Sign in

Cybersecurity Dive

@cybersecuritydive.bsky.social
324 followers 5 following 658 posts

We provide business journalism into the most impactful news and trends shaping cybersecurity.

PostsRepliesMedia
Cybersecurity Dive @cybersecuritydive.bsky.social · 02/10/2026
Fortinet warns that critical flaw in FortiMail is facing exploitation: www.cybersecuritydive.com/news/fortine... (by David Jones)
cybersecuritydive.com
Fortinet warns that critical flaw in FortiMail is facing exploitation
Security researchers said that attackers can gain access to credentials, stored mail and other connected systems.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 02/10/2026
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says: www.cybersecuritydive.com/news/ai-cybe... (by @ericjgeller.com)
cybersecuritydive.com
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
The company’s latest report previews how AI is changing threat activity, including by automating ransomware attacks.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 01/10/2026
State-linked actor targets U.S. AI policy experts in credential phishing campaigns: www.cybersecuritydive.com/news/state-l... (by David Jones)
cybersecuritydive.com
State-linked actor targets US AI policy experts in credential phishing campaigns
The China-linked espionage attacks were designed to gain insight into the country’s strategy and regulatory environment.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 01/10/2026
SOC staffers generally pleased with AI’s impact, but worries remain: www.cybersecuritydive.com/news/ai-secu... (by @ericjgeller.com)
cybersecuritydive.com
SOC staffers generally pleased with AI’s impact, but worries remain
AI is likely to eliminate some entry-level SOC roles, a survey found, but it is also creating opportunities to develop more strategic skills.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 01/10/2026
Mass exploitation of Citrix NetScaler: What we currently know: www.cybersecuritydive.com/news/exploit... (by David Jones)
cybersecuritydive.com
Mass exploitation of Citrix NetScaler: What we currently know
Suspected state-linked actors targeted critical vulnerabilities in the widely used platform, causing widespread disruption across Europe and North America.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 30/09/2026
National cyber director defends private-sector hacking program, urges focus on security basics: www.cybersecuritydive.com/news/oncd-wh... (by @ericjgeller.com)
cybersecuritydive.com
National cyber director defends private-sector hacking program, urges focus on security basics
Letting businesses help the government deter cybercrime will benefit all Americans, Sean Cairncross said.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 29/09/2026
Citrix NetScaler exploitation began days before public notification: www.cybersecuritydive.com/news/citrix-... (by David Jones)
cybersecuritydive.com
Citrix NetScaler exploitation began days before public notification
Customers need to check systems for compromise prior to patching, because the security upgrade may not fully resolve an infected system.
001
Cybersecurity Dive @cybersecuritydive.bsky.social · 29/09/2026
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations: www.cybersecuritydive.com/news/cyberse... (by @ericjgeller.com)
cybersecuritydive.com
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations
Representatives of three critical infrastructure sectors identified the conflicting and redundant rules that they said made their jobs much more difficult.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 29/09/2026
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts: www.cybersecuritydive.com/news/citrix-... (by David Jones)
cybersecuritydive.com
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
Security teams received urgent calls to disconnect servers before authorities confirmed critical zero-day flaws.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 28/09/2026
Kiteworks lifts advisory after precautionary warning for customers to shut down systems: www.cybersecuritydive.com/news/kitewor... (by David Jones)
cybersecuritydive.com
Kiteworks lifts advisory after precautionary warning for customers to shut down systems
The firm had received information from law enforcement of a possible attack.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 28/09/2026
Niche AI tools pose major cybersecurity risk to infrastructure operators: www.cybersecuritydive.com/news/ai-apps... (by @ericjgeller.com)
cybersecuritydive.com
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/09/2026
Threat groups ramp up social-engineering attacks against healthcare sector: www.cybersecuritydive.com/news/threat-... (by David Jones)
cybersecuritydive.com
Threat groups ramp up social-engineering attacks against healthcare sector
Hackers linked to high-profile cybercrime groups have used voice-phishing tactics to trick workers into giving up credentials in recent attacks.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/09/2026
Businesses expand AI’s cybersecurity uses as comfort with technology grows: www.cybersecuritydive.com/news/ai-cybe... (by @ericjgeller.com)
cybersecuritydive.com
Businesses expand AI’s cybersecurity uses as comfort with technology grows
Companies in the experimentation stage were less likely than established users to deploy advanced AI-powered defenses, a new survey found.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/09/2026
Rogue OpenAI agent targeted Australian government site: www.cybersecuritydive.com/news/rogue-o... (by David Jones)
cybersecuritydive.com
Rogue OpenAI agent targeted Australian government site
The prime minister rebuked the company for its slow response and warned that AI poses significant risks that need to be further addressed.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 24/09/2026
Wiz uses AI to find vulnerabilities in railroads, hospitals and other critical infrastructure: www.cybersecuritydive.com/news/wiz-ai-... (by @ericjgeller.com)
cybersecuritydive.com
Wiz uses AI to find vulnerabilities in railroads, hospitals and other critical infrastructure
The Google subsidiary invited all infrastructure operators to apply for its free scanning service.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 23/09/2026
FBI probes cyberattack tied to third-party jobs portal: www.cybersecuritydive.com/news/fbi-hac... (by @ericjgeller.com)
cybersecuritydive.com
FBI probes cyberattack tied to third-party jobs portal
The potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 23/09/2026
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries: www.cybersecuritydive.com/news/cyberse... (by @ericjgeller.com)
cybersecuritydive.com
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries
Many companies still aren’t preparing thoroughly enough to face a hack, the insurance firm Travelers said in a new report.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 23/09/2026
Industrial leaders face cyber resilience gap as attacks shake confidence: www.cybersecuritydive.com/news/industr... (by David Jones)
cybersecuritydive.com
Industrial leaders face cyber resilience gap as attacks shake confidence
More than one-third of organizations consider cyber risk as the top obstacle to growth.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 22/09/2026
Retailers tamp down shadow AI but struggle to oversee agentic sprawl: www.cybersecuritydive.com/news/retail-... (by @ericjgeller.com)
cybersecuritydive.com
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
The use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/09/2026
Google AI models broke out of sandbox, hacked three companies: www.cybersecuritydive.com/news/google-... (by @ericjgeller.com)
cybersecuritydive.com
Google AI models broke out of sandbox, hacked three companies
The incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/09/2026
China-nexus actor steals thousands of documents in monthslong exploitation campaign: www.cybersecuritydive.com/news/china-n... (by David Jones)
cybersecuritydive.com
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Researchers suspect the hacker employed LLMs to develop custom tools.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 18/09/2026
Settra ransomware variant deployed in recent attacks: www.cybersecuritydive.com/news/settra-... (by David Jones)
cybersecuritydive.com
Settra ransomware variant deployed in recent attacks
Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 18/09/2026
CISA ends weekly vulnerability roundups as part of shift to prioritization approach: www.cybersecuritydive.com/news/cisa-vu... (by @ericjgeller.com)
cybersecuritydive.com
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 17/09/2026
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters: www.cybersecuritydive.com/news/fbi-coa... (by David Jones)
cybersecuritydive.com
FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
The investigation comes at a time of heightened vigilance over U.S. port facilities and maritime security.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 17/09/2026
Manufacturers make patching progress, but identity management still major weakness: www.cybersecuritydive.com/news/manufac... (by @ericjgeller.com)
cybersecuritydive.com
Manufacturers make patching progress, but identity management still major weakness
Misconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 16/09/2026
Hackers exploit zero-day flaw in Cisco email gateway: www.cybersecuritydive.com/news/hackers... (by David Jones)
cybersecuritydive.com
Hackers exploit zero-day flaw in Cisco email gateway
Researchers warn the vulnerability could be used by state-linked actors for espionage.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 16/09/2026
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers: www.cybersecuritydive.com/news/cisa-cr... (by @ericjgeller.com)
cybersecuritydive.com
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
“I need people that can pivot from day to day,” the agency’s acting chief told reporters.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 15/09/2026
Companies’ AI strategies don’t account for their agentic tools: www.cybersecuritydive.com/news/ai-gove... (by @ericjgeller.com)
cybersecuritydive.com
Companies’ AI strategies don’t account for their agentic tools
Businesses are taking AI governance seriously, but their plans lag behind the technology they’re using, according to an EY survey.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 14/09/2026
Security teams increasingly outflanked by AI agents: www.cybersecuritydive.com/news/securit... (by David Jones)
cybersecuritydive.com
Security teams increasingly outflanked by AI agents
A report warns that non-human identities are growing beyond the ability of existing systems to track.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 14/09/2026
Malicious actors already using critical GitLab flaw, CISA and others warn: www.cybersecuritydive.com/news/gitlab-... (by @ericjgeller.com)
cybersecuritydive.com
Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments.
020
Cybersecurity Dive @cybersecuritydive.bsky.social · 11/09/2026
State authorities warn they lack resources to address cyber threat to critical sectors: www.cybersecuritydive.com/news/state-i... (by David Jones)
cybersecuritydive.com
State authorities warn they lack resources to address cyber threat to critical sectors
A report shows that state CIOs and CISOs need additional funding, personnel and training to protect water, energy and healthcare.
100
Cybersecurity Dive @cybersecuritydive.bsky.social · 11/09/2026
Accountability, oversight and AI: Inside Microsoft’s security transformation: www.cybersecuritydive.com/news/microso... (by @ericjgeller.com)
cybersecuritydive.com
Accountability, oversight and AI: Inside Microsoft’s security transformation
Stung by years of embarrassing hacks, the tech giant overhauled how it approached cybersecurity. Company leaders now say they’re seeing results.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
Threat groups enhance cyberattack capabilities with AI: www.cybersecuritydive.com/news/threat-... (by David Jones)
cybersecuritydive.com
Threat groups enhance cyberattack capabilities with AI
A report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
White House sees water cybersecurity partnership in Texas as national blueprint: www.cybersecuritydive.com/news/water-c... (by @ericjgeller.com)
cybersecuritydive.com
White House sees water cybersecurity partnership in Texas as national blueprint
A top cybersecurity official said the government was taking a new approach to protecting critical infrastructure.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
How AI anxieties dominated the summer’s big cybersecurity conference: www.cybersecuritydive.com/news/black-h... (by @ericjgeller.com)
cybersecuritydive.com
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology’s next evolution.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 10/09/2026
CISA is on the verge of filling hundreds of critical vacancies: www.cybersecuritydive.com/news/cisa-hi... (by @ericjgeller.com)
cybersecuritydive.com
CISA is on the verge of filling hundreds of critical vacancies
Meanwhile, the agency is finalizing an incident-reporting regulation and setting up a new industry coordination structure.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 09/09/2026
CISOs are feeling the security burden of accelerated AI use: www.cybersecuritydive.com/news/cisos-f... (by David Jones)
cybersecuritydive.com
CISOs are feeling the security burden of accelerated AI use
A report shows CISOs face increased pressures related to cyber resilience and business continuity.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 09/09/2026
New FBI cyber strategy promises increase in adversary disruptions: www.cybersecuritydive.com/news/fbi-cyb... (by @ericjgeller.com)
cybersecuritydive.com
New FBI cyber strategy promises increase in adversary disruptions
The document also focuses on helping victims, reflecting the bureau’s attempt to encourage more companies to share information with it.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 09/09/2026
N-able issues patch for zero-day flaw: www.cybersecuritydive.com/news/n-able-... (by David Jones)
cybersecuritydive.com
N-able issues patch for zero-day flaw
Security researchers warned the company of unusual threat activity in a recently patched N-able environment.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 08/09/2026
Don’t let AI distract from cybersecurity basics, officials and executives warn: www.cybersecuritydive.com/news/ai-cybe... (by @ericjgeller.com)
cybersecuritydive.com
Don’t let AI distract from cybersecurity basics, officials and executives warn
Simple attacks remain far more consequential than anything AI is doing, government and industry leaders said.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 03/09/2026
Government lacks ability to verify AI labs’ claims, experts say: www.cybersecuritydive.com/news/ai-nati... (by @ericjgeller.com)
cybersecuritydive.com
Government lacks ability to verify AI labs’ claims, experts say
A new survey of national security practitioners identified a wide range of near- and medium-term AI risks for policymakers to consider.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 03/09/2026
SonicWall urges immediate patching of chained vulnerabilities: www.cybersecuritydive.com/news/sonicwa... (by David Jones)
cybersecuritydive.com
SonicWall urges immediate patching of chained vulnerabilities
Just weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 03/09/2026
Government, industry partner to shut down long-running Sality botnet: www.cybersecuritydive.com/news/doj-cro... (by @ericjgeller.com)
cybersecuritydive.com
Government, industry partner to shut down long-running Sality botnet
A nonprofit group is now working to contact the botnet’s victims.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 02/09/2026
CISA scraps 6 free cybersecurity assessments for critical infrastructure operators: www.cybersecuritydive.com/news/cisa-cy... (by @ericjgeller.com)
cybersecuritydive.com
CISA scraps 6 free cybersecurity assessments for critical infrastructure operators
The agency’s decision, spurred by workload concerns, could leave organizations without valuable insights into their vulnerabilities.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/08/2026
CISA orders agencies to fix exploited Zimbra vulnerability: www.cybersecuritydive.com/news/cisa-zi... (by @ericjgeller.com)
cybersecuritydive.com
CISA orders agencies to fix exploited Zimbra vulnerability
The collaboration software’s developer took almost a full month to patch the flaw after disclosing it.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 25/08/2026
Researchers warn about chained SharePoint sequence: www.cybersecuritydive.com/news/researc... (by David Jones)
cybersecuritydive.com
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 24/08/2026
House Democrats ask GAO to study CISA workforce cuts: www.cybersecuritydive.com/news/cisa-wo... (by @ericjgeller.com)
cybersecuritydive.com
House Democrats ask GAO to study CISA workforce cuts
The five lawmakers, who serve on the Homeland Security Committee, said Congress didn’t know enough about the Trump administration’s changes to the cybersecurity agency.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 24/08/2026
UK power facility disabled for days after suspected state-linked cyberattack: www.cybersecuritydive.com/news/uk-powe... (by David Jones)
cybersecuritydive.com
UK power facility disabled for days after suspected state-linked cyberattack
The disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.
000
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/08/2026
Microsoft confirms maximum severity flaw in Entra ID targeted for exploitation: www.cybersecuritydive.com/news/microso... (by David Jones)
cybersecuritydive.com
Microsoft confirms maximum severity flaw in Entra ID targeted for exploitation
The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.
010
Cybersecurity Dive @cybersecuritydive.bsky.social · 21/08/2026
Defense contractors’ CMMC confidence lags, even as self-assessments improve: www.cybersecuritydive.com/news/defense... (by @ericjgeller.com)
cybersecuritydive.com
Defense contractors’ CMMC confidence lags, even as self-assessments improve
A “confidence disconnect” is plaguing the industry, a consulting firm said.
000