The Latest
-
Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
High-profile CISA departure adds to agency’s struggles
The Trump administration’s workforce purge is sapping CISA of its best talent, experts say. CISA deputy Matt Hartman is the latest to leave the agency.
-
Major tech vendors call for streamlining US foreign cyber aid
A new coalition will push policymakers to change how the government oversees foreign purchases of U.S. cyber resources.
Updated May 21, 2025 -
Researchers warn of China-backed espionage campaign targeting laid-off US workers
A report by FDD says an elaborate online recruiting effort is using LinkedIn and fake online companies to gather sensitive intelligence.
-
Ivanti Endpoint Mobile Manager customers exploited via chained vulnerabilities
The company said additional CVEs may be necessary for flaws in related open-source libraries, but researchers are raising questions.
Updated May 20, 2025 -
Hack could cost Coinbase up to $400M: filing
The crypto exchange is offering a $20 million reward for information leading to the hackers’ arrest. Coinbase terminated customer support agents who leaked customer data.
-
Hearing shows broad support for extension of cyber info-sharing law
With bipartisan support and backing from the private sector, the 2015 law appears to be on a glide path to reauthorization.
-
Opinion
How hospitality companies can stay ahead of cyberattacks this summer
Hotels are a popular target for cyberattacks, but industry collaboration and intelligence sharing can serve as defense mechanisms.
-
FBI warns senior US officials are being impersonated using texts, AI-based voice cloning
Hackers are increasingly using vishing and smishing for state-backed espionage campaigns and major ransomware attacks.
-
Researchers warn threat actors in UK retail attacks are targeting US sector
Google Threat Intelligence researchers say the hackers behind intrusions at multiple British retailers are launching similar social engineering attacks against American companies.
-
Steelmaker Nucor discloses cyberattack on IT network
The company halted production at various locations and took potentially affected systems offline.
-
GOP lawmakers urge ban of networking vendor TP-Link, citing ties to China
The Trump administration is facing mounting pressure to formulate a strategy for addressing supply-chain threats that endanger national security.
-
Congress faces pressure to renew cyber information-sharing law
The law’s expiration in September could jeopardize a wide range of information-sharing partnerships that have helped catch and thwart cyberattacks in the U.S.
-
UK retailer Co-op restoring systems following major cyberattack
The company is carefully ramping up systems and is boosting deliveries to its 2,300 food stores after stock issues.
-
M&S says hackers gained access to customer data in April cyberattack
The UK retailer said the payment data was masked and therefore not usable.
-
China helps North Korean operatives land IT roles, bypassing sanctions
One Chinese company with at least 35 affiliates has shipped IT equipment to a North Korean government-backed organization.
Updated May 14, 2025 -
Lee Enterprises spent $2M for ransomware recovery
The newspaper chain said the attack will have lingering impacts on its balance sheet, and its lender waived certain payments.
-
PowerSchool data breach leads to school extortion attempts
A threat actor has contacted multiple school districts demanding payments related to student and staff data stolen in a December breach.
-
SAP NetWeaver exploitation enters second wave of threat activity
Researchers are tracking hundreds of cases around the world and warning that the risk is more serious than previously known.
-
Defense contractors get a head start on CMMC audits
Software investments, infrastructure upgrades and compliance documentation topped the list of Cybersecurity Maturity Model Certification implementation costs, a new survey shows.
-
CISA, FBI warn of ‘unsophisticated’ hackers targeting industrial systems
Federal authorities, including the EPA and the U.S. Department of Energy, urged network defenders to secure remote access and use stronger passwords.
-
Ransomware claims dipped slightly in 2024, cyber insurer says
A major cyber insurer’s annual report lays out how hackers are trying to steal money and how its policyholders responded.
-
CrowdStrike to cut 500 jobs in plan to scale business
The cybersecurity firm has faced increasing market pressures amid a scramble by rivals to consolidate enterprise customers on unified platforms.
Updated May 8, 2025 -
Masimo says cyberattack has impacted its ability to fulfill orders
The maker of patient monitoring devices does not currently expect to change its earnings guidance.
-
Retrieved from R. Eskalis/NIST.
NIST loses key cyber experts in standards and research
The head of the agency’s Computer Security Division and roughly a dozen of his subordinates took the Trump administration’s retirement offers, placing key programs at risk.
-
Airlines in North America prioritize investments in cyber, AI
Spending plans come amid rising concerns over third-party cyber risk.