Threats


  • The Microsoft logo is seen at an Experience Center on Fifth Avenue on April 03, 2024 in New York City.
    Image attribution tooltip
    Michael M. Santiago via Getty Images
    Image attribution tooltip

    FBI warns about PhaaS platform used to access Microsoft 365 environments

    Device code phishing enabled hackers to bypass multifactor authentication without credentials.

    By May 26, 2026
  • An Iranian flag flutters in front of a building with many windows
    Image attribution tooltip
    Michael Gruber via Getty Images
    Image attribution tooltip

    Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages

    Companies, particularly those in the affected industries, should harden their defenses against impersonation schemes, Palo Alto Networks said.

    By May 22, 2026
  • Trendline

    Managing identity sprawl

    Cyber threat actors know the simplest way to hack into an enterprise and remain under the radar is with stolen, legitimate user credentials -- and cloud services and AI are making managing and securing digital identities more challenging than ever.

    By Cybersecurity Dive staff
  • Woman in a black suit stands behind a podium with a sign that reads "enhancing cybersecurity protecting New Yorkers."
    Image attribution tooltip
    Courtesy of Darren McGee/ Office of Governor Kathy Hochul
    Image attribution tooltip

    New York regulator calls for additional cyber mitigation amid heightened threat environment

    The guidance from the state Department of Financial Services arises from concerns about frontier AI and threats linked to the Iran war and other geopolitical risks.

    By May 22, 2026
  • Close-up Focus on Person's Hands Typing on the Desktop Computer Keyboard
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Grafana Labs links GitHub environment breach to TanStack npm supply chain attack

    The company behind the widely used observability platform refused an extortion demand and has since taken steps to harden its security.

    By May 21, 2026
  • Cyberhackers-Ransomware
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Microsoft disrupts cybercrime operation that hid behind legitimate software

    The Fox Tempest malware-signing-as-a-service operation was linked to numerous ransomware attacks.

    By May 20, 2026
  • A dark screen shows light colored text reading "Welcome to GitHub" and "We are glad you're here."
    Image attribution tooltip
    Leon Neal / Staff via Getty Images
    Image attribution tooltip

    Compromised coding tool helped hackers breach thousands of GitHub repositories

    The attack is the latest example of hackers’ intense focus on open-source packages.

    By May 20, 2026
  • An electronic tower stands against a blue sky.
    Image attribution tooltip
    The image by Ervins Strauhmanis is licensed under CC BY 2.0
    Image attribution tooltip

    Telecom sector launches its own private ISAC

    Federal government involvement in an existing group chilled some cybersecurity discussions among major telecom providers. The new group is intended to alleviate those anxieties.

    By May 19, 2026
  • Hooded person types on computer in a dark room with multiple monitors and cables everywhere.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Grafana Labs says hacker gained access to codebase through leaked token

    The company, which operates a widely used observability platform, is refusing to pay an extortion demand.

    By Updated May 19, 2026
  • The Cisco office at Santana Row Shopping Mall in San Jose California.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller

    Researchers discovered the authentication bypass vulnerability while investigating a prior issue in the same service.

    By May 15, 2026
  • A person holds a smartphone with a secure padlock icon and a cyber security app on the screen.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    MSPs need AI to fight AI-fueled cyberthreats: Guardz

    Entry points haven’t changed, but the speed and scale of attacks have intensified, the security vendor found.

    By Kelly Teal, Channel Dive contributor • May 15, 2026
  • Foxconn's manufacturing site in the Village of Mount Pleasant, Wisconsin.
    Image attribution tooltip
    Courtesy of Foxconn
    Image attribution tooltip

    Foxconn confirms cyberattack affecting some North American facilities

    A ransomware group has claimed a major attack against the electronics manufacturer.

    By May 13, 2026
  • Digital technology vector background depicting a cyberattack.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Canvas owner reaches ‘agreement’ with threat actors after data breach

    Cybersecurity experts suggest that Instructure appears to have made a ransomware payment, which the FBI highly discourages.

    By Anna Merod • May 13, 2026
  • A banner reading "Power of Community" and "RSAC 2026 Conference" hangs over a walkway between two sets of escalators
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip

    AI and an absent government: Takeaways from RSAC 2026

    Cybersecurity professionals discussed the balance between autonomy and oversight at the recent conference.

    By May 12, 2026
  • A screenshot of a message from ShinyHunters on a laptop screen.
    Image attribution tooltip
    Permission granted by Chris Insana
    Image attribution tooltip

    Second Canvas data breach causes major disruptions for schools, colleges

    The Instructure-owned learning management system went offline on May 7 after a threat actor once again gained unauthorized access.

    By Anna Merod • May 11, 2026
  • Digital background depicting AI systems and machine learning technologies
    Image attribution tooltip
    MF3d via Getty Images
    Image attribution tooltip

    AI used to develop working zero-day exploit, researchers warn

    A report by GTIG shows threat groups are increasingly leveraging AI to scale attacks. The exploitation attempt was disclosed and patched, preventing a mass incident.

    By May 11, 2026
  • A digital depiction of a red triangle sign with an exclamation point in the center with binary code in the background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Instructure confirms cybersecurity incident

    The ed tech company that operates Canvas said information impacted by the data breach includes messages, names, email addresses and student ID numbers.

    By Anna Merod • May 8, 2026
  • Palo Alto Networks
    Image attribution tooltip
    Matt Kapko/Cybersecurity Dive
    Image attribution tooltip

    Palo Alto Networks warns state-linked cluster behind zero-day exploitation

    A patch for the flaw, which hackers began targeting in early April, won’t be ready for another week.

    By May 7, 2026
  • Iran-sponsored threat group behind false flag social engineering campaign

    The state-linked actor has been masquerading as a criminal ransomware group in attacks targeting U.S. organizations.

    By May 6, 2026
  • A large entrance sign that reads "Gate A, NIST, National Institute of Standards and Technology, U.S. Department of Commerce" is mounted on a rock base and surrounded by grass and trees. In the background to the left of the sign, there is a commercial building.
    Image attribution tooltip
    R. Eskalis/NIST. Retrieved from NIST.
    Image attribution tooltip

    NIST will test three major tech firms’ frontier AI models for cybersecurity risks

    After Anthropic’s announcement of Claude Mythos, agencies across the government are racing to get ahead of new AI models’ potential dangers.

    By Updated May 21, 2026
  • An American flag and a flag bearing the seal of the Cybersecurity and Infrastructure Security Agency (which features an eagle holding a shield with elements of a skyline on it) flank a large upright square panel bearing the same CISA seal. On the wall to the right of the panel and the flags, a row of digital clocks shows the time in the four major U.S. time zones.
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip

    CISA urges critical infrastructure firms to ‘fortify’ before it’s too late

    As concerns mount about potential cyber sabotage by the Chinese government, the U.S. is warning operators to practice maintaining services in a degraded state.

    By Updated May 5, 2026
  • View of the White House with flowers and fountain in front.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    White House questions tech industry on defensive AI use, cybersecurity resilience

    Companies may be reluctant to answer some of the government’s questions, given the sensitive topics they address.

    By May 1, 2026
  • Login information attached to large hook hanging in front of computer keyboard.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    As email phishing evolves, malicious attachments decline and QR codes surge

    A new Microsoft report also describes the collapse of a once-dominant tool for generating phishing websites with fake CAPTCHAs.

    By May 1, 2026
  • An illustration of agentic AI
    Image attribution tooltip
    MF3d via Getty Images
    Image attribution tooltip

    US and allies urge ‘careful adoption’ of AI agents

    New guidance from a coalition of Western governments underscores the difficult-to-predict risks of still-evolving agentic tools.

    By May 1, 2026
  • Chris Skipworth, Passpack, password management, operational technology, connected building systems
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    US agencies promote zero-trust practices for operational technology networks

    Many zero-trust defenses work differently in industrial environments than in traditional business networks, five federal agencies said in newly published guidance.

    By April 30, 2026
  • Two people standing face to face on a plastics production line.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    ‘Fundamental tension’ undermines manufacturers’ cybersecurity

    A simple security mistake caused roughly one-quarter of all financial losses in the sector in 2025, cybersecurity insurer Resilience said.

    By April 28, 2026