SecurityWeek

Marks & Spencer Expects Ransomware Attack to Cost $400 Million

Security Week - Thu, 05/22/2025 - 7:21am

UK retailer Marks & Spencer expects the disruptions caused by the recent cyberattack to continue through July. 

The post Marks & Spencer Expects Ransomware Attack to Cost $400 Million appeared first on SecurityWeek.

Categories: SecurityWeek

Security Theater or Real Defense? The KPIs That Tell the Truth

Security Week - Thu, 05/22/2025 - 6:00am

In the end, cybersecurity isn’t just about collecting data. It’s about proving that your defenses actually work.

The post Security Theater or Real Defense? The KPIs That Tell the Truth appeared first on SecurityWeek.

Categories: SecurityWeek

Taming the Hacker Storm: Why Millions in Cybersecurity Spending Isn’t Enough

Security Week - Thu, 05/22/2025 - 6:00am

Despite massive investment, the explosion of sophisticated malware and deepfake attacks persists because organizations struggle to verify digital identities and establish fundamental trust.

The post Taming the Hacker Storm: Why Millions in Cybersecurity Spending Isn’t Enough appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Patches High-Severity DoS, Privilege Escalation Vulnerabilities

Security Week - Thu, 05/22/2025 - 4:39am

Cisco published 10 security advisories detailing over a dozen vulnerabilities, including two high-severity flaws in its Identity Services Engine (ISE) and Unified Intelligence Center.

The post Cisco Patches High-Severity DoS, Privilege Escalation Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

GitLab, Atlassian Patch High-Severity Vulnerabilities

Security Week - Thu, 05/22/2025 - 1:05am

GitLab and Atlassian have released patches for over a dozen vulnerabilities in their products, including high-severity bugs.

The post GitLab, Atlassian Patch High-Severity Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

CISA Says Russian Hackers Targeting Western Supply-Lines to Ukraine

Security Week - Wed, 05/21/2025 - 4:47pm

Russian military intelligence hackers intensify targeting of Western logistics and technology companies moving supplies into Ukraine. 

The post CISA Says Russian Hackers Targeting Western Supply-Lines to Ukraine appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft Sinkholes Domains, Disrupts Notorious ‘Lumma Stealer’ Malware Operation

Security Week - Wed, 05/21/2025 - 2:21pm

Redmond’s threat hunters found 394,000 Windows systems talking to Lumma controllers, a victim pool included global manufacturers. 

The post Microsoft Sinkholes Domains, Disrupts Notorious ‘Lumma Stealer’ Malware Operation appeared first on SecurityWeek.

Categories: SecurityWeek

Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway

Security Week - Wed, 05/21/2025 - 11:37am

More than 100 AutomationDirect MB-Gateway devices may be vulnerable to attacks from the internet due to CVE-2025-36535.

The post Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway appeared first on SecurityWeek.

Categories: SecurityWeek

Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users

Security Week - Wed, 05/21/2025 - 9:45am

A mandatory filing to the Maine Attorney General says 69,461 customers nationwide were affected and dates the breach back to last December.

The post Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users appeared first on SecurityWeek.

Categories: SecurityWeek

US Student to Plead Guilty Over PowerSchool Hack

Security Week - Wed, 05/21/2025 - 6:54am

Matthew Lane allegedly hacked PowerSchool using stolen credentials and admitted to extorting a telecoms provider.

The post US Student to Plead Guilty Over PowerSchool Hack appeared first on SecurityWeek.

Categories: SecurityWeek

Cellcom Service Disruption Caused by Cyberattack

Security Week - Wed, 05/21/2025 - 6:01am

Wireless carrier Cellcom has confirmed that a week-long widespread service outage is the result of a cyberattack.

The post Cellcom Service Disruption Caused by Cyberattack appeared first on SecurityWeek.

Categories: SecurityWeek

Google DeepMind Unveils Defense Against Indirect Prompt Injection Attacks

Security Week - Wed, 05/21/2025 - 5:58am

Google DeepMind has developed an ongoing process to counter the continuously evolving threatIndirect prompt injection (IPI) attacks.

The post Google DeepMind Unveils Defense Against Indirect Prompt Injection Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Wiz Warns of Ongoing Exploitation of Recent Ivanti Vulnerabilities

Security Week - Wed, 05/21/2025 - 5:49am

Wiz warns that threat actors are chaining two recent Ivanti vulnerabilities to achieve unauthenticated remote code execution.

The post Wiz Warns of Ongoing Exploitation of Recent Ivanti Vulnerabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit

Security Week - Wed, 05/21/2025 - 5:41am

SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st.

The post Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit appeared first on SecurityWeek.

Categories: SecurityWeek

Up to 25% of Internet-Exposed ICS Are Honeypots: Researchers

Security Week - Wed, 05/21/2025 - 5:35am

Many of the industrial control system (ICS) instances seen in internet scanning are likely or possibly honeypots, not real devices.

The post Up to 25% of Internet-Exposed ICS Are Honeypots: Researchers appeared first on SecurityWeek.

Categories: SecurityWeek

Ransomware Attack Forces Kettering Health to Cancel Procedures

Security Week - Wed, 05/21/2025 - 4:38am

Kettering Health has canceled inpatient and outpatient procedures as it deals with a system-wide outage caused by a ransomware attack.

The post Ransomware Attack Forces Kettering Health to Cancel Procedures appeared first on SecurityWeek.

Categories: SecurityWeek

Critical OpenPGP.js Vulnerability Allows Spoofing

Security Week - Wed, 05/21/2025 - 3:15am

An OpenPGP.js vulnerability tracked as CVE-2025-47934 allows message signature verification to be spoofed. 

The post Critical OpenPGP.js Vulnerability Allows Spoofing appeared first on SecurityWeek.

Categories: SecurityWeek

NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch

Security Week - Tue, 05/20/2025 - 9:57am

VMware patches flaws that expose users to data leakage, command execution and denial-of-service attacks. No temporary workarounds available. 

The post NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerability Exploitation Probability Metric Proposed by NIST, CISA Researchers 

Security Week - Tue, 05/20/2025 - 8:37am

The Likely Exploited Vulnerabilities (LEV) equations can help augment KEV- and EPSS-based remediation prioritization. 

The post Vulnerability Exploitation Probability Metric Proposed by NIST, CISA Researchers  appeared first on SecurityWeek.

Categories: SecurityWeek

Event Preview: 2025 Threat Detection & Incident Response (Virtual) Summit

Security Week - Tue, 05/20/2025 - 8:30am

SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st.

The post Event Preview: 2025 Threat Detection & Incident Response (Virtual) Summit appeared first on SecurityWeek.

Categories: SecurityWeek

Pages