Featured

Apple Unveils iPhone Memory Protections to Combat Sophisticated Attacks

Apple Unveils iPhone Memory Protections to Combat Sophisticated Attacks 2025-09-10 at 15:54 By Eduard Kovacs Apple’s new Memory Integrity Enforcement (MIE) brings always-on memory-safety protection covering key attack surfaces — including the kernel and over 70 userland processes. The post Apple Unveils iPhone Memory Protections to Combat Sophisticated Attacks appeared first on SecurityWeek. This article […]

Apple Unveils iPhone Memory Protections to Combat Sophisticated Attacks Read More »

Highly Popular NPM Packages Poisoned in New Supply Chain Attack

Highly Popular NPM Packages Poisoned in New Supply Chain Attack 2025-09-10 at 11:45 By Ionut Arghire Designed to intercept cryptocurrency transactions, the malicious code reached 10% of cloud environments. The post Highly Popular NPM Packages Poisoned in New Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Highly Popular NPM Packages Poisoned in New Supply Chain Attack Read More »

Microsoft Patches 86 Vulnerabilities

Microsoft Patches 86 Vulnerabilities 2025-09-09 at 21:57 By Eduard Kovacs Microsoft has released patches for dozens of flaws in Windows and other products, including ones with ‘exploitation more likely’ rating. The post Microsoft Patches 86 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches 86 Vulnerabilities Read More »

Mitsubishi Electric to Acquire Nozomi Networks for Nearly $1 Billion

Mitsubishi Electric to Acquire Nozomi Networks for Nearly $1 Billion 2025-09-09 at 14:00 By Eduard Kovacs The industrial cybersecurity firm will become a wholly owned subsidiary of Mitsubishi Electric. The post Mitsubishi Electric to Acquire Nozomi Networks for Nearly $1 Billion appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Mitsubishi Electric to Acquire Nozomi Networks for Nearly $1 Billion Read More »

Salesloft GitHub Account Compromised Months Before Salesforce Attack

Salesloft GitHub Account Compromised Months Before Salesforce Attack 2025-09-08 at 16:06 By Ionut Arghire The list of impacted cybersecurity firms has been expanded to include BeyondTrust, Bugcrowd, CyberArk, Cato Networks, JFrog, and Rubrik. The post Salesloft GitHub Account Compromised Months Before Salesforce Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Salesloft GitHub Account Compromised Months Before Salesforce Attack Read More »

Fintech Firm Wealthsimple Says Supply Chain Attack Resulted in Data Breach

Fintech Firm Wealthsimple Says Supply Chain Attack Resulted in Data Breach 2025-09-08 at 13:05 By Eduard Kovacs Canadian firm Wealthsimple says a data breach impacts the information of some customers, but accounts and funds remain secure. The post Fintech Firm Wealthsimple Says Supply Chain Attack Resulted in Data Breach appeared first on SecurityWeek. This article

Fintech Firm Wealthsimple Says Supply Chain Attack Resulted in Data Breach Read More »

More Cybersecurity Firms Hit by Salesforce-Salesloft Drift Breach

More Cybersecurity Firms Hit by Salesforce-Salesloft Drift Breach 2025-09-05 at 11:51 By Ionut Arghire Proofpoint, SpyCloud, Tanium, and Tenable confirmed that hackers accessed information stored in their Salesforce instances. The post More Cybersecurity Firms Hit by Salesforce-Salesloft Drift Breach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Cybersecurity Firms Hit by Salesforce-Salesloft Drift Breach Read More »

Recent SAP S/4HANA Vulnerability Exploited in Attacks

Recent SAP S/4HANA Vulnerability Exploited in Attacks 2025-09-05 at 11:09 By Eduard Kovacs A critical SAP S/4HANA code injection flaw tracked as CVE-2025-42957 and allowing full system takeover has been exploited in the wild. The post Recent SAP S/4HANA Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Recent SAP S/4HANA Vulnerability Exploited in Attacks Read More »

Apple Seeks Researchers for 2026 iPhone Security Program

Apple Seeks Researchers for 2026 iPhone Security Program 2025-09-04 at 18:23 By Eduard Kovacs Security researchers interested in participating in the 2026 Apple Security Research Device program can apply until October 31. The post Apple Seeks Researchers for 2026 iPhone Security Program appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Apple Seeks Researchers for 2026 iPhone Security Program Read More »

Two Exploited Vulnerabilities Patched in Android

Two Exploited Vulnerabilities Patched in Android 2025-09-04 at 11:40 By Ionut Arghire Elevation of privilege flaws in Android Runtime (CVE-2025-48543) and Linux kernel (CVE-2025-38352) have been exploited in targeted attacks. The post Two Exploited Vulnerabilities Patched in Android appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Two Exploited Vulnerabilities Patched in Android Read More »

US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack

US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack 2025-09-03 at 22:15 By Ionut Arghire Flaw allows attackers to reset and hijack TP-Link TL-WA855RE devices; CISA urges users to retire discontinued extenders. The post US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack appeared first on SecurityWeek. This article is an

US Cybersecurity Agency Flags Wi-Fi Range Extender Vulnerability Under Active Attack Read More »

WhatsApp Zero-Day Exploited in Attacks Targeting Apple Users

WhatsApp Zero-Day Exploited in Attacks Targeting Apple Users 2025-09-02 at 14:48 By Ionut Arghire The vulnerability (CVE-2025-55177) was exploited along an iOS/macOS zero-day in suspected spyware attacks. The post WhatsApp Zero-Day Exploited in Attacks Targeting Apple Users appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WhatsApp Zero-Day Exploited in Attacks Targeting Apple Users Read More »

Ransomware Group Exploits Hybrid Cloud Gaps, Gains Full Azure Control in Enterprise Attacks

Ransomware Group Exploits Hybrid Cloud Gaps, Gains Full Azure Control in Enterprise Attacks 2025-08-29 at 16:25 By Ionut Arghire Storm-0501 has been leveraging cloud-native capabilities for data exfiltration and deletion, without deploying file-encrypting malware. The post Ransomware Group Exploits Hybrid Cloud Gaps, Gains Full Azure Control in Enterprise Attacks appeared first on SecurityWeek. This article

Ransomware Group Exploits Hybrid Cloud Gaps, Gains Full Azure Control in Enterprise Attacks Read More »

China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years

China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years 2025-08-28 at 17:21 By Ionut Arghire China-linked APT ‘Salt Typhoon’ exploited known router flaws to maintain persistent access across telecom, government, and military networks, giving Beijing’s intelligence services global surveillance reach. The post China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years appeared first on SecurityWeek.

China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years Read More »

Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack

Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack 2025-08-28 at 13:55 By Ionut Arghire With more than 4 million weekly downloads, the Nx build platform became the first known supply chain breach where hackers weaponized AI assistants for data theft. The post Hackers Target Popular Nx Build System in First AI-Weaponized

Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack Read More »

PromptLock: First AI-Powered Ransomware Emerges

PromptLock: First AI-Powered Ransomware Emerges 2025-08-27 at 14:51 By Ionut Arghire Proof-of-concept ransomware uses AI models to generate attack scripts in real time. The post PromptLock: First AI-Powered Ransomware Emerges appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PromptLock: First AI-Powered Ransomware Emerges Read More »

OneFlip: An Emerging Threat to AI that Could Make Vehicles Crash and Facial Recognition Fail

OneFlip: An Emerging Threat to AI that Could Make Vehicles Crash and Facial Recognition Fail 2025-08-25 at 20:17 By Kevin Townsend Researchers unveil OneFlip, a Rowhammer-based attack that flips a single bit in neural network weights to stealthily backdoor AI systems without degrading performance. The post OneFlip: An Emerging Threat to AI that Could Make

OneFlip: An Emerging Threat to AI that Could Make Vehicles Crash and Facial Recognition Fail Read More »

Farmers Insurance Data Breach Impacts Over 1 Million People

Farmers Insurance Data Breach Impacts Over 1 Million People 2025-08-25 at 09:35 By Eduard Kovacs Farmers New World Life Insurance and Farmers Group have filed separate data breach notifications with state authorities.  The post Farmers Insurance Data Breach Impacts Over 1 Million People appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Farmers Insurance Data Breach Impacts Over 1 Million People Read More »

Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects

Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects 2025-08-22 at 19:04 By Associated Press Dubbed Operation Serengeti 2.0, the operation took place between June and August. The post Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects appeared first on SecurityWeek. This article is

Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects Read More »

GPT-5 Has a Vulnerability: Its Router Can Send You to Older, Less Safe Models

GPT-5 Has a Vulnerability: Its Router Can Send You to Older, Less Safe Models 2025-08-20 at 17:52 By Kevin Townsend Instead of GPT-5 Pro, your query could be quietly redirected to an older, weaker model, opening the door to jailbreaks, hallucinations, and unsafe outputs. The post GPT-5 Has a Vulnerability: Its Router Can Send You

GPT-5 Has a Vulnerability: Its Router Can Send You to Older, Less Safe Models Read More »

Scroll to Top