SecurityWeek

The Root of AI Hallucinations: Physics Theory Digs Into the ‘Attention’ Flaw

Security Week - Wed, 05/28/2025 - 5:51am

Physicist Neil Johnson explores how fundamental laws of nature could explain why AI sometimes fails—and what to do about it.

The post The Root of AI Hallucinations: Physics Theory Digs Into the ‘Attention’ Flaw appeared first on SecurityWeek.

Categories: SecurityWeek

$223 Million Stolen in Cetus Protocol Hack

Security Week - Wed, 05/28/2025 - 5:23am

Hackers exploited a vulnerability in Cetus Protocol, a liquidity provider on the SUI blockchain.

The post $223 Million Stolen in Cetus Protocol Hack appeared first on SecurityWeek.

Categories: SecurityWeek

Zscaler to Acquire MDR Specialist Red Canary

Security Week - Tue, 05/27/2025 - 5:31pm

Zscaler signals a big push into the security-operations market with the announcement of plans to buy Denver-based Red Canary.

The post Zscaler to Acquire MDR Specialist Red Canary appeared first on SecurityWeek.

Categories: SecurityWeek

Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack

Security Week - Tue, 05/27/2025 - 2:27pm

Sina Gholinejad pleaded guilty to computer-fraud and wire-fraud-conspiracy charges linked to the Robbinhood ransomware hit on Baltimore.

The post Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack appeared first on SecurityWeek.

Categories: SecurityWeek

DragonForce Ransomware Hackers Exploiting SimpleHelp Vulnerabilities

Security Week - Tue, 05/27/2025 - 11:06am

Sophos warns that a DragonForce ransomware operator chained three vulnerabilities in SimpleHelp to target a managed service provider.

The post DragonForce Ransomware Hackers Exploiting SimpleHelp Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Russian Government Hackers Caught Buying Passwords from Cybercriminals

Security Week - Tue, 05/27/2025 - 10:52am

Microsoft flags a new Kremlin hacking team buying stolen usernames and passwords from infostealer markets for use in cyberespionage attacks. 

The post Russian Government Hackers Caught Buying Passwords from Cybercriminals appeared first on SecurityWeek.

Categories: SecurityWeek

Ongoing Campaign Uses 60 NPM Packages to Steal Data

Security Week - Tue, 05/27/2025 - 10:12am

Security firm Socket warns flags a campaign targeting NPM users with tens of malicious packages that can hijack system information.

The post Ongoing Campaign Uses 60 NPM Packages to Steal Data appeared first on SecurityWeek.

Categories: SecurityWeek

Dutch Intelligence Agencies Say Russian Hackers Stole Police Data in Cyberattack

Security Week - Tue, 05/27/2025 - 9:44am

The agencies said that the group, which they called Laundry Bear, is actively trying to steal sensitive data from EU and NATO countries and is “extremely likely Russian state supported.”

The post Dutch Intelligence Agencies Say Russian Hackers Stole Police Data in Cyberattack appeared first on SecurityWeek.

Categories: SecurityWeek

Inside the $111 Billion Cloud Security Market: Acquisition, Expansion, and Where to Aim Next

Security Week - Tue, 05/27/2025 - 8:57am

As cloud security spending surges to $111 billion, new data highlights Microsoft's dominance, the U.S. market's outsized role, and Google's strategic acquisition of Wiz.

The post Inside the $111 Billion Cloud Security Market: Acquisition, Expansion, and Where to Aim Next appeared first on SecurityWeek.

Categories: SecurityWeek

Law Firms Warned of Silent Ransom Group Attacks

Security Week - Tue, 05/27/2025 - 5:59am

The FBI warns US law firms that the Silent Ransom Group (SRG) has been constantly targeting the legal industry.

The post Law Firms Warned of Silent Ransom Group Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Nova Scotia Power Confirms Ransomware Attack, 280k Notified of Data Breach

Security Week - Mon, 05/26/2025 - 2:43am

Nova Scotia Power has finally admitted that the recent cyberattack was a ransomware attack, but it hasn’t paid the hackers.

The post Nova Scotia Power Confirms Ransomware Attack, 280k Notified of Data Breach appeared first on SecurityWeek.

Categories: SecurityWeek

Signal Adds Screenshot-Blocker to Thwart ‘Windows Recall’ 

Security Week - Fri, 05/23/2025 - 10:13am

Signal said the privacy feature is on by default for every Windows 11 user to block Microsoft from taking screenshots for Windows Recall.

The post Signal Adds Screenshot-Blocker to Thwart ‘Windows Recall’  appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Volkswagen App Hacked, DR32 Sentenced, New OT Security Solution

Security Week - Fri, 05/23/2025 - 9:41am

Noteworthy stories that might have slipped under the radar: serious vulnerabilities found in a Volkswagen app, Australian hacker DR32 sentenced in the US, and Immersive launches OT security training solution.

The post In Other News: Volkswagen App Hacked, DR32 Sentenced, New OT Security Solution appeared first on SecurityWeek.

Categories: SecurityWeek

Russian Qakbot Gang Leader Indicted in US

Security Week - Fri, 05/23/2025 - 7:07am

Russian national Rustam Gallyamov was indicted in the US for his leading role in the development and distribution of Qakbot malware.

The post Russian Qakbot Gang Leader Indicted in US appeared first on SecurityWeek.

Categories: SecurityWeek

Companies Warned of Commvault Vulnerability Exploitation

Security Week - Fri, 05/23/2025 - 6:31am

CISA warns companies of a widespread campaign targeting a Commvault vulnerability to hack Azure environments.

The post Companies Warned of Commvault Vulnerability Exploitation appeared first on SecurityWeek.

Categories: SecurityWeek

Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks

Security Week - Fri, 05/23/2025 - 5:30am

A Chinese threat actor exploited a zero-day vulnerability in Trimble Cityworks to hack local government entities in the US.

The post Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

DanaBot Botnet Disrupted, 16 Suspects Charged

Security Week - Fri, 05/23/2025 - 4:58am

The DanaBot botnet ensnared over 300,000 devices and caused more than $50 million in damages before being disrupted.

The post DanaBot Botnet Disrupted, 16 Suspects Charged appeared first on SecurityWeek.

Categories: SecurityWeek

Chinese Spies Exploit Ivanti Vulnerabilities Against Critical Sectors

Security Week - Fri, 05/23/2025 - 4:19am

A Chinese espionage group has been chaining two recent Ivanti EPMM vulnerabilities in attacks against organizations in multiple critical sectors.

The post Chinese Spies Exploit Ivanti Vulnerabilities Against Critical Sectors appeared first on SecurityWeek.

Categories: SecurityWeek

Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw

Security Week - Thu, 05/22/2025 - 12:55pm

Akamai documents a privilege escalation flaw in Windows Server 2025 after Redmond declines to ship an immediate patch.

The post Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw appeared first on SecurityWeek.

Categories: SecurityWeek

Marlboro-Chesterfield Pathology Data Breach Impacts 235,000 People

Security Week - Thu, 05/22/2025 - 8:03am

Marlboro-Chesterfield Pathology has been targeted by the SafePay ransomware group, which stole personal information from its systems.

The post Marlboro-Chesterfield Pathology Data Breach Impacts 235,000 People appeared first on SecurityWeek.

Categories: SecurityWeek

Pages