RSS Amplifier

News source

Cybersecurity Dive - Latest News

Cybersecurity News

cybersecuritydive.comSource feed ↗19 articles

Live Last read · last published · next check

Written by

Latest articles

Microsoft confirms maximum severity flaw in Entra ID targeted for exploitation

The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.

Defense contractors’ CMMC confidence lags, even as self-assessments improve

A "confidence disconnect" is plaguing the industry, a consulting firm said.

Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks

Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.

What we know so far about the hacking campaign against US water systems

Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.

AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn

Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.

Ransomware disproportionately targets medium-sized firms, straining customer relationships

These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.

DOJ charges 17 people in Iran-backed hacking campaign against US

Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.

GitLab issues emergency patch for critical code-injection flaw

Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.

AI-powered vulnerability clearinghouse faces deep skepticism, major challenges

The U.S. government's promises about the Gold Eagle coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.

Critical flaw in SAP Commerce Cloud faces initial exploitation attempts

The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.

Major genetic-testing firm says hack compromised sensitive patient data

The June breach, which also exposed employees' information, underscored the supply-chain risks facing the healthcare sector.

Why more security data has blurred companies’ view of risk

More security data can create blind spots. Here's how to regain visibility.

Researchers confirm breach claims by data-extortion group

The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.

Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks

With companies confronting more sophisticated threats, AI agents are driving demand for cybersecurity tools, CEO Chuck Robbins said.

Researchers find AI-powered hacking tools for sale in underground forums

A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.

US government will let private companies hack criminal gangs

The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.

Hackers abuse AI models to find new entry paths

Network defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.

Cisco says software vulnerability could let hackers crash firewalls

Threat actors have already begun exploiting the flaw, according to the U.S. government.

Former BlackFile affiliates linked to extortion campaign targeting private equity

Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.