In Other News: Black Basta Chats Leaked, New SEC Cyber Unit, DOGE Site Hacked appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerabilities in MongoDB Library Allow RCE on Node.js Servers

Fri, 02/21/2025 - 8:07am

OPSWAT details two critical vulnerabilities in the Mongoose ODM library for MongoDB leading to remote code execution on the Node.js server.

The post Vulnerabilities in MongoDB Library Allow RCE on Node.js Servers appeared first on SecurityWeek.

Categories: SecurityWeek

How China Pinned University Cyberattacks on NSA Hackers

Fri, 02/21/2025 - 7:26am

A researcher dives into Chinese reports attributing cyberattacks on Northwestern Polytechnical University to the NSA’s TAO division.

The post How China Pinned University Cyberattacks on NSA Hackers appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Warns of Attacks Exploiting Craft CMS Vulnerability

Fri, 02/21/2025 - 6:44am

CISA has added a Craft CMS flaw tracked as CVE-2025-23209 to its Known Exploited Vulnerabilities (KEV) catalog.

The post CISA Warns of Attacks Exploiting Craft CMS Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Second Recently Patched Flaw Exploited to Hack Palo Alto Firewalls

Fri, 02/21/2025 - 6:01am

Palo Alto Networks is warning customers that a second vulnerability patched in February is being exploited in attacks.

The post Second Recently Patched Flaw Exploited to Hack Palo Alto Firewalls appeared first on SecurityWeek.

Categories: SecurityWeek

Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines

Thu, 02/20/2025 - 12:04pm

China-linked cyberespionage toolkits are popping up in ransomware attacks, forcing defenders to rethink how they combat state-backed hackers.

The post Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines appeared first on SecurityWeek.

Categories: SecurityWeek

Mining Company NioCorp Loses $500,000 in BEC Hack

Thu, 02/20/2025 - 11:02am

NioCorp Developments has informed the SEC that it lost $0.5 million after its systems were compromised.

The post Mining Company NioCorp Loses $500,000 in BEC Hack appeared first on SecurityWeek.

Categories: SecurityWeek

AI Can Supercharge Productivity, But we Still Need a Human-in-the-Loop

Thu, 02/20/2025 - 9:23am

AI systems can sometimes struggle with complex or nuanced situations, so human intervention can help identify and address potential issues that algorithms might not.

The post AI Can Supercharge Productivity, But we Still Need a Human-in-the-Loop appeared first on SecurityWeek.

Categories: SecurityWeek

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd

Thu, 02/20/2025 - 8:34am

Atlassian has released patches for 12 critical- and high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd, and Jira.

The post Atlassian Patches Critical Vulnerabilities in Confluence, Crowd appeared first on SecurityWeek.

Categories: SecurityWeek

CISA, FBI Warn of China-Linked Ghost Ransomware Attacks

Thu, 02/20/2025 - 8:24am

CISA and the FBI warn organizations of attacks employing the Ghost (Cring) ransomware, operated by Chinese hackers.

The post CISA, FBI Warn of China-Linked Ghost Ransomware Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

PoC Exploit Published for Critical Ivanti EPM Vulnerabilities

Thu, 02/20/2025 - 6:41am

Proof-of-concept (PoC) code and technical details on four critical-severity Ivanti EPM vulnerabilities are now available.

The post PoC Exploit Published for Critical Ivanti EPM Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

US Military Health Provider HNFS Pays $11M in Settlement Over Cybersecurity Failures

Thu, 02/20/2025 - 6:15am

US military health benefits program administrator HNFS to pay $11 million in settlement over its false claims of cybersecurity compliance.

The post US Military Health Provider HNFS Pays $11M in Settlement Over Cybersecurity Failures appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft Patches Exploited Power Pages Vulnerability

Thu, 02/20/2025 - 5:44am

Microsoft has patched CVE-2025-24989, a Power Pages privilege escalation vulnerability that has been exploited in attacks.

The post Microsoft Patches Exploited Power Pages Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

How Hackers Manipulate Agentic AI with Prompt Engineering

Wed, 02/19/2025 - 9:43am

Organizations adopting the transformative nature of agentic AI are urged to take heed of prompt engineering tactics being practiced by threat actors.

The post How Hackers Manipulate Agentic AI with Prompt Engineering appeared first on SecurityWeek.

Categories: SecurityWeek

CISO Conversations: Kevin Winter at Deloitte and Richard Marcus at AuditBoard

Wed, 02/19/2025 - 9:22am

SecurityWeek speaks with Kevin Winter, Global CISO at Deloitte, and Richard Marcus, CISO at AuditBoard.

The post CISO Conversations: Kevin Winter at Deloitte and Richard Marcus at AuditBoard appeared first on SecurityWeek.

Categories: SecurityWeek

Blockaid Raises $50 Million to Secure Blockchain Applications

Wed, 02/19/2025 - 8:45am

Blockaid raises $50 million in Series B funding to scale operations to meet demand for its blockchain application security platform.

The post Blockaid Raises $50 Million to Secure Blockchain Applications appeared first on SecurityWeek.

Categories: SecurityWeek

Pages