The Latest

  • The Microsoft logo is seen at an Experience Center on Fifth Avenue on April 03, 2024 in New York City.
    Image attribution tooltip
    Michael M. Santiago via Getty Images
    Image attribution tooltip

    FBI warns about PhaaS platform used to access Microsoft 365 environments

    Device code phishing enabled hackers to bypass multifactor authentication without credentials.

  • An Iranian flag flutters in front of a building with many windows
    Image attribution tooltip
    Michael Gruber via Getty Images
    Image attribution tooltip

    Iranian government, not hacktivist group, breached LA Metro system, security firm says

    A report by Israel-based Gambit Security dismisses the hackers’ claims of being patriotic but unaffiliated activists.

  • An Iranian flag flutters in front of a building with many windows
    Image attribution tooltip
    Michael Gruber via Getty Images
    Image attribution tooltip

    Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages

    Companies, particularly those in the affected industries, should harden their defenses against impersonation schemes, Palo Alto Networks said.

  • Woman in a black suit stands behind a podium with a sign that reads "enhancing cybersecurity protecting New Yorkers."
    Image attribution tooltip
    Courtesy of Darren McGee/ Office of Governor Kathy Hochul
    Image attribution tooltip

    New York regulator calls for additional cyber mitigation amid heightened threat environment

    The guidance from the state Department of Financial Services arises from concerns about frontier AI and threats linked to the Iran war and other geopolitical risks.

  • Close-up Focus on Person's Hands Typing on the Desktop Computer Keyboard
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Grafana Labs links GitHub environment breach to TanStack npm supply chain attack

    The company behind the widely used observability platform refused an extortion demand and has since taken steps to harden its security.

  • CISA, cybersecurity, agency
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    CISA asks cybersecurity community to alert it to vulnerability exploitation

    The agency wants to ensure that its public catalog of actively exploited flaws is as comprehensive as possible.

  • A dark screen shows light colored text reading "Welcome to GitHub" and "We are glad you're here."
    Image attribution tooltip
    Leon Neal / Staff via Getty Images
    Image attribution tooltip

    Compromised coding tool helped hackers breach thousands of GitHub repositories

    The attack is the latest example of hackers’ intense focus on open-source packages.

  • Cyberhackers-Ransomware
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Microsoft disrupts cybercrime operation that hid behind legitimate software

    The Fox Tempest malware-signing-as-a-service operation was linked to numerous ransomware attacks.

  • An electronic tower stands against a blue sky.
    Image attribution tooltip
    The image by Ervins Strauhmanis is licensed under CC BY 2.0
    Image attribution tooltip

    Telecom sector launches its own private ISAC

    Federal government involvement in an existing group chilled some cybersecurity discussions among major telecom providers. The new group is intended to alleviate those anxieties.

  • Digital code data numbers and secure lock icons on hacker's hands working with keyboard computer on dark blue tone background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN

    Researchers said a wave of attacks began in February targeting firewalls that appeared to be protected. 

  • Six men stand on a stage. Three men hold an oversized $4 million check made out to "Team Atlanta," while two of the other men flank this trio and pose for a photo with them. The sixth person stands off to the side and applauds.
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip
    Deep Dive

    How a government contest launched a revolution in AI-based bug hunting

    Security researchers have spent months honing AI systems that can find and fix serious vulnerabilities. Critical infrastructure everywhere could benefit.

  • Hooded person types on computer in a dark room with multiple monitors and cables everywhere.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Grafana Labs says hacker gained access to codebase through leaked token

    The company, which operates a widely used observability platform, is refusing to pay an extortion demand.

    Updated May 19, 2026
  • The Cisco office at Santana Row Shopping Mall in San Jose California.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller

    Researchers discovered the authentication bypass vulnerability while investigating a prior issue in the same service.

  • Digital background depicting AI systems and machine learning technologies
    Image attribution tooltip
    MF3d via Getty Images
    Image attribution tooltip

    Frontier AI models reap rapid discovery of security vulnerabilities

    Security teams have just a few months before AI-driven exploitation becomes the norm, researchers warn.

  • Team of hackers dressed in black work on computers in dark room.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    West Pharmaceutical starts restoring operations after ransomware attack

    The company confirmed data was stolen and encrypted by the attackers.

  • Foxconn's manufacturing site in the Village of Mount Pleasant, Wisconsin.
    Image attribution tooltip
    Courtesy of Foxconn
    Image attribution tooltip

    Foxconn confirms cyberattack affecting some North American facilities

    A ransomware group has claimed a major attack against the electronics manufacturer.

  • A digital depiction of a red triangle sign with an exclamation point in the center with binary code in the background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Instructure confirms cybersecurity incident

    The ed tech company that operates Canvas said information impacted by the data breach includes messages, names, email addresses and student ID numbers.

  • Sam Altman speaks in a conference setting
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    OpenAI launches Daybreak to combat cyber threats

    The cybersecurity initiative uses AI to detect software vulnerabilities, partnering with Cloudflare, Cisco and CrowdStrike to counter threats.

  • A banner reading "Power of Community" and "RSAC 2026 Conference" hangs over a walkway between two sets of escalators
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip

    AI and an absent government: Takeaways from RSAC 2026

    Cybersecurity professionals discussed the balance between autonomy and oversight at the recent conference.

  • Artificial intelligence technology AI symbol digital concept 3d illustration
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Identity takes center stage as a leading factor in enterprise cyberattacks

    A new report shows two-thirds of ransomware attacks began with an identity-related breach.

  • Electrical transmission towers and their power lines loom over trees at dusk
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip
    Deep Dive

    New cybersecurity industry coalition aims to lead US critical infrastructure protection

    The new Alliance for Critical Infrastructure’s biggest goal: changing how the nation plans for a major cybersecurity crisis.

  • Claude, AI startup, Anthropic
    Image attribution tooltip
    Permission granted by Anthropic
    Image attribution tooltip

    Anthropic’s Claude used in attempted compromise of Mexican water utility

    Researchers warn the incident highlights how AI tools can help untrained threat actors develop complex cyberattack capabilities.

  • Digital background depicting AI systems and machine learning technologies
    Image attribution tooltip
    MF3d via Getty Images
    Image attribution tooltip

    AI used to develop working zero-day exploit, researchers warn

    A report by GTIG shows threat groups are increasingly leveraging AI to scale attacks. The exploitation attempt was disclosed and patched, preventing a mass incident.

  • A screenshot of a message from ShinyHunters on a laptop screen.
    Image attribution tooltip
    Permission granted by Chris Insana
    Image attribution tooltip

    Second Canvas data breach causes major disruptions for schools, colleges

    The Instructure-owned learning management system went offline on May 7 after a threat actor once again gained unauthorized access.

  • Palo Alto Networks
    Image attribution tooltip
    Matt Kapko/Cybersecurity Dive
    Image attribution tooltip

    Palo Alto Networks warns state-linked cluster behind zero-day exploitation

    A patch for the flaw, which hackers began targeting in early April, won’t be ready for another week.