Sign in

Cybersecurity Dive

@cybersecuritydive.bsky.social
321 followers 5 following 653 posts

We provide business journalism into the most impactful news and trends shaping cybersecurity.

PostsRepliesMedia
Cybersecurity Dive @cybersecuritydive.bsky.social · 6h
National cyber director defends private-sector hacking program, urges focus on security basics: www.cybersecuritydive.com/news/oncd-wh... (by @ericjgeller.com)
cybersecuritydive.com
National cyber director defends private-sector hacking program, urges focus on security basics
Letting businesses help the government deter cybercrime will benefit all Americans, Sean Cairncross said.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 29/09/2026
Citrix NetScaler exploitation began days before public notification: www.cybersecuritydive.com/news/citrix-... (by David Jones)
cybersecuritydive.com
Citrix NetScaler exploitation began days before public notification
Customers need to check systems for compromise prior to patching, because the security upgrade may not fully resolve an infected system.
001
Cybersecurity Dive @cybersecuritydive.bsky.social · 29/09/2026
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations: www.cybersecuritydive.com/news/cyberse... (by @ericjgeller.com)
cybersecuritydive.com
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations
Representatives of three critical infrastructure sectors identified the conflicting and redundant rules that they said made their jobs much more difficult.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 29/09/2026
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts: www.cybersecuritydive.com/news/citrix-... (by David Jones)
cybersecuritydive.com
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
Security teams received urgent calls to disconnect servers before authorities confirmed critical zero-day flaws.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 28/09/2026
Kiteworks lifts advisory after precautionary warning for customers to shut down systems: www.cybersecuritydive.com/news/kitewor... (by David Jones)
cybersecuritydive.com
Kiteworks lifts advisory after precautionary warning for customers to shut down systems
The firm had received information from law enforcement of a possible attack.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 28/09/2026
Niche AI tools pose major cybersecurity risk to infrastructure operators: www.cybersecuritydive.com/news/ai-apps... (by @ericjgeller.com)
cybersecuritydive.com
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/09/2026
Threat groups ramp up social-engineering attacks against healthcare sector: www.cybersecuritydive.com/news/threat-... (by David Jones)
cybersecuritydive.com
Threat groups ramp up social-engineering attacks against healthcare sector
Hackers linked to high-profile cybercrime groups have used voice-phishing tactics to trick workers into giving up credentials in recent attacks.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/09/2026
Businesses expand AI’s cybersecurity uses as comfort with technology grows: www.cybersecuritydive.com/news/ai-cybe... (by @ericjgeller.com)
cybersecuritydive.com
Businesses expand AI’s cybersecurity uses as comfort with technology grows
Companies in the experimentation stage were less likely than established users to deploy advanced AI-powered defenses, a new survey found.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/09/2026
Rogue OpenAI agent targeted Australian government site: www.cybersecuritydive.com/news/rogue-o... (by David Jones)
cybersecuritydive.com
Rogue OpenAI agent targeted Australian government site
The prime minister rebuked the company for its slow response and warned that AI poses significant risks that need to be further addressed.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 24/09/2026
Wiz uses AI to find vulnerabilities in railroads, hospitals and other critical infrastructure: www.cybersecuritydive.com/news/wiz-ai-... (by @ericjgeller.com)
cybersecuritydive.com
Wiz uses AI to find vulnerabilities in railroads, hospitals and other critical infrastructure
The Google subsidiary invited all infrastructure operators to apply for its free scanning service.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 23/09/2026
FBI probes cyberattack tied to third-party jobs portal: www.cybersecuritydive.com/news/fbi-hac... (by @ericjgeller.com)
cybersecuritydive.com
FBI probes cyberattack tied to third-party jobs portal
The potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 23/09/2026
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries: www.cybersecuritydive.com/news/cyberse... (by @ericjgeller.com)
cybersecuritydive.com
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries
Many companies still aren’t preparing thoroughly enough to face a hack, the insurance firm Travelers said in a new report.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 23/09/2026
Industrial leaders face cyber resilience gap as attacks shake confidence: www.cybersecuritydive.com/news/industr... (by David Jones)
cybersecuritydive.com
Industrial leaders face cyber resilience gap as attacks shake confidence
More than one-third of organizations consider cyber risk as the top obstacle to growth.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 22/09/2026
Retailers tamp down shadow AI but struggle to oversee agentic sprawl: www.cybersecuritydive.com/news/retail-... (by @ericjgeller.com)
cybersecuritydive.com
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
The use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/09/2026
Google AI models broke out of sandbox, hacked three companies: www.cybersecuritydive.com/news/google-... (by @ericjgeller.com)
cybersecuritydive.com
Google AI models broke out of sandbox, hacked three companies
The incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/09/2026
China-nexus actor steals thousands of documents in monthslong exploitation campaign: www.cybersecuritydive.com/news/china-n... (by David Jones)
cybersecuritydive.com
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Researchers suspect the hacker employed LLMs to develop custom tools.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 18/09/2026
Settra ransomware variant deployed in recent attacks: www.cybersecuritydive.com/news/settra-... (by David Jones)
cybersecuritydive.com
Settra ransomware variant deployed in recent attacks
Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 18/09/2026
CISA ends weekly vulnerability roundups as part of shift to prioritization approach: www.cybersecuritydive.com/news/cisa-vu... (by @ericjgeller.com)
cybersecuritydive.com
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 17/09/2026
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters: www.cybersecuritydive.com/news/fbi-coa... (by David Jones)
cybersecuritydive.com
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
The investigation comes at a time of heightened vigilance over U.S. port facilities and maritime security.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 17/09/2026
Manufacturers make patching progress, but identity management still major weakness: www.cybersecuritydive.com/news/manufac... (by @ericjgeller.com)
cybersecuritydive.com
Manufacturers make patching progress, but identity management still major weakness
Misconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 16/09/2026
Hackers exploit zero-day flaw in Cisco email gateway: www.cybersecuritydive.com/news/hackers... (by David Jones)
cybersecuritydive.com
Hackers exploit zero-day flaw in Cisco email gateway
Researchers warn the vulnerability could be used by state-linked actors for espionage.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 16/09/2026
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers: www.cybersecuritydive.com/news/cisa-cr... (by @ericjgeller.com)
cybersecuritydive.com
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
“I need people that can pivot from day to day,” the agency’s acting chief told reporters.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 15/09/2026
Companies’ AI strategies don’t account for their agentic tools: www.cybersecuritydive.com/news/ai-gove... (by @ericjgeller.com)
cybersecuritydive.com
Companies’ AI strategies don’t account for their agentic tools
Businesses are taking AI governance seriously, but their plans lag behind the technology they’re using, according to an EY survey.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 14/09/2026
Security teams increasingly outflanked by AI agents: www.cybersecuritydive.com/news/securit... (by David Jones)
cybersecuritydive.com
Security teams increasingly outflanked by AI agents
A report warns that non-human identities are growing beyond the ability of existing systems to track.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 14/09/2026
Malicious actors already using critical GitLab flaw, CISA and others warn: www.cybersecuritydive.com/news/gitlab-... (by @ericjgeller.com)
cybersecuritydive.com
Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments.
020
Cybersecurity Dive @cybersecuritydive.bsky.social · 11/09/2026
State authorities warn they lack resources to address cyber threat to critical sectors: www.cybersecuritydive.com/news/state-i... (by David Jones)
cybersecuritydive.com
State authorities warn they lack resources to address cyber threat to critical sectors
A report shows that state CIOs and CISOs need additional funding, personnel and training to protect water, energy and healthcare.
100
Cybersecurity Dive @cybersecuritydive.bsky.social · 11/09/2026
Accountability, oversight and AI: Inside Microsoft’s security transformation: www.cybersecuritydive.com/news/microso... (by @ericjgeller.com)
cybersecuritydive.com
Accountability, oversight and AI: Inside Microsoft’s security transformation
Stung by years of embarrassing hacks, the tech giant overhauled how it approached cybersecurity. Company leaders now say they’re seeing results.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
Threat groups enhance cyberattack capabilities with AI: www.cybersecuritydive.com/news/threat-... (by David Jones)
cybersecuritydive.com
Threat groups enhance cyberattack capabilities with AI
A report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
White House sees water cybersecurity partnership in Texas as national blueprint: www.cybersecuritydive.com/news/water-c... (by @ericjgeller.com)
cybersecuritydive.com
White House sees water cybersecurity partnership in Texas as national blueprint
A top cybersecurity official said the government was taking a new approach to protecting critical infrastructure.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
How AI anxieties dominated the summer’s big cybersecurity conference: www.cybersecuritydive.com/news/black-h... (by @ericjgeller.com)
cybersecuritydive.com
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology’s next evolution.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
CISA is on the verge of filling hundreds of critical vacancies: www.cybersecuritydive.com/news/cisa-hi... (by @ericjgeller.com)
cybersecuritydive.com
CISA is on the verge of filling hundreds of critical vacancies
Meanwhile, the agency is finalizing an incident-reporting regulation and setting up a new industry coordination structure.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 09/09/2026
CISOs are feeling the security burden of accelerated AI use: www.cybersecuritydive.com/news/cisos-f... (by David Jones)
cybersecuritydive.com
CISOs are feeling the security burden of accelerated AI use
A report shows CISOs face increased pressures related to cyber resilience and business continuity.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 09/09/2026
New FBI cyber strategy promises increase in adversary disruptions: www.cybersecuritydive.com/news/fbi-cyb... (by @ericjgeller.com)
cybersecuritydive.com
New FBI cyber strategy promises increase in adversary disruptions
The document also focuses on helping victims, reflecting the bureau’s attempt to encourage more companies to share information with it.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 09/09/2026
N-able issues patch for zero-day flaw: www.cybersecuritydive.com/news/n-able-... (by David Jones)
cybersecuritydive.com
N-able issues patch for zero-day flaw
Security researchers warned the company of unusual threat activity in a recently patched N-able environment.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 08/09/2026
Don’t let AI distract from cybersecurity basics, officials and executives warn: www.cybersecuritydive.com/news/ai-cybe... (by @ericjgeller.com)
cybersecuritydive.com
Don’t let AI distract from cybersecurity basics, officials and executives warn
Simple attacks remain far more consequential than anything AI is doing, government and industry leaders said.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 03/09/2026
Government lacks ability to verify AI labs’ claims, experts say: www.cybersecuritydive.com/news/ai-nati... (by @ericjgeller.com)
cybersecuritydive.com
Government lacks ability to verify AI labs’ claims, experts say
A new survey of national security practitioners identified a wide range of near- and medium-term AI risks for policymakers to consider.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 03/09/2026
SonicWall urges immediate patching of chained vulnerabilities: www.cybersecuritydive.com/news/sonicwa... (by David Jones)
cybersecuritydive.com
SonicWall urges immediate patching of chained vulnerabilities
Just weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 03/09/2026
Government, industry partner to shut down long-running Sality botnet: www.cybersecuritydive.com/news/doj-cro... (by @ericjgeller.com)
cybersecuritydive.com
Government, industry partner to shut down long-running Sality botnet
A nonprofit group is now working to contact the botnet’s victims.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 02/09/2026
CISA scraps 6 free cybersecurity assessments for critical infrastructure operators: www.cybersecuritydive.com/news/cisa-cy... (by @ericjgeller.com)
cybersecuritydive.com
CISA scraps 6 free cybersecurity assessments for critical infrastructure operators
The agency’s decision, spurred by workload concerns, could leave organizations without valuable insights into their vulnerabilities.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/08/2026
CISA orders agencies to fix exploited Zimbra vulnerability: www.cybersecuritydive.com/news/cisa-zi... (by @ericjgeller.com)
cybersecuritydive.com
CISA orders agencies to fix exploited Zimbra vulnerability
The collaboration software’s developer took almost a full month to patch the flaw after disclosing it.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/08/2026
Researchers warn about chained SharePoint sequence: www.cybersecuritydive.com/news/researc... (by David Jones)
cybersecuritydive.com
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 24/08/2026
House Democrats ask GAO to study CISA workforce cuts: www.cybersecuritydive.com/news/cisa-wo... (by @ericjgeller.com)
cybersecuritydive.com
House Democrats ask GAO to study CISA workforce cuts
The five lawmakers, who serve on the Homeland Security Committee, said Congress didn’t know enough about the Trump administration’s changes to the cybersecurity agency.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 24/08/2026
UK power facility disabled for days after suspected state-linked cyberattack: www.cybersecuritydive.com/news/uk-powe... (by David Jones)
cybersecuritydive.com
UK power facility disabled for days after suspected state-linked cyberattack
The disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/08/2026
Microsoft confirms maximum severity flaw in Entra ID targeted for exploitation: www.cybersecuritydive.com/news/microso... (by David Jones)
cybersecuritydive.com
Microsoft confirms maximum severity flaw in Entra ID targeted for exploitation
The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/08/2026
Defense contractors’ CMMC confidence lags, even as self-assessments improve: www.cybersecuritydive.com/news/defense... (by @ericjgeller.com)
cybersecuritydive.com
Defense contractors’ CMMC confidence lags, even as self-assessments improve
A “confidence disconnect” is plaguing the industry, a consulting firm said.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 20/08/2026
What we know so far about the hacking campaign against US water systems: www.cybersecuritydive.com/news/what-we... (by David Jones)
cybersecuritydive.com
What we know so far about the hacking campaign against US water systems
Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 20/08/2026
Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks: www.cybersecuritydive.com/news/water-h... (by @ericjgeller.com)
cybersecuritydive.com
Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 19/08/2026
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn: www.cybersecuritydive.com/news/ai-hack... (by David Jones)
cybersecuritydive.com
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 19/08/2026
Ransomware disproportionately targets medium-sized firms, straining customer relationships: www.cybersecuritydive.com/news/ransomw... (by @ericjgeller.com)
cybersecuritydive.com
Ransomware disproportionately targets medium-sized firms, straining customer relationships
These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 19/08/2026
DOJ charges 17 people in Iran-backed hacking campaign against US: www.cybersecuritydive.com/news/doj-cha... (by David Jones)
cybersecuritydive.com
DOJ charges 17 people in Iran-backed hacking campaign against US
Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.
001