Latest Cybersecurity News and Articles


New Reports Uncover Jailbreaks, Unsafe Code, and Data Theft Risks in Leading AI Systems

29 April 2025
Various generative artificial intelligence (GenAI) services have been found vulnerable to two types of jailbreak attacks that make it possible to produce illicit or dangerous content. The first of the two techniques, codenamed Inception, instructs an AI tool to imagine a fictitious scenario, which can then be adapted into a second scenario within the first one where there exists no safety

How do You Know if You’re Ready for a Red Team Partnership?

29 April 2025
Before engaging in a full-scope exercise, it’s important to assess whether your program, people and processes are truly ready.  The post How do You Know if You’re Ready for a Red Team Partnership? appeared first on SecurityWeek.

Commvault Command Center has a critical security flaw

29 April 2025
Commvault Command Center has a critical security flaw. Security leaders discuss. 

SentinelOne’s Purple AI Athena Brings Autonomous Decision-Making to the SOC

29 April 2025
Athena marks a major leap in SOC automation, enabling real-time detection, triage, and remediation with minimal human oversight. The post SentinelOne’s Purple AI Athena Brings Autonomous Decision-Making to the SOC appeared first on SecurityWeek.

Security leaders share thoughts on Blue Shield of California data breach

29 April 2025
Blue Shield of California has notified members of a data breach that may have impacted protected health information.

China’s Secret Weapon? How EV Batteries Could be Weaponized to Disrupt America

29 April 2025
As Xi Jinping advances his vision for China’s dominance by 2049, cybersecurity experts warn that connected technologies—like EV batteries—may quietly serve as tools of influence, espionage, and disruption. The post China’s Secret Weapon? How EV Batteries Could be Weaponized to Disrupt America appeared first on SecurityWeek.

SentinelOne Uncovers Chinese Espionage Campaign Targeting Its Infrastructure and Clients

29 April 2025
Cybersecurity company SentinelOne has revealed that a China-nexus threat cluster dubbed PurpleHaze conducted reconnaissance attempts against its infrastructure and some of its high-value customers. "We first became aware of this threat cluster during a 2024 intrusion conducted against an organization previously providing hardware logistics services for SentinelOne employees," security

Pistachio Raises $7 Million for Cybersecurity Training Platform

29 April 2025
Cybersecurity awareness training platform Pistachio has raised $7 million in a Series A funding round led by Walter Ventures. The post Pistachio Raises $7 Million for Cybersecurity Training Platform appeared first on SecurityWeek.

LayerX Raises $11 Million for Browser Security Solution

29 April 2025
Browser security firm LayerX has raised $11 million in a Series A funding round extension led by Jump Capital. The post LayerX Raises $11 Million for Browser Security Solution appeared first on SecurityWeek.

Cybersecurity Firms Raise Over $1.7 Billion Ahead of RSA Conference 2025

29 April 2025
More than 30 companies announced a total of $1.7 billion in funding in weeks leading up to the industry’s largest gathering. The post Cybersecurity Firms Raise Over $1.7 Billion Ahead of RSA Conference 2025 appeared first on SecurityWeek.

AI-powered, automated attacks have reached record numbers

29 April 2025
Research finds AI-powered, automated attacks have reached record numbers. 

Google Tracked 75 Zero-Days in 2024

29 April 2025
The number of exploited zero-days seen by Google in 2024 dropped to 75, from 98 observed in the previous year. The post Google Tracked 75 Zero-Days in 2024 appeared first on SecurityWeek.

Product Walkthrough: Securing Microsoft Copilot with Reco

29 April 2025
Find out how Reco keeps Microsoft 365 Copilot safe by spotting risky prompts, protecting data, managing user access, and identifying threats - all while keeping productivity high. Microsoft 365 Copilot promises to boost productivity by turning natural language prompts into actions. Employees can generate reports, comb through data, or get instant answers just by asking Copilot.  However,

RSA Conference 2025 Announcements Summary (Day 1) 

29 April 2025
Hundreds of companies are showcasing their products and services this week at the 2025 edition of the RSA Conference in San Francisco. The post RSA Conference 2025 Announcements Summary (Day 1)  appeared first on SecurityWeek.

Exploited Vulnerability Exposes Over 400 SAP NetWeaver Servers to Attacks

29 April 2025
More than 400 SAP NetWeaver servers are impacted by CVE-2025-31324, an exploited remote code execution vulnerability. The post Exploited Vulnerability Exposes Over 400 SAP NetWeaver Servers to Attacks appeared first on SecurityWeek.

Google Reports 75 Zero-Days Exploited in 2024 — 44% Targeted Enterprise Security Products

29 April 2025
Google has revealed that it observed 75 zero-day vulnerabilities exploited in the wild in 2024, down from 98 in 2023.  Of the 75 zero-days, 44% of them targeted enterprise products. As many as 20 flaws were identified in security software and appliances. "Zero-day exploitation of browsers and mobile devices fell drastically, decreasing by about a third for browsers and by about half for

CISA Warns of Exploited Broadcom, Commvault Vulnerabilities

29 April 2025
CISA urges immediate patching for recently disclosed Broadcom, Commvault, and Qualitia vulnerabilities exploited in the wild. The post CISA Warns of Exploited Broadcom, Commvault Vulnerabilities appeared first on SecurityWeek.

Malware Attack Targets World Uyghur Congress Leaders via Trojanized UyghurEdit++ Tool

29 April 2025
In a new campaign detected in March 2025, senior members of the World Uyghur Congress (WUC) living in exile have been targeted by a Windows-based malware that's capable of conducting surveillance. The spear-phishing campaign involved the use of a trojanized version of a legitimate open-source word processing and spell check tool called UyghurEdit++ developed to support the use of the Uyghur

‘Source of data’: are electric cars vulnerable to cyber spies and hackers?

29 April 2025
‘Source of data’: are electric cars vulnerable to cyber spies and hackers? British defence firms have reportedly warned staff not to connect their phones to Chinese-made EVsMobile phones and desktop computers are longstanding targets for cyber spies – but how vulnerable are electric cars?On Monday the i newspaper claimed that British defence firms working for the UK government have warned staff against connecting or pairing their phones with Chinese-made electric cars, due to fears that Beijing could extract sensitive data from the devices. Continue reading...

CISA Adds Actively Exploited Broadcom and Commvault Flaws to KEV Database

29 April 2025
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added two high-severity security flaws impacting Broadcom Brocade Fabric OS and Commvault Web Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerabilities in question are listed below - CVE-2025-1976 (CVSS score: 8.6) - A code injection flaw