Threats
-
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
The company’s latest report previews how AI is changing threat activity, including by automating ransomware attacks.
By Eric Geller • Oct. 2, 2026 -
State-linked actor targets US AI policy experts in credential phishing campaigns
The China-linked espionage attacks were designed to gain insight into the country’s strategy and regulatory environment.
By David Jones • Updated Oct. 2, 2026 -
Explore the Trendline➔
Getty Images
TrendlineManaging and securing identity sprawl
Cyber threat actors know the simplest way to hack into an enterprise and remain under the radar is with stolen, legitimate user credentials -- and AI is making managing and securing digital identities more challenging than ever.
By Cybersecurity Dive staff -
Mass exploitation of Citrix NetScaler: What we currently know
Suspected state-linked actors targeted critical vulnerabilities in the widely used platform, causing widespread disruption across Europe and North America.
By David Jones • Sept. 30, 2026 -
Column
Dotted Line: How construction is dealing with cybersecurity in the age of AI
Contractors rank cybersecurity low on their priority lists. But lawyers say being prepared is critical when the inevitable breach occurs.
By Joe Bousquin • Sept. 29, 2026 -
Kiteworks lifts advisory after precautionary warning for customers to shut down systems
The firm had received information from law enforcement of a possible attack.
By David Jones • Sept. 28, 2026 -
Citrix via Flickr
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
Security teams received urgent calls to disconnect servers before authorities confirmed critical zero-day flaws.
By David Jones • Sept. 28, 2026 -
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI.
By Eric Geller • Sept. 28, 2026 -
Businesses expand AI’s cybersecurity uses as comfort with technology grows
Companies in the experimentation stage were less likely than established users to deploy advanced AI-powered defenses, a new survey found.
By Eric Geller • Sept. 25, 2026 -
Threat groups ramp up social-engineering attacks against healthcare sector
Hackers linked to high-profile cybercrime groups have used voice-phishing tactics to trick workers into giving up credentials in recent attacks.
By David Jones • Sept. 25, 2026 -
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries
Many companies still aren’t preparing thoroughly enough to face a hack, the insurance firm Travelers said in a new report.
By Eric Geller • Sept. 23, 2026 -
Insurance sector begins to offer clarity on AI-related cyber claims
The emergence of agentic AI and frontier models has led to widespread uncertainty for policyholders.
By David Jones • Sept. 22, 2026 -
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
The use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk.
By Eric Geller • Sept. 22, 2026 -
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Researchers suspect the hacker employed LLMs to develop custom tools.
By David Jones • Sept. 21, 2026 -
Settra ransomware variant deployed in recent attacks
Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools.
By David Jones • Sept. 18, 2026 -
Retrived from Daimler Truck
Manufacturers make patching progress, but identity management still major weakness
Misconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found.
By Eric Geller • Sept. 17, 2026 -
Companies’ AI strategies don’t account for agentic tools
Businesses are taking AI governance seriously, but their plans lag behind the technology they’re using, according to an EY survey.
By Eric Geller • Sept. 15, 2026 -
Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments.
By Eric Geller • Sept. 14, 2026 -
Sponsored by Arctic Wolf
Security teams are adopting AI faster than they trust it
New survey data reveals a widening gap between AI adoption and AI trust.
Sept. 14, 2026 -
Deep Dive
Accountability, oversight and AI: Inside Microsoft’s security transformation
Stung by years of embarrassing hacks, the tech giant overhauled how it approached cybersecurity. Company leaders now say they’re seeing results.
By Eric Geller • Sept. 11, 2026 -
Threat groups enhance cyberattack capabilities with AI
A report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.
By David Jones • Sept. 10, 2026 -
White House sees water cybersecurity partnership in Texas as national blueprint
The government is taking a new approach to protecting critical infrastructure, National Cyber Director Sean Cairncross said.
By Eric Geller • Sept. 10, 2026 -
CISA is on the verge of filling hundreds of critical vacancies
The agency is also working to finalize an incident-reporting regulation and set up a new industry coordination structure, its acting director said.
By Eric Geller • Sept. 10, 2026 -
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology’s next evolution.
By Eric Geller • Sept. 9, 2026 -
CISOs are feeling the security burden of accelerated AI use
A report shows CISOs face increased pressures related to cyber resilience and business continuity.
By David Jones • Sept. 9, 2026 -
New FBI cyber strategy promises increase in adversary disruptions
The document also focuses on helping victims, reflecting the bureau’s goal of encouraging more companies to share information with it.
By Eric Geller • Sept. 9, 2026