The Latest

  • Microsoft building exterior
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Microsoft discloses maximum severity flaw in Entra ID

    The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.

  • The Pentagon is seen from a flight taking off from Ronald Reagan Washington National Airport.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Defense contractors still struggling with basic CMMC requirements

    A “confidence disconnect” is plaguing the industry, a consulting firm said.

  • Water treatment plant infrastructure at sunset.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    What we know so far about the hacking campaign against US water systems

    Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.

  • A medical professional rests their hand on a laptop keyboard while a stethoscope sits on the table next to them.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks

    Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.

  • Siemens flags fly in front of Siemens AG headquarters in Berlin, Germany, on Aug. 20, 2024.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn

    Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.

    Updated Aug. 20, 2026
  • antitrust enforcement
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    DOJ charges 17 people in Iran-backed hacking campaign against US

    Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.

    Updated Aug. 19, 2026
  • Ransomware Data Breach Protection Cyber Security Email Phishing Encrypted Technology, Digital Information Protected Secured
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ransomware disproportionately targets medium-sized firms, straining customer relationships

    These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.

  • A man stands at a lectern near signs that read "Winning the AI race"
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip
    Deep Dive

    AI-powered vulnerability clearinghouse faces deep skepticism, major challenges

    The U.S. government’s promises about the Gold Eagle coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.

  • a software developer inspects code on a screen
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    GitLab issues emergency patch for critical code-injection flaw

    Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.

    Updated Aug. 19, 2026
  • A research scientist is at work in a laboratory setting.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Major genetic-testing firm says hack compromised sensitive patient data

    The June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector.

  • SAP office exterior.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Critical flaw in SAP Commerce Cloud faces initial exploitation attempts

    The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.

    Updated Aug. 18, 2026
  • Microsoft building with logo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Researchers confirm breach claims by data-extortion group

    The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.

  • Image attribution tooltip
    katleho Seisa via Getty Images
    Image attribution tooltip

    US government will let private companies hack criminal gangs

    The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.

    Updated Aug. 13, 2026
  • A large sign says "Cisco" in red letters. The sign sits on a grassy lawn.
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks

    With companies confronting more sophisticated threats, AI agents are driving demand for cybersecurity tools, CEO Chuck Robbins said.

  • AI fraud online scams software tools
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Researchers find AI-powered hacking tools for sale in underground forums

    A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.

    Updated Aug. 14, 2026
  • A large sign says "Cisco" in red letters. The sign sits on a grassy lawn in front of a building with many windows.
    Image attribution tooltip
    Sundry Photography via Getty Images
    Image attribution tooltip

    Cisco says software vulnerability could let hackers crash firewalls

    Threat actors have already begun exploiting the flaw, according to the U.S. government.

  • Ryan Whelan head of cyber intelligence at Accenture and John Hultquist, chief analyst, Google Threat Intelligence Group, discuss how threat actors are using AI to develop new attack methods at the 2026 Black Hat USA conference in Las Vegas.
    Image attribution tooltip
    Permission granted by David Jones
    Image attribution tooltip

    Hackers abuse AI models to find new entry paths

    Network defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.

  • A digital depiction of a red triangle sign with an exclamation point in the center with binary code in the background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Deep Dive

    CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’

    The vulnerability coordination project has had a rocky few years, but a key leader says it will “flourish and improve.”

  • Close up of Wall Street sign, with tall buildings in the background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Former BlackFile affiliates linked to extortion campaign targeting private equity

    Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.

  • Circular clarifier tanks are seen at a water treatment facility
    Image attribution tooltip
    pigphoto/iStock/Getty Images Plus via Getty Images
    Image attribution tooltip

    Civil-society initiative will pay cybersecurity vendors to protect rural water systems

    DEF CON Franklin is seeking philanthropic grants, but its founder said the federal government ultimately needs to step in.

  • David Weston, CVP, AI Security at Microsoft, delivers a keynote address during the 2026 Black Hat USA conference in Las Vegas.
    Image attribution tooltip
    Permission granted by Black Hat USA
    Image attribution tooltip

    Secure development can help turn the tables as AI alters cyber landscape

    A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.

  • American Hospital Hallway
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’

    Regulatory failures, funding constraints and industry consolidation have created serious hacking risks.

  • Forescout - Vedere Labs presented research at the Black Hat USA conference about vulnerabilities in TP-Link Omada that could allow attackers to abuse zero-touch provisioning technology.
    Image attribution tooltip
    Permission granted by David Jones
    Image attribution tooltip
  • People stand at a conference booth in a large room in a convention center. The words "OpenAI Daybreak" are printed in large font on a wall behind the booth.
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip

    AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says

    The Trump administration believes leading AI companies have learned important lessons from recent incidents and regulation isn’t necessary to preserve those lessons.

  • A man speaks while a woman and a man on either side of him listen to him
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip

    Hackers grow more willing to destroy, not just disrupt, OT systems

    Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics.