Threats
-
OpenAI pledges $1B to provide resources, training for frontline cyber defenders
Amid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors.
By David Jones • Sept. 4, 2026 -
Government, industry partner to shut down long-running Sality botnet
A nonprofit group is now working to contact victims.
By Eric Geller • Sept. 3, 2026 -
Explore the Trendline➔
Getty Images
TrendlineCISO Strategy
AI is rapidly transforming the cybersecurity landscape, and CISOs must keep pace.
By Cybersecurity Dive staff -
Government lacks ability to verify AI labs’ claims, experts say
A new survey of national security practitioners identified a wide range of near- and medium-term AI risks for policymakers to consider.
By Eric Geller • Sept. 3, 2026 -
Frontier AI helps exploit flaws in tests using key industrial devices
A report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.
By David Jones • Sept. 1, 2026 -
State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
By David Jones • Aug. 31, 2026 -
Frontier AI tipping the scales toward cyber adversaries
Researchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses.
By David Jones • Aug. 28, 2026 -
CISA identifies security hurdles that led to very different results in two red-team engagements
The agency said its recent simulated cyberattacks offered several key lessons for many organizations.
By Eric Geller • Aug. 28, 2026 -
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
Compromised IoT devices were used in a yearslong campaign against key sectors and federal agencies.
By David Jones • Aug. 27, 2026 -
Treasury to help financial firms transition to quantum-resistant encryption
The government is concerned that hackers could someday decrypt financial information and other secrets using code-breaking quantum computers.
By Eric Geller • Aug. 26, 2026 -
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
By David Jones • Updated Aug. 26, 2026 -
CISA orders agencies to fix exploited Zimbra vulnerability
The collaboration software’s developer took almost a full month to patch the flaw after disclosing it.
By Eric Geller • Aug. 25, 2026 -
UK power facility disabled for days after suspected state-linked cyberattack
The disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.
By David Jones • Aug. 24, 2026 -
Sponsored by EzProtect
Salesforce gave every org the same free scanner. Attackers already know what it misses.
A defense every attacker can rehearse against isn't a defense. It's a false sense of security.
By Matt Meyers, CTA, Founder and CEO, EzProtect • Aug. 24, 2026 -
Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.
By Eric Geller • Aug. 20, 2026 -
What we know so far about the hacking campaign against US water systems
Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.
By David Jones • Aug. 20, 2026 -
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.
By David Jones • Updated Aug. 20, 2026 -
DOJ charges 17 people in Iran-backed hacking campaign against US
Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.
By David Jones • Updated Aug. 19, 2026 -
Sponsored by Zurich Resilience Solutions
Why more security data has blurred companies’ view of risk
More security data can create blind spots. Here’s how to regain visibility.
Aug. 17, 2026 -
Researchers confirm breach claims by data-extortion group
The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.
By David Jones • Aug. 14, 2026 -
Researchers find AI-powered hacking tools for sale in underground forums
A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.
By David Jones • Updated Aug. 14, 2026 -
US government will let private companies hack criminal gangs
The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.
By Eric Geller • Updated Aug. 13, 2026 -
Hackers abuse AI models to find new entry paths
Network defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.
By David Jones • Aug. 12, 2026 -
Cisco says software vulnerability could let hackers crash firewalls
Threat actors have already begun exploiting the flaw, according to the U.S. government.
By Eric Geller • Aug. 12, 2026 -
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.
By David Jones • Aug. 11, 2026 -
Civil-society initiative will pay cybersecurity vendors to protect rural water systems
DEF CON Franklin is seeking philanthropic grants, but its founder said the federal government ultimately needs to step in.
By Eric Geller • Aug. 10, 2026