The Latest

  • CISA, cybersecurity, agency
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    House Democrats ask GAO to study CISA workforce cuts

    Five lawmakers serving on the Homeland Security Committee said Congress didn’t know enough about the Trump administration’s changes to the cybersecurity agency.

  • A man stands at a lectern that has a plaque bearing the acronym "RUSI"
    Image attribution tooltip
    Courtesy of National Cyber Security Centre
    Image attribution tooltip

    UK power facility disabled for days after suspected state-linked cyberattack

    The disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.

  • Microsoft building exterior
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Microsoft discloses maximum severity flaw in Entra ID

    The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.

  • The Pentagon is seen from a flight taking off from Ronald Reagan Washington National Airport.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Defense contractors still struggling with basic CMMC requirements

    A “confidence disconnect” is plaguing the industry, a consulting firm said.

  • Water treatment plant infrastructure at sunset.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    What we know so far about the hacking campaign against US water systems

    Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.

  • A medical professional rests their hand on a laptop keyboard while a stethoscope sits on the table next to them.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks

    Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.

  • Siemens flags fly in front of Siemens AG headquarters in Berlin, Germany, on Aug. 20, 2024.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn

    Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.

    Updated Aug. 20, 2026
  • antitrust enforcement
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    DOJ charges 17 people in Iran-backed hacking campaign against US

    Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.

    Updated Aug. 19, 2026
  • Ransomware Data Breach Protection Cyber Security Email Phishing Encrypted Technology, Digital Information Protected Secured
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ransomware disproportionately targets medium-sized firms, straining customer relationships

    These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.

  • A man stands at a lectern near signs that read "Winning the AI race"
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip
    Deep Dive

    AI-powered vulnerability clearinghouse faces deep skepticism, major challenges

    The U.S. government’s promises about the Gold Eagle coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.

  • a software developer inspects code on a screen
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    GitLab issues emergency patch for critical code-injection flaw

    Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.

    Updated Aug. 19, 2026
  • A research scientist is at work in a laboratory setting.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Major genetic-testing firm says hack compromised sensitive patient data

    The June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector.

  • SAP office exterior.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Critical flaw in SAP Commerce Cloud faces initial exploitation attempts

    The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.

    Updated Aug. 18, 2026
  • Microsoft building with logo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Researchers confirm breach claims by data-extortion group

    The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.

  • Image attribution tooltip
    katleho Seisa via Getty Images
    Image attribution tooltip

    US government will let private companies hack criminal gangs

    The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.

    Updated Aug. 13, 2026
  • A large sign says "Cisco" in red letters. The sign sits on a grassy lawn.
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks

    With companies confronting more sophisticated threats, AI agents are driving demand for cybersecurity tools, CEO Chuck Robbins said.

  • AI fraud online scams software tools
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Researchers find AI-powered hacking tools for sale in underground forums

    A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.

    Updated Aug. 14, 2026
  • A large sign says "Cisco" in red letters. The sign sits on a grassy lawn in front of a building with many windows.
    Image attribution tooltip
    Sundry Photography via Getty Images
    Image attribution tooltip

    Cisco says software vulnerability could let hackers crash firewalls

    Threat actors have already begun exploiting the flaw, according to the U.S. government.

  • Ryan Whelan head of cyber intelligence at Accenture and John Hultquist, chief analyst, Google Threat Intelligence Group, discuss how threat actors are using AI to develop new attack methods at the 2026 Black Hat USA conference in Las Vegas.
    Image attribution tooltip
    Permission granted by David Jones
    Image attribution tooltip

    Hackers abuse AI models to find new entry paths

    Network defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.

  • A digital depiction of a red triangle sign with an exclamation point in the center with binary code in the background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Deep Dive

    CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’

    The vulnerability coordination project has had a rocky few years, but a key leader says it will “flourish and improve.”

  • Close up of Wall Street sign, with tall buildings in the background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Former BlackFile affiliates linked to extortion campaign targeting private equity

    Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.

  • Circular clarifier tanks are seen at a water treatment facility
    Image attribution tooltip
    pigphoto/iStock/Getty Images Plus via Getty Images
    Image attribution tooltip

    Civil-society initiative will pay cybersecurity vendors to protect rural water systems

    DEF CON Franklin is seeking philanthropic grants, but its founder said the federal government ultimately needs to step in.

  • David Weston, CVP, AI Security at Microsoft, delivers a keynote address during the 2026 Black Hat USA conference in Las Vegas.
    Image attribution tooltip
    Permission granted by Black Hat USA
    Image attribution tooltip

    Secure development can help turn the tables as AI alters cyber landscape

    A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.

  • American Hospital Hallway
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’

    Regulatory failures, funding constraints and industry consolidation have created serious hacking risks.

  • Forescout - Vedere Labs presented research at the Black Hat USA conference about vulnerabilities in TP-Link Omada that could allow attackers to abuse zero-touch provisioning technology.
    Image attribution tooltip
    Permission granted by David Jones
    Image attribution tooltip