Channel

Cyber Events

Conference, briefing, training, hearing, and industry-event coverage that tracks where security leaders, researchers, regulators, and vendors are gathering.

Cyber Events
Cyber Events

Iran uses commercial data to track US military, new macOS espionage software, CVD blueprint released — Analysis of key cybersecurity events this week

This week's security incidents cover Iran's use of ad metadata and cellular roaming protocols to track US military phones, a new CrashStealer macOS malware disguised as crash reports to steal information, and the release of a Coordinated Vulnerability Disclosure (CVD) blueprint by CISA and other agencies. These events respectively reveal mobile geographic tracking risks, new information theft techniques on the macOS platform, and progress in standardizing enterprise vulnerability disclosure.

Benjamin Clarke6 min read
Cyber Events

Weekly Cybersecurity News: DHS database breached, Adobe accelerates patch updates, Canada disrupts ransomware operations

Summary of Important Cybersecurity Events This Week: U.S. Department of Homeland Security's HSIN database hacked; Adobe announces twice-monthly security updates; Canadian Communications Security Agency proactively disrupts ransomware infrastructure; QuimaRAT cross-platform trojan sold on the dark web; Abnormal AI refutes Anthropic's trademark infringement allegations; AssuranceAmerica data breach affects 7 million people; NSA relaunches TAO elite hacker unit; FBI warns of TeamPCP supply chain attack.

Amira Al-Fahad5 min read
Cyber Events

Open source software supply chain security sounds the alarm again: researchers disclose dozens of zero-day vulnerabilities in batches.

A researcher going by the alias Bikini has published PoC code on GitHub for dozens of zero-day vulnerabilities in multiple open-source projects, including FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, OpenVPN, and VLC, with nine of them having received CVE IDs. This has sparked renewed concerns among enterprises about the security of open-source software supply chains.

Benjamin Clarke2 min read
Cyber Events

Tata Electronics supply chain leak and AI-driven threat acceleration: In-depth analysis of this week's global cybersecurity situation

This week, Tata Electronics suffered a major data breach, with 630GB of confidential files exposed, involving the supply chains of Apple and Tesla. Meanwhile, the Five Eyes issued an AI threat warning, China's 360 launched a Mythos-like AI attack system, and Snyk underwent layoffs and restructuring. This article provides an in-depth analysis of the incident's impact, attack methods, and defense strategies from a corporate security perspective.

Sarah Jenkins5 min read
Cyber Events

This week's security brief: Apple fixes Beats eavesdropping vulnerability, DOT concludes Delta investigation, AWS releases Continuum

Apple releases Beats firmware update to fix unauthorized microphone access vulnerability; U.S. Department of Transportation concludes investigation into Delta Air Lines' service disruption caused by CrowdStrike incident; AWS launches AI-driven vulnerability management tool Continuum. Meanwhile, the Popa botnet is linked to an Israeli company, and Google Cloud Config Connector has an unpatched privilege escalation vulnerability.

Marcus Thorne5 min read
Cyber Events

Coupang Fined a Record $400 Million: Data Governance Failures as a Warning for Enterprise Security

South Korea's Personal Information Protection Commission has imposed a $400 million fine on e-commerce giant Coupang for a security breach that resulted in the leak of data from over 30 million customers. This penalty highlights severe deficiencies in access control and key management, serving as a wake-up call for global enterprise data governance.

Elena Richter4 min read
Cyber Events

NCSC calls on businesses to immediately strengthen cyber resilience: in an era of uncertainty, security operations must come before “certainty”

The UK National Cyber Security Centre (NCSC) emphasized at Infosecurity Europe that, in the face of geopolitical uncertainty, AI-driven technological change, and an increasingly complex enterprise IT environment, organizations cannot wait for “clearer signals” before acting; they should immediately strengthen cyber resilience, identity security, and incident response readiness.

Marcus Thorne7 min read
Cyber Events

Threat Detection and Incident Response Summit Signals a Shift Toward AI-Enabled Security Operations

SecurityWeek has made all sessions of its Threat Detection & Incident Response Summit available on demand, with topics focused on alert fatigue, AI-driven detection, identity protection, cloud visibility, and incident response. For enterprises, this is not just an industry event; it also reflects how security operations are shifting from “single-point tools” to an “intelligent, interconnected, and verifiable response system.”

Benjamin Clarke6 min read