News
News
- July 23, 2026
23 Jul'26
OpenAI models escape containment, hack Hugging Face
In an unprecedented -- and unintended -- cyberattack, frontier AI models autonomously escaped their contained testing environment and breached another company's systems.
- July 23, 2026
23 Jul'26
Black Hat 2026: Key news, takeaways and security trends
This is your guide to the breaking news, trending topics and more at Black Hat USA 2026, from Dark Reading, Cybersecurity Dive and TechTarget Cybersecurity.
- July 20, 2026
20 Jul'26
Employees' shadow AI use is poorly monitored, survey finds
Employee behavior has always presented one of the biggest enterprise cybersecurity challenges. Add AI into the equation, and education and governance become even more critical.
-
- July 17, 2026
17 Jul'26
Industry reacts to Gold Eagle vulnerability management plan
As AI-discovered software vulnerabilities accumulate at an unprecedented pace, security pros say they hope Gold Eagle creates some order from the chaos.
- July 10, 2026
10 Jul'26
ClickFix and removable media lead malware delivery methods
Now more than ever, defenders must look for suspicious behavior, not specific malware. Learn how to defend against two trending initial access methods.
- July 08, 2026
08 Jul'26
First fully agentic ransomware attack sparks readiness concerns
An AI model's autonomous execution of a complete ransomware operation marks a new era. Learn why experts say rapid detection and response, not revolutionary defenses, are key.
- June 26, 2026
26 Jun'26
NO FAKES Act advances: What CISOs need to know
As the NO FAKES Act moves to the Senate, the country is closer to real protections against unauthorized AI replica use -- a move that also has enterprise implications.
- June 24, 2026
24 Jun'26
As Q-Day looms, 90% of systems are unprepared for PQC
Quantum computing could break encryption in the next several years, and research suggests that few organizations are ready. Experts say CISOs must act now.
- June 18, 2026
18 Jun'26
Most security pros say their culture is 'just average'
'The Life and Times of Cybersecurity Professionals' survey assessed how workers feel about defending against constant threats, as well as what's getting better and what is not.
- June 12, 2026
12 Jun'26
What CISA's new remediation directive means for CISOs
CISA's updated directive for federal agencies compresses mandatory patching timelines to just three days for high-risk flaws, urging practitioners to 'patch smarter, not harder.'
-
- June 12, 2026
12 Jun'26
It's time to update incident response for the AI era
Your latest cybersecurity incident might not be a threat actor, but an internal AI agent doing what it's authorized to do. Incident response must evolve to accommodate AI.
- June 10, 2026
10 Jun'26
AI in cyberdefense: Learning from threat actors' playbooks
At the Gartner Cybersecurity and Risk Management Summit 2026, security professionals learned how to use AI to counter the AI-fueled cyberattacks directed against them.
- June 10, 2026
10 Jun'26
Gartner Security & Risk Management Summit 2026: Adapting for AI
Check out SearchSecurity's Gartner Security & Risk Management Summit guide for reports on notable presentations and sessions on the latest security topics.
- June 08, 2026
08 Jun'26
CISO role changes as cyber-risk appetites in the C-suite grow
As cybersecurity fears in the C-suite wane, the cyber-risk appetites of executives and boards are changing. Find out what it means for cybersecurity spending and the CISO role.
- June 05, 2026
05 Jun'26
Researchers build autonomous AI worm that can reason and adapt
University of Toronto researchers created a proof-of-concept AI worm that dynamically identifies vulnerabilities and adapts its attack strategies. Here's what it means for enterprises.
- June 03, 2026
03 Jun'26
Lost in translation: Cybersecurity board reporting for CISOs
Cybersecurity board reports don't always land. At the Security and Risk Management Summit 2026, Gartner analysts suggested a novel way to communicate cyber-risk to corporate directors.
- May 29, 2026
29 May'26
EO 14390 raises stakes for enterprise cybersecurity
Reframing cybercrime as a national security issue, EO 14390 could lead to stronger links between government and the private sector. Find out what it means for enterprise security.
- May 29, 2026
29 May'26
First month of Mythos Preview testing exposes 10K flaws
Anthropic's Mythos Preview exposed 10,000-plus security flaws at tech giants in one month, revealing both opportunities and risks for the future of cybersecurity.
- May 27, 2026
27 May'26
OT attacks shift from recon to physical control, raising stakes
Malicious hackers are no longer just snooping around OT systems, researchers warn. They're preparing to cause real-world damage.
- May 27, 2026
27 May'26
For CISOs, dawn of OpenAI Daybreak brings good and bad news
OpenAI Daybreak shows how AI reshapes vulnerability discovery. But AI-driven security tools raise accountability questions and fuel the AI arms race between defenders and attackers.
- May 22, 2026
22 May'26
Verizon 2026 DBIR: 6 key takeaways for CISOs
The 2026 DBIR -- practically required reading for CISOs -- identifies critical enterprise security trends, from exploit-driven breaches to shadow AI dangers and third-party risks.
- May 15, 2026
15 May'26
Instructure cyberattack reignites ransom payment debate
Instructure struck a deal to recover its stolen data -- likely paying a hefty ransom. For CISOs, deciding whether to negotiate with cybercriminals should come down to business risk.
- May 08, 2026
08 May'26
News brief: Security worries and warnings as AI use expands
Check out the latest security news from TechTarget SearchSecurity's sister sites, Cybersecurity Dive and Dark Reading.
- May 01, 2026
01 May'26
News brief: Critical infrastructure, OT cybersecurity attacks
Check out the latest security news from TechTarget SearchSecurity's sister sites, Cybersecurity Dive and Dark Reading.
- April 24, 2026
24 Apr'26
News brief: AI woes continue for security leaders
Check out the latest security news from TechTarget SearchSecurity's sister sites, Cybersecurity Dive and Dark Reading.
- April 17, 2026
17 Apr'26
At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government
Depending on whom you ask, AI could mean the end of the world as we know it, or the beginning of a new era of ease and enlightenment in the SOC. Learn more in this video discussion.
- April 17, 2026
17 Apr'26
News brief: Microsoft security vulnerabilities revealed
Check out the latest security news from TechTarget SearchSecurity's sister sites, Cybersecurity Dive and Dark Reading.
- April 17, 2026
17 Apr'26
RSAC 2026 Conference: Key news and industry analysis
Check out SearchSecurity's RSAC 2026 guide for reports on notable presentations and breaking news at the world's biggest infosec event.
- April 10, 2026
10 Apr'26
News brief: Iranian cyberattacks target U.S. water, energy
Check out the latest security news from TechTarget SearchSecurity's sister sites, Cybersecurity Dive and Dark Reading.
- April 03, 2026
03 Apr'26
News brief: Iran cyberattacks escalate, U.S. targets named
Check out the latest security news from the Informa TechTarget team.
- March 27, 2026
27 Mar'26
News brief: U.S. absence at RSAC sparks leadership concerns
Check out the latest security news from the Informa TechTarget team.
- March 20, 2026
20 Mar'26
News brief: Stryker recovering after large-scale cyberattack
Check out the latest security news from the Informa TechTarget team.
- March 13, 2026
13 Mar'26
News brief: Risk of Iran-backed cyberattacks rising in U.S.
Check out the latest security news from the Informa TechTarget team.
- March 06, 2026
06 Mar'26
News brief: Strikes on Iran put cybersecurity teams on alert
Check out the latest security news from the Informa TechTarget team.
- January 30, 2026
30 Jan'26
News brief: Patch critical and high-severity vulnerabilities now
Check out the latest security news from the Informa TechTarget team.
- January 23, 2026
23 Jan'26
News brief: Email scams highlight need for employee vigilance
Check out the latest security news from the Informa TechTarget team.
- January 16, 2026
16 Jan'26
News brief: Security flaws put thousands of systems at risk
Check out the latest security news from the Informa TechTarget team.
- January 09, 2026
09 Jan'26
News brief: AI threats to shape 2026 cybersecurity
Check out the latest security news from the Informa TechTarget team.
- December 19, 2025
19 Dec'25
News brief: Browser security flaws pose growing risk
Check out the latest security news from the Informa TechTarget team.
- December 12, 2025
12 Dec'25
News brief: Future of security holds bigger budgets, new threats
Check out the latest security news from the Informa TechTarget team.
- December 05, 2025
05 Dec'25
News brief: RCE flaws persist as top cybersecurity threat
Check out the latest security news from the Informa TechTarget team.
- December 05, 2025
05 Dec'25
Security highlights from AWS re:Invent 2025
AWS made a handful of announcements about how it is prepping to secure increased productivity with AI.
- November 21, 2025
21 Nov'25
News brief: U.S. cyberdefenses take aim at foreign threats
Check out the latest security news from the Informa TechTarget team.
- November 14, 2025
14 Nov'25
News brief: Agentic AI disrupts security, for better or worse
Check out the latest security news from the Informa TechTarget team.
- November 07, 2025
07 Nov'25
News brief: Collaboration apps face security scrutiny -- again
Check out the latest security news from the Informa TechTarget team.
- October 31, 2025
31 Oct'25
News brief: Nation-state threats evolve and escalate
Check out the latest security news from the Informa TechTarget team.
- October 24, 2025
24 Oct'25
Cybersecurity awareness news brief: What works, what doesn't
Check out the latest security news from the Informa TechTarget team.
- October 17, 2025
17 Oct'25
News brief: National cyberdefenses under mounting pressure
Check out the latest security news from the Informa TechTarget team.
- September 26, 2025
26 Sep'25
News brief: AI cybersecurity worries mount
Check out the latest security news from the Informa TechTarget team.
- September 19, 2025
19 Sep'25
News brief: KillSec, Yurei score successful ransomware attacks
Check out the latest security news from the Informa TechTarget team.
- September 12, 2025
12 Sep'25
News brief: Salesloft Drift breach update and timeline
Check out the latest security news from the Informa TechTarget team.
- September 05, 2025
05 Sep'25
News brief: U.S. Cyber Trust Mark update and how to prepare
Check out the latest security news from the Informa TechTarget team.
- August 22, 2025
22 Aug'25
News brief: Safeguards emerge to address security for AI
Check out the latest security news from the Informa TechTarget team.
- August 08, 2025
08 Aug'25
Black Hat news: Exposed vaults, firmware flaws, AI hacks
Check out the latest security news from the Informa TechTarget team.
- August 01, 2025
01 Aug'25
News brief: Rise of AI exploits and the cost of shadow AI
Check out the latest security news from the Informa TechTarget team.
- July 25, 2025
25 Jul'25
News brief: SharePoint attacks hammer globe
Check out the latest security news from the Informa TechTarget team.
- July 18, 2025
18 Jul'25
News brief: Cyberattack trends signal security arms race
Check out the latest security news from the Informa TechTarget team.
- July 11, 2025
11 Jul'25
News brief: Hafnium, Scattered Spider hackers arrested
Check out the latest security news from the Informa TechTarget team.
- June 30, 2025
30 Jun'25
News brief: AI security threats surge as governance lags
Check out the latest security news from the Informa TechTarget team.
- June 20, 2025
20 Jun'25
News brief: LOTL attacks, spoofed sites, malicious repositories
Check out the latest security news from the Informa TechTarget team.
- June 13, 2025
13 Jun'25
News brief: Gartner Security and Risk Management Summit recap
Check out the latest security news from the Informa TechTarget team.
- June 06, 2025
06 Jun'25
News brief: CISA and partners face budget overhauls, cuts
Check out the latest security news from the Informa TechTarget team.
- May 30, 2025
30 May'25
News brief: Week's top breaches stem from third-party attacks
Check out the latest security news from the Informa TechTarget team.
- May 16, 2025
16 May'25
News brief: Patch critical SAP, Samsung and chat app flaws now
Check out the latest security news from the Informa TechTarget team.
- May 09, 2025
09 May'25
News brief: AI security risks highlighted at RSAC 2025
Check out the latest security news from the Informa TechTarget team.
- April 30, 2025
30 Apr'25
RSAC Conference 2025 video reports
We chatted on camera with attendees and presenters at RSAC 2025. Check out this video collection to get highlights from one of the world's major cybersecurity conferences.
- March 28, 2025
28 Mar'25
News brief: China-linked APTs and Russian access broker
Check out the latest security news from the Informa TechTarget team.
- March 20, 2025
20 Mar'25
Cloudflare unveils tools for safeguarding AI deployment
The cybersecurity vendor's new suite helps businesses, developers and content creators deploy AI technology at scale safely and securely.
- February 28, 2025
28 Feb'25
Microsoft targets AI deepfake cybercrime network in lawsuit
Microsoft alleges that defendants used stolen Azure OpenAI API keys and special software to bypass content guardrails and generate illicit AI deepfakes for payment.
- February 27, 2025
27 Feb'25
FBI: Lazarus Group behind $1.5 billion Bybit heist
Researchers say the heist, in which North Korean state-sponsored hackers stole funds from a cold wallet, is the biggest theft in the history of the cryptocurrency industry.
- February 27, 2025
27 Feb'25
CrowdStrike: China hacking has reached 'inflection point'
In its 2025 Global Threat Report, CrowdStrike observed an increase in China's cyber capabilities, with a focus on espionage and 'pre-positioning' itself in critical environments.
- February 26, 2025
26 Feb'25
NCC Group tracks alarming ransomware surge in January
NCC Group found ransomware activity in January surpassed previous monthly highs with 590 attacks, as one notorious gang experienced a notable resurgence.
- February 25, 2025
25 Feb'25
Black Basta ransomware leak sheds light on targets, tactics
VulnCheck found the ransomware gang targeted CVEs in popular enterprise products from Microsoft, Citrix, Cisco, Fortinet, Palo Alto Networks, Confluence Atlassian and more.
- February 25, 2025
25 Feb'25
Dragos: Ransomware attacks against industrial orgs up 87%
Ransomware attacks continue to be a major pain point for industrial organizations, as the sector has historically struggled with vulnerability management.
- February 24, 2025
24 Feb'25
Apple pulls Advanced Data Protection in UK, sparking concerns
Privacy and security concerns mount, as Apple pulls the end-to-end encryption feature for users located in the U.K. following pressures from the government.
- February 21, 2025
21 Feb'25
Palo Alto Networks vulnerabilities exploited in chained attack
The cybersecurity vendor urges customers to take immediate action to mitigate recently disclosed vulnerabilities that are being actively exploited in the wild.
- February 20, 2025
20 Feb'25
Risk & Repeat: Salt Typhoon hasn't stopped hacking
Although the Salt Typhoon telecom breaches from last year appear to have been remediated, the Chinese state-sponsored threat group continues to target critical organizations.
- February 20, 2025
20 Feb'25
CISA, FBI warn of Ghost/Cring ransomware attacks
Ghost is a China-based financially motivated ransomware group that has launched attacks against organizations in more than 70 countries -- including its own.
- February 18, 2025
18 Feb'25
Palo Alto Networks PAN-OS vulnerability exploited in the wild
Palo Alto Networks says threat actors used a publicly available PoC exploit in attack attempts against firewall customers with PAN-OS management interfaces exposed to the internet.
- February 13, 2025
13 Feb'25
Salt Typhoon compromises telecom providers' Cisco devices
Salt Typhoon's latest campaign exploits older vulnerabilities in Cisco edge devices to gain access to the networks of several telecom companies, including two based in the U.S.
- February 12, 2025
12 Feb'25
Fortinet discloses second authentication bypass vulnerability
Fortinet disclosed CVE-2025-24472 in an updated advisory that confused some in the infosec community because it stated that 'reports show this is being exploited in the wild.'
- February 11, 2025
11 Feb'25
Apple zero day used in 'extremely sophisticated attack'
CVE-2025-24200 is a zero-day vulnerability that bypasses Apple's USB Restricted Mode in iPhones and iPads and was exploited in the wild against 'specific targeted individuals.'
- February 10, 2025
10 Feb'25
Trimble Cityworks zero-day flaw under attack, patch now
CVE-2025-0994 is a high-severity deserialization vulnerability that enables remote code execution in unpatched versions of Cityworks enterprise asset management software.
- February 07, 2025
07 Feb'25
Ransomware hits healthcare, critical services in January
Ransomware attacks against healthcare organizations in January reflect an increasing need for threat actors to adapt and get aggressive as defenders improve.
- February 06, 2025
06 Feb'25
Unpatched.ai: Who runs the vulnerability discovery platform?
There is limited information on the AI-powered vulnerability discovery platform that emerged in December after it reported Microsoft vulnerabilities
- February 05, 2025
05 Feb'25
Zyxel won't patch end-of-life routers against zero-day attacks
Networking hardware vendor Zyxel has no plans to patch multiple end-of-life routers against new zero-day flaws and advises customers to replace affected devices entirely.
- February 05, 2025
05 Feb'25
Chainalysis records 35% decrease in ransom payments in 2024
While the first half of 2024 was on pace to surpass 2023's record-setting numbers, Chainalysis found that the volume of ransom payments dropped in the second half of the year.
- February 04, 2025
04 Feb'25
AMD, Google disclose Zen processor microcode vulnerability
AMD said CVE-2024-56161, which first leaked last month, requires an attacker to have local administrator privileges as well as developed and executed malicious microcode.
- February 04, 2025
04 Feb'25
WatchTowr warns abandoned S3 buckets pose supply chain risk
WatchTowr researchers found that they could reregister abandoned Amazon S3 buckets and detail alarming ways that threat actors could exploit the attack surface.
- February 03, 2025
03 Feb'25
NSFocus: DeepSeek AI hit with 'well planned' DDoS attacks
Cybersecurity vendor NSFocus said AI startup DeepSeek endured multiple waves of DDoS attacks from attackers since its reasoning model was released Jan. 20.
- January 30, 2025
30 Jan'25
Risk & Repeat: DeepSeek security issues emerge
The introduction of DeepSeek's new generative AI models has been met with fervor, but security issues have created apparent challenges for the Chinese startup.
- January 30, 2025
30 Jan'25
Wiz reveals DeepSeek database exposed API keys, chat history
Wiz expressed concern about security shortcomings with AI tools and services amid the rapid adoption and rising popularity of offerings like DeepSeek-R1.
- January 30, 2025
30 Jan'25
German police disrupt Cracked, Nulled cybercrime forums
Cracked and Nulled had a combined community of approximately 10 million users who used the sites to discuss cybercrime and sell malware and hacking tools.
- January 29, 2025
29 Jan'25
Google details adversarial AI activity on Gemini
Google identified APTs from more than 20 nations misusing its Gemini AI chatbot but noted that threat actors were unsuccessful in finding novel techniques or vulnerabilities.
- January 28, 2025
28 Jan'25
DeepSeek claims 'malicious attacks' disrupting AI service
DeepSeek, which gained popularity recently for its AI platform, did not specify the cause of 'large-scale malicious attacks,' which continue to disrupt new account registrations.
- January 28, 2025
28 Jan'25
Apple zero-day vulnerability under attack on iOS devices
Apple said the zero-day vulnerability, tracked as CVE-2025-24085, affects its CoreMedia framework and 'may have been actively exploited against versions of iOS before iOS 17.2.'
- January 27, 2025
27 Jan'25
Former CSRB members largely silent on dismissal
The Cyber Safety Review Board was investigating recent attacks by Chinese state-sponsored threat actor Salt Typhoon when DHS terminated all advisory board memberships.
- January 24, 2025
24 Jan'25
DOJ indicts 5 individuals in North Korea IT worker scam
An unsealed indictment revealed threat actors working for North Korea tricked at least 64 U.S. businesses into hiring fake IT workers for financial and propriety data gains.
- January 24, 2025
24 Jan'25
AMD processor vulnerability inadvertently leaked early
The flaw was revealed when hardware manufacturer Asus published a patch for an 'AMD Microcode Signature Verification Vulnerability' to a gaming motherboard update page.
- January 23, 2025
23 Jan'25
Zero-day vulnerability in SonicWall SMA series under attack
SonicWall released a hotfix for a critical pre-authentication remote code execution vulnerability in Secure Mobile Access 1000 products amidst reports of zero-day exploitation.