A “confidence disconnect” is plaguing the industry, a consulting firm said.
Tag: Cybersecurity Dive – Latest News
Microsoft confirms maximum severity flaw in Entra ID targeted for exploitation
The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.
Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.
What we know so far about the hacking campaign against US water systems
Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of…
Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.
Ransomware disproportionately targets medium-sized firms, straining customer relationships
These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.
DOJ charges 17 people in Iran-backed hacking campaign against US
Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government…
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations…
Critical flaw in SAP Commerce Cloud faces initial exploitation attempts
The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.
Major genetic-testing firm says hack compromised sensitive patient data
The June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector.
Why more security data has blurred companies’ view of risk
More security data can create blind spots. Here’s how to regain visibility.
Researchers confirm breach claims by data-extortion group
The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.
Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks
AI agents are driving demand for cybersecurity tools as companies confront increasingly sophisticated threats, CEO Chuck Robbins said.
Hackers abuse AI models to find new entry paths
Network defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.
Cisco says software vulnerability could let hackers crash firewalls
Threat actors have already begun exploiting the flaw, according to the U.S. government.
Researchers find AI-powered hacking tools for sale in underground forums
A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.
US government will let private companies hack criminal gangs
The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.
