Latest Cybersecurity News and Articles


Vulnerability discovered in Subaru’s connected vehicle service

31 January 2025
Subaru’s STARLINK connected vehicle service contains a vulnerability that permits access to user accounts and vehicles. 

CISA, FDA Warn of Dangerous Backdoor in Contec Patient Monitors

31 January 2025
CISA and FDA say Contec patient monitors used in the US contain a backdoor function that could allow remote attackers to tamper with the device. The post CISA, FDA Warn of Dangerous Backdoor in Contec Patient Monitors appeared first on SecurityWeek.

ChatGPT, DeepSeek Vulnerable to AI Jailbreaks

31 January 2025
Different research teams have demonstrated jailbreaks against ChatGPT, DeepSeek, and Alibaba’s Qwen AI models.  The post ChatGPT, DeepSeek Vulnerable to AI Jailbreaks appeared first on SecurityWeek.

Top 5 AI-Powered Social Engineering Attacks

31 January 2025
Social engineering has long been an effective tactic because of how it focuses on human vulnerabilities. There’s no brute-force ‘spray and pray’ password guessing. No scouring systems for unpatched software. Instead, it simply relies on manipulating emotions such as trust, fear, and respect for authority, usually with the goal of gaining access to sensitive information or protected systems.

Italy Bans Chinese DeepSeek AI Over Data Privacy and Ethical Concerns

31 January 2025
Italy's data protection watchdog has blocked Chinese artificial intelligence (AI) firm DeepSeek's service within the country, citing a lack of information on its use of users' personal data. The development comes days after the authority, the Garante, sent a series of questions to DeepSeek, asking about its data handling practices and where it obtained its training data. In particular, it wanted

Google Bans 158,000 Malicious Android App Developer Accounts in 2024

31 January 2025
Google said it blocked over 2.36 million policy-violating Android apps from being published to the Google Play app marketplace in 2024 and banned more than 158,000 bad developer accounts that attempted to publish such harmful apps. The tech giant also noted it prevented 1.3 million apps from getting excessive or unnecessary access to sensitive user data during the time period by working with

NorthBay Health Data Breach Impacts 569,000 Individuals

31 January 2025
NorthBay Health says hackers stole the personal information of 569,000 individuals in a 2024 ransomware attack. The post NorthBay Health Data Breach Impacts 569,000 Individuals appeared first on SecurityWeek.

Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft

31 January 2025
Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain elevated access or obtain sensitive information. The list of identified flaws, which impact versions 8.x of the software, is below - CVE-2025-22218 (CVSS score: 8.5) - A malicious actor with View Only Admin

Clutch Security Raises $20 Million for Non-Human Identity Protection Platform

31 January 2025
Clutch Security has raised $20 million in a Series A funding round led by SignalFire to secure non-human identities. The post Clutch Security Raises $20 Million for Non-Human Identity Protection Platform appeared first on SecurityWeek.

Trump Administration Faces Security Balancing Act in Borderless Cyber Landscape

30 January 2025
What challenges will the new administration face and what might President Trump’s record on cybersecurity indicate about the likely approach in 2025 and beyond? The post Trump Administration Faces Security Balancing Act in Borderless Cyber Landscape appeared first on SecurityWeek.

Justice Department Sues to Block $14 Billion Juniper Buyout by Hewlett Packard Enterprise

30 January 2025
The lawsuit said that the combination of businesses would eliminate competition, raise prices and reduce innovation. The post Justice Department Sues to Block $14 Billion Juniper Buyout by Hewlett Packard Enterprise appeared first on SecurityWeek.

VMware Patches High-Risk Flaws in Oft-Targeted Aria Operations Products

30 January 2025
VMWare calls attention to patches for multiple 'high-risk' security defects in its Aria Operations and Aria Operations for Logs products. The post VMware Patches High-Risk Flaws in Oft-Targeted Aria Operations Products appeared first on SecurityWeek.

Conifers.ai Scores $25M Investment for Agentic AI SOC Technology

30 January 2025
Backed by SYN Ventures, Conifers.ai plans to use “agentic AI” technology to tackle complex security operations center (SOC) problems. The post Conifers.ai Scores $25M Investment for Agentic AI SOC Technology appeared first on SecurityWeek.

Taming Shadow AI: Valence Security, Endor Labs Unveil New Protections to Counter Hidden AI Threats

30 January 2025
Valence Security and Endor Labs have introduced extensions to their existing platforms specifically to tackle the invisibility and wrongful use of Shadow AI. The post Taming Shadow AI: Valence Security, Endor Labs Unveil New Protections to Counter Hidden AI Threats appeared first on SecurityWeek.

Backline Emerges From Stealth With $9M in Funding for Vulnerability Remediation Platform

30 January 2025
Backline has emerged from stealth mode with an autonomous security remediation platform and $9 million in seed funding. The post Backline Emerges From Stealth With $9M in Funding for Vulnerability Remediation Platform appeared first on SecurityWeek.

Infrastructure Laundering: Blending in with the Cloud

30 January 2025
In an effort to blend in and make their malicious traffic tougher to block, hosting firms catering to cybercriminals in China and Russia increasingly are funneling their operations through major U.S. cloud providers. Research published this week on one such outfit -- a sprawling network tied to Chinese organized crime gangs and aptly named "Funnull" -- highlights a persistent whac-a-mole problem facing cloud services.

Cyber Insights 2025: Cyberinsurance – The Debate Continues

30 January 2025
Better risk management could lead to reduced premiums on top of value for money, making cyberinsurance a silent driver for improved cybersecurity. The post Cyber Insights 2025: Cyberinsurance – The Debate Continues appeared first on SecurityWeek.

Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations

30 January 2025
Over 57 distinct threat actors with ties to China, Iran, North Korea, and Russia have been observed using artificial intelligence (AI) technology powered by Google to further enable their malicious cyber and information operations. "Threat actors are experimenting with Gemini to enable their operations, finding productivity gains but not yet developing novel capabilities," Google Threat

Seraphic Attracts $29M Investment to Chase Enterprise Browser Business

30 January 2025
Seraphic Security banks $29 million investment as VCs remain bullish on startups with security-themed browsers for corporate defenders. The post Seraphic Attracts $29M Investment to Chase Enterprise Browser Business appeared first on SecurityWeek.

PayPal ordered to pay $2M in settlement from 2022 breach

30 January 2025
The New York State Department of Financial Services has declared that PayPal will pay $2M in a settlement.