Latest Cybersecurity News and Articles


JPMorgan Chase & Co. CISO writes open letter to third-party suppliers

02 May 2025
Patrick Opet, CISO at JPMorgan Chase & Co., writes open letter to third-party suppliers. 

xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs

01 May 2025
A employee at Elon Musk's artificial intelligence company xAI leaked a private key on GitHub that for the past two months could have allowed anyone to query private xAI large language models (LLMs) which appear to have been custom made for working with internal data from Musk's companies, including SpaceX, Tesla and Twitter/X, KrebsOnSecurity has learned.

NCSC statement: Incident impacting retailers

01 May 2025
The latest statement from the NCSC regarding the cyber incident impacting UK retailers

More than 500,000 records exposed in ticket reseller breach

01 May 2025
520,054 records were exposed in ticket reseller breach. 

Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers

01 May 2025
Cybersecurity researchers have shed light on a new campaign targeting WordPress sites that disguises the malware as a security plugin. The plugin, which goes by the name "WP-antymalwary-bot.php," comes with a variety of features to maintain access, hide itself from the admin dashboard, and execute remote code. "Pinging functionality that can report back to a command-and-control (C&C) server

61% of organizations not prepared to address critical risks

01 May 2025
The Global Risk Survey from AlixPartners found that 61% or more organizations are not sufficiently prepared to address critical risks.

Canadian Electric Utility Hit by Cyberattack

01 May 2025
Nova Scotia Power and Emera are responding to a cybersecurity incident that impacted IT systems and networks.  The post Canadian Electric Utility Hit by Cyberattack appeared first on SecurityWeek.

Year of the Twin Dragons: Developers Must Slay the Complexity and Security Issues of AI Coding Tools

01 May 2025
The advantages AI tools deliver in speed and efficiency are impossible for developers to resist. But the complexity and risk created by AI-generated code can’t be ignored. The post Year of the Twin Dragons: Developers Must Slay the Complexity and Security Issues of AI Coding Tools appeared first on SecurityWeek.

89% of security teams have already begun to implement AI

01 May 2025
A recent Cymulate report found that 71% of those surveyed consider threat exposure validation to be “absolutely essential.” 

Commvault Shares IoCs After Zero-Day Attack Hits Azure Environment

01 May 2025
Commvault provides indicators of compromise and mitigation guidance after a zero-day exploit targeting its Azure environment lands in CISA’s KEV catalog. The post Commvault Shares IoCs After Zero-Day Attack Hits Azure Environment appeared first on SecurityWeek.

Why top SOC teams are shifting to Network Detection and Response

01 May 2025
Security Operations Center (SOC) teams are facing a fundamentally new challenge — traditional cybersecurity tools are failing to detect advanced adversaries who have become experts at evading endpoint-based defenses and signature-based detection systems. The reality of these “invisible intruders” is driving a significant need for a multi-layered approach to detecting threats,

Chinese APT’s Adversary-in-the-Middle Tool Dissected

01 May 2025
ESET has analyzed Spellbinder, the IPv6 SLAAC spoofing tool Chinese APT TheWizards uses to deploy its WizardNet backdoor. The post Chinese APT’s Adversary-in-the-Middle Tool Dissected appeared first on SecurityWeek.

Claude AI Exploited to Operate 100+ Fake Political Personas in Global Influence Campaign

01 May 2025
Artificial intelligence (AI) company Anthropic has revealed that unknown threat actors leveraged its Claude chatbot for an "influence-as-a-service" operation to engage with authentic accounts across Facebook and X. The sophisticated activity, branded as financially-motivated, is said to have used its AI tool to orchestrate 100 distinct persons on the two social media platforms, creating a

Actions Over Words: Career Lessons for the Security Professional

01 May 2025
In a world full of noise and promises, it’s those who consistently deliver behind the scenes who build the most respected and rewarding careers. The post Actions Over Words: Career Lessons for the Security Professional appeared first on SecurityWeek.

SonicWall Flags Two More Vulnerabilities as Exploited

01 May 2025
SonicWall has updated the advisories for two vulnerabilities to warn that they are being exploited in the wild. The post SonicWall Flags Two More Vulnerabilities as Exploited appeared first on SecurityWeek.

New Research Reveals: 95% of AppSec Fixes Don’t Reduce Risk

01 May 2025
For over a decade, application security teams have faced a brutal irony: the more advanced the detection tools became, the less useful their results proved to be. As alerts from static analysis tools, scanners, and CVE databases surged, the promise of better security grew more distant. In its place, a new reality took hold—one defined by alert fatigue and overwhelmed teams. According to OX

DarkWatchman, Sheriff Malware Hit Russia and Ukraine with Stealth and Nation-Grade Tactics

01 May 2025
Russian companies have been targeted as part of a large-scale phishing campaign that's designed to deliver a known malware called DarkWatchman. Targets of the attacks include entities in the media, tourism, finance and insurance, manufacturing, retail, energy, telecom, transport, and biotechnology sectors, Russian cybersecurity company F6 said. The activity is assessed to be the work of a

Ascension Discloses Data Breach Potentially Linked to Cleo Hack

01 May 2025
Ascension is notifying over 100,000 people that their personal information was stolen in a data breach potentially linked to the Cleo hack. The post Ascension Discloses Data Breach Potentially Linked to Cleo Hack appeared first on SecurityWeek.

SentinelOne Targeted by North Korean IT Workers, Ransomware Groups, Chinese Hackers

01 May 2025
SentinelOne has shared some information on the types of threat actors that have targeted the security firm recently. The post SentinelOne Targeted by North Korean IT Workers, Ransomware Groups, Chinese Hackers appeared first on SecurityWeek.

Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach

01 May 2025
Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no evidence of unauthorized data access. "This activity has affected a small number of customers we have in common with Microsoft, and we are working with those customers to provide assistance," the company