Security Week

Subscribe to Security Week feed Security Week
Cybersecurity News, Insights & Analysis
Updated: 23 min 51 sec ago

New ‘ResolverRAT’ Targeting Healthcare, Pharmaceutical Organizations

Mon, 04/14/2025 - 9:40am

Organizations in the healthcare and pharmaceutical sectors have been targeted with ResolverRAT, a new malware family with advanced capabilities.

The post New ‘ResolverRAT’ Targeting Healthcare, Pharmaceutical Organizations appeared first on SecurityWeek.

Categories: SecurityWeek

AI Hallucinations Create a New Software Supply Chain Threat

Mon, 04/14/2025 - 8:54am

Researchers uncover new software supply chain threat from LLM-generated package hallucinations.

The post AI Hallucinations Create a New Software Supply Chain Threat appeared first on SecurityWeek.

Categories: SecurityWeek

Industry Moves for the week of April 14, 2025 - SecurityWeek

Mon, 04/14/2025 - 6:41am
Explore industry moves and significant changes in the industry for the week of April 14, 2025. Stay updated with the latest industry trends and shifts.
Categories: SecurityWeek

Malicious NPM Packages Target Cryptocurrency, PayPal Users

Mon, 04/14/2025 - 6:41am

Threat actors are publishing malicious NPM packages to steal PayPal credentials and hijack cryptocurrency transfers.

The post Malicious NPM Packages Target Cryptocurrency, PayPal Users appeared first on SecurityWeek.

Categories: SecurityWeek

Rapid7 Reveals RCE Path in Ivanti VPN Appliance After Silent Patch Debacle

Fri, 04/11/2025 - 1:48pm

The CVE-2025-22457 has already been exploited by a China-nexus hacking gang notorious for breaking into edge network devices.

The post Rapid7 Reveals RCE Path in Ivanti VPN Appliance After Silent Patch Debacle appeared first on SecurityWeek.

Categories: SecurityWeek

Hackers Breach Morocco’s Social Security Database

Fri, 04/11/2025 - 10:02am

The hackers who posted the documents on Telegram said the attack was in response to alleged Moroccan “harassment” of Algeria on social media platforms.

The post Hackers Breach Morocco’s Social Security Database appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerability in OttoKit WordPress Plugin Exploited in the Wild

Fri, 04/11/2025 - 8:15am

A vulnerability in the OttoKit WordPress plugin with over 100,000 active installations has been exploited in the wild.

The post Vulnerability in OttoKit WordPress Plugin Exploited in the Wild appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Scattered Spider Still Active, EncryptHub Unmasked, Rydox Extraditions

Fri, 04/11/2025 - 8:00am

Noteworthy stories that might have slipped under the radar: Scattered Spider still active despite arrests, hacker known as EncryptHub unmasked, Rydox admins extradited to US. 

The post In Other News: Scattered Spider Still Active, EncryptHub Unmasked, Rydox Extraditions appeared first on SecurityWeek.

Categories: SecurityWeek

SonicWall Patches High-Severity Vulnerability in NetExtender

Fri, 04/11/2025 - 7:00am

SonicWall has released fixes for three vulnerabilities in NetExtender for Windows, including a high-severity bug.

The post SonicWall Patches High-Severity Vulnerability in NetExtender appeared first on SecurityWeek.

Categories: SecurityWeek

1.6 Million People Impacted by Data Breach at Laboratory Services Cooperative

Fri, 04/11/2025 - 6:35am

Laboratory Services Cooperative says the personal and medical information of 1.6 million was stolen in an October 2024 data breach.

The post 1.6 Million People Impacted by Data Breach at Laboratory Services Cooperative appeared first on SecurityWeek.

Categories: SecurityWeek

China Admitted to US That It Conducted Volt Typhoon Attacks: Report

Fri, 04/11/2025 - 6:10am

In a secret meeting between Chinese and US officials, the former confirmed conducting cyberattacks on US infrastructure.

The post China Admitted to US That It Conducted Volt Typhoon Attacks: Report appeared first on SecurityWeek.

Categories: SecurityWeek

Rising Tides: Bryson Bort on Cyber Entrepreneurship and the Needed Focus on Critical Infrastructure

Fri, 04/11/2025 - 6:03am

Very few people in the cybersecurity industry do not know, or know of, Bryson Bort. Yes, he’s the CEO/Founder of SCYTHE, but he’s also the co-founder of ICS Village (the next one at RSA Conference from April 28 to May 1, 2025). This event, and all of our industry’s attention on critical infrastructure, is pivotal […]

The post Rising Tides: Bryson Bort on Cyber Entrepreneurship and the Needed Focus on Critical Infrastructure appeared first on SecurityWeek.

Categories: SecurityWeek

Europol Targets Customers of Smokeloader Pay-Per-Install Botnet

Thu, 04/10/2025 - 11:15am

Law enforcement agencies in multiple countries have announced the arrests of users of the malicious Smokeloader botnet.

The post Europol Targets Customers of Smokeloader Pay-Per-Install Botnet appeared first on SecurityWeek.

Categories: SecurityWeek

Trump Revokes Security Clearance for Ex-CISA Director Chris Krebs

Thu, 04/10/2025 - 10:45am

Trump orders a termination of any active security clearances held by Krebs and a suspension of clearances held by individuals at SentinelOne.

The post Trump Revokes Security Clearance for Ex-CISA Director Chris Krebs appeared first on SecurityWeek.

Categories: SecurityWeek

Juniper Networks Patches Dozens of Junos Vulnerabilities

Thu, 04/10/2025 - 9:34am

Juniper Networks has patched two dozen vulnerabilities in Junos OS and Junos OS Evolved, and dozens of flaws in Junos Space third-party dependencies.

The post Juniper Networks Patches Dozens of Junos Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Study Identifies 20 Most Vulnerable Connected Devices of 2025

Thu, 04/10/2025 - 8:01am

Routers are the riskiest devices in enterprise networks as they contain the most critical vulnerabilities, a new Forescout report shows.

The post Study Identifies 20 Most Vulnerable Connected Devices of 2025 appeared first on SecurityWeek.

Categories: SecurityWeek

GitHub Announces General Availability of Security Campaigns

Thu, 04/10/2025 - 7:10am

GitHub security campaigns make it easier for developers and security teams to collaborate on fixing vulnerabilities in their applications.

The post GitHub Announces General Availability of Security Campaigns appeared first on SecurityWeek.

Categories: SecurityWeek

Nissan Leaf Hacked for Remote Spying, Physical Takeover

Thu, 04/10/2025 - 6:40am

Researchers find vulnerabilities that can be exploited to remotely take control of a Nissan Leaf’s functions, including physical controls.

The post Nissan Leaf Hacked for Remote Spying, Physical Takeover appeared first on SecurityWeek.

Categories: SecurityWeek

Operations of Sensor Giant Sensata Disrupted by Ransomware Attack

Thu, 04/10/2025 - 6:10am

Sensata has informed the SEC that shipping, manufacturing and other operations have been impacted by a ransomware attack.

The post Operations of Sensor Giant Sensata Disrupted by Ransomware Attack appeared first on SecurityWeek.

Categories: SecurityWeek

‘AkiraBot’ Spammed 80,000 Websites With AI-Generated Messages

Thu, 04/10/2025 - 4:50am

CAPTCHA-evading Python framework AkiraBot has spammed over 80,000 websites with AI-generated spam messages.

The post ‘AkiraBot’ Spammed 80,000 Websites With AI-Generated Messages appeared first on SecurityWeek.

Categories: SecurityWeek

Pages