News
After major Poland energy grid cyberattack, CISA issues warning to U.S. audience
1+ hour, 38+ min ago (285+ words) A recent attempt at a destructive cyberattack on Poland's power grid has prompted the Cybersecurity and Infrastructure Security Agency to publish a warning for U.S. critical infrastructure owners and operators. CISA said its warning was meant to "amplify" that Polish report....
Fallout from latest Ivanti zero-days spreads to nearly 100 victims
1+ day, 12+ min ago (520+ words) Ivanti customers, including major government agencies, face mounting pressure as attackers expand their scope of targets to exploit a pair of vulnerabilities the vendor disclosed last week after in-the-wild attacks already occurred." The attacks were publicly disclosed as researchers and…...
What leaders can learn from the WEF's Cybersecurity Outlook
4+ day, 23+ hour ago (118+ words) Greg speaks with Brian Dye, CEO of Corelight, about the World Economic Forum's Global Cybersecurity Outlook 2026 AI is reshaping cybersecurity faster than most organizations can govern it'and the risk no longer stops at the edge of the enterprise. In this…...
CISA tells agencies to stop using unsupported edge devices
5+ day, 4+ hour ago (357+ words) It's a stab at tackling one of the most persistent and difficult-to-manage avenues of attack for hackers, a vector that has factored into some of the most consequential and most common types of exploits in recent years. New edge-device vulnerabilities…...
Ivanti’s EPMM is under active attack, thanks to two critical zero-days
1+ week, 1+ hour ago (773+ words) Attackers are again focusing on a familiar target in the network edge space, actively exploiting two critical zero-day vulnerabilities in Ivanti software that allows administrators to set mobile device and application controls." The vulnerabilities " CVE-2026-1281 and CVE-2026-1340 " each carry a…...
China-based espionage group compromised Notepad++ for six months
1+ week, 1+ day ago (424+ words) A China-based threat group operating for almost two decades broke into the internal systems of Notepad++, an extremely popular open source-code editor, to spy on a select group of targeted users, researchers at Rapid7 said Monday. The Chinese APT group Lotus…...
Why 'move fast and break things' is driving supply-chain cyber risk
1+ week, 1+ day ago (288+ words) But Zuckerberg's call was heard well beyond Facebook's offices. The tech industry has embraced the philosophy for close to two decades, with benefits that are visible all around us: from Tik-Tok influencers, to contactless mobile payments, self-driving taxis, and AI-powered…...
Google's disruption rips millions out of devices out of malicious network
1+ week, 4+ day ago (586+ words) Google's action, aided by Cloudflare, Lumen's Black Lotus Labs and Spur, impaired some of IPIDEA's proxy infrastructure, but not all of it. The coordinated strikes against malicious infrastructure underscore the back-and-forth struggle threat hunters confront when they take out pieces…...
Opportunistic by Default: How OT gets pulled into the blast radius
1+ week, 4+ day ago (117+ words) Opportunistic by Default: How OT gets pulled into the blast radius'CyberScoop In this episode of Safe Mode, we look at how opportunistic campaigns'often starting as loud disruption like DDoS'can probe for weak points and, in some cases, move closer to…...
Why the domain registration system is a major security threat, according to Secret Service
1+ week, 5+ day ago (366+ words) The internet domain registration system is a major weakness that malicious hackers can exploit, but is often being overlooked, a senior Secret Service official said Thursday. "It is staggering to me that we live in a world where domain registrars…...