The Latest
-
Retrieved from GAO.
GAO report details scope of cybersecurity regulation overlap
A morass of rules is forcing companies to report the same information multiple times — and sometimes, those rules conflict.
-
Sponsored by BlueVoyant
What the Trojan horse gets right (and wrong) about AI security
Agentic AI didn't invent new risk. It removed the friction that used to keep environments in check.
-
CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy
The agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices.
-
Russia-backed threat actor targets Western organizations in phishing campaign
The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.
-
OpenAI models escaped containment, hacked major AI application library
The attack is the first known instance of frontier models autonomously breaking out of a testing environment and into another company’s servers.
-
Threat group claims credit for ransomware attack on Coca-Cola’s dairy unit
The attackers previously exploited vulnerabilities or used stolen credentials for initial access.
-
Ransomware victims fail to fix flaws that exposed them
Many organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found.
-
Microsoft SharePoint under attack via new exploit
Security researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.
Updated July 23, 2026 -
Researchers trace SonicWall SMA1000 exploitation to late June
Multiple threat actors, including INC ransomware, have targeted vulnerable firewall systems.
-
Hackers steal customer data from major hospital software vendor
The breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks.
-
Ransomware attack forces Coca-Cola to suspend US production at dairy unit
The beverage company is still working to determine the full scope of the breach at its Fairlife business.
-
Abbott discloses cyberattack on cancer diagnostics business
The cyberattack follows Abbott’s recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed.
-
Iran-nexus actors using AI to enhance cyber playbook
A report shows state-linked and hacktivist groups have used ChatGPT and other tools for malware development, phishing and mapping out industrial sites.
-
Gaps in network security, oversight strategy hamper US’s aviation cybersecurity regulators
A new government audit identified several weaknesses at the two agencies that protect air travel from hackers.
-
US launches vulnerability clearinghouse amid AI-fueled surge in flaws
The Trump administration hopes the program will accelerate the discovery and fixing of serious technical problems before hackers exploit them.
-
CISA warns that multiple vulnerabilities in SharePoint are under exploitation
Security researchers say additional flaws are being chained together and a patch will not be available until August.
-
Healthcare sector faces persistent supply-chain security, identity management challenges
A new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare.
-
Sharp rise in AI adoption for cyber defense exposes major governance gap
A report by the SANS Institute indicates a split between senior security leaders and frontline practitioners.
-
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.
-
US authorities warn that state-linked hackers are targeting vulnerable networking devices
Hackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.
-
CISA details security lapses that led to GitHub leak of passwords, cloud access keys
The agency’s blog post came as lawmakers pressed the agency for answers.
-
Citrix via Flickr
Initial access broker linked to weaponization of CitrixBleed2 flaw
A similar pattern of exploitation was seen in prior attacks involving an open-source machine emulator.
-
Ransomware ecosystem grows, but ‘four-headed monster’ dominates
AI is helping hackers, a new report finds, but mostly by automating very human behaviors.
-
Data breach hits car insurance provider
Hackers gained access to more than 6.9 million records at AssuranceAmerica by targeting a company employee.
-
Accenture faces massive data breach that could put clients at risk
The threat actor claiming responsibility says they stole source code, encryption keys and more.
-
US enterprises incorporate cyber risk into larger strategic focus
The rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact.
Updated July 8, 2026