Security Week
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
The company disconnected its systems on July 13 and is starting to gradually restore operations.
The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek.
Risk Ledger Raises $32 Million in Series B Funding
The British firm has built a collaborative platform to help organizations address supply chain security risks.
The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek.
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.
The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
The company says the incident has not affected product quality and safety, nor Fairlife’s Canada production.
The post Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack appeared first on SecurityWeek.
Legacy Systems, Real-World Impacts: The Reality of OT Security
Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts.
The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek.
Two Scattered Spider Hackers Sentenced to Jail in UK
Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL).
The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek.
AI Data Centers Are Being Built Faster Than They Can Be Secured
AI infrastructure introduces new security risks that traditional data center designs were never built to handle.
The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek.
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek.
Oak Emerges From Stealth Mode With $60 Million in Funding
The startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment.
The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek.
Splunk, Zoom Patch Critical Vulnerabilities
The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges.
The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek.
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek.
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.
The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek.
Old UEFI Shims Expose Systems to Secure Boot Bypass
Signed by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS.
The post Old UEFI Shims Expose Systems to Secure Boot Bypass appeared first on SecurityWeek.
Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability.
The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek.
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek.
Unpatched Cursor Vulnerability Exposes Users to Code Execution
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically.
The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.
The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek.
Windows Bind Link Attacks Can Hide Malware From EDR Tools
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.
The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek.
Virtual Event Today: Cloud & Data Security Summit
Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.
The post Virtual Event Today: Cloud & Data Security Summit appeared first on SecurityWeek.
US Charges Russian Individuals and Firms for Running Cybercrime Services
The suspects and their companies were previously sanctioned by the United States and its allies.
The post US Charges Russian Individuals and Firms for Running Cybercrime Services appeared first on SecurityWeek.
