Threats
-
The most vulnerable AI products are also some of the most commonly exposed online
It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.
By Eric Geller • July 24, 2026 -
Russia-backed threat actor targets Western organizations in phishing campaign
The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.
By David Jones • July 23, 2026 -
Explore the Trendline➔
Getty Images
-
CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy
The agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices.
By David Jones • July 23, 2026 -
Threat group claims credit for ransomware attack on Coca-Cola’s dairy unit
The attackers previously exploited vulnerabilities or used stolen credentials for initial access.
By David Jones • July 22, 2026 -
Ransomware victims fail to fix flaws that exposed them
Many organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found.
By Eric Geller • July 21, 2026 -
Researchers trace SonicWall SMA1000 exploitation to late June
Multiple threat actors, including INC ransomware, have targeted vulnerable firewall systems.
By David Jones • July 20, 2026 -
Ransomware attack forces Coca-Cola to suspend US production at dairy unit
The beverage company is still working to determine the full scope of the breach at its Fairlife business.
By David Jones • July 17, 2026 -
Gaps in network security, oversight strategy hamper US’s aviation cybersecurity regulators
A new government audit identified several weaknesses at the two agencies that protect air travel from hackers.
By Eric Geller • July 16, 2026 -
Iran-nexus actors using AI to enhance cyber playbook
A report shows state-linked and hacktivist groups have used ChatGPT and other tools for malware development, phishing and mapping out industrial sites.
By David Jones • July 16, 2026 -
US launches vulnerability clearinghouse amid AI-fueled surge in flaws
The Trump administration hopes the program will accelerate the discovery and fixing of serious technical problems before hackers exploit them.
By Eric Geller • July 15, 2026 -
Healthcare sector faces persistent supply-chain security, identity management challenges
A new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare.
By Eric Geller • July 14, 2026 -
US authorities warn that state-linked hackers are targeting vulnerable networking devices
Hackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.
By David Jones • July 13, 2026 -
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.
By Eric Geller • July 13, 2026 -
Ransomware ecosystem grows, but ‘four-headed monster’ dominates
AI is helping hackers, a new report finds, but mostly by automating very human behaviors.
By Eric Geller • July 9, 2026 -
Businesses modernizing networks for AI fear expanding attack surface, limited visibility
IT leaders are worried that security controls aren’t keeping pace with threats to AI systems.
By Eric Geller • July 7, 2026 -
Deep Dive
Sophisticated threat campaign pushes Cisco to the very edge
A monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure.
By David Jones • July 7, 2026 -
Alleged member of Scattered Spider extradited to US
A man with dual U.S.-Estonian citizenship was charged in connection to the hack of a luxury jewelry retailer.
By David Jones • July 6, 2026 -
Why schools are easy prey for hackers — and why they struggle to fight back
Power plants and gas pipelines might receive more attention, but schools are arguably more vulnerable.
By Eric Geller • July 6, 2026 -
FortiBleed campaign traced to INC and Lynx ransomware operations
Researchers are also investigating the role of a suspected zero-day vulnerability.
By David Jones • July 2, 2026 -
Most cybersecurity workers have been told to conceal a breach, report finds
Security firm Bitdefender also found that U.S. companies were simultaneously more confident and more strained on cyber defense than foreign peers.
By Eric Geller • July 2, 2026 -
Retrieved from iStock.
Insurance body confirms hackers posted Oracle PeopleSoft breach data
NAIC warned that some ratings agencies have suspended data feeds as a precaution.
By David Jones • Updated June 29, 2026 -
NIST offers security guidance for water utilities using remote-access tools
The technology is one of the water sector’s biggest cybersecurity weaknesses.
By Eric Geller • June 25, 2026 -
Microsoft, Europol lead global takedown of infostealer malware
Cybercriminals used Amadey and StealC to infect thousands of computers worldwide, leading to ransomware and other digital crimes.
By David Jones • June 24, 2026 -
Ransomware attacks grew in 2025 as traditional data breaches fell
In a new report, Bitsight charted a massive surge in internet-exposed AI services.
By Eric Geller • June 24, 2026 -
Trump sets new deadlines for agencies and contractors to adopt post-quantum cryptography
The president also launched efforts to research the scientific benefits of quantum computers — and protect that research from adversaries.
By Eric Geller • June 23, 2026