The modern bank heist is already under way

The image of the bank robber is hopelessly outdated. Today’s heist does not begin with a getaway car outside a branch. It begins quietly, with an adversary establishing persistence inside a financial institution’s network and studying how the organisation responds, Read More …

FBI Cyber Strategy

This Strategy sets the course for FBI Cyber Division to defend the American people and the nation’s critical infrastructure in cyberspace. It defines our priorities, objectives, and framework for countering malicious cyber activity directed at the United States. It guides Read More …

Berlin planning ‘protective shield’ to defend against sabotage

The new plan would see the creation of a “Cyberdome,” a network of digital sensors that would help seek out and intercept hacking attempts. Germany is planning to develop a “protective shield” to combat sabotage attempts following an attempted drone Read More …

Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked. At the Def Con cybersecurity conference in Read More …

Feds get 3 days to patch N-able God mode flaw under active exploit

The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies three days to patch a flaw that could let attackers reach managed service provider (MSP) customers. Read More …

Experts warn hackers could shut down entire power grids by hijacking cloud accounts

Whenever an AI data center thinks really, really hard, it can increase its power consumption so much to trigger disruptions and possibly even blackouts and gear malfunctions. So, is it possible for a malicious actor to trigger this scenario deliberately, Read More …

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Palo Alto Unit 42 conducted this research in close partnership with Siemens, reflecting their shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) Read More …

AI models capable of devastating attacks on governments and business months away

Powerful AI models capable of devastating new cyber attacks on governments and businesses are mere months away, intelligence agencies for the Five Eyes have warned in a rare joint statement, urging leaders to “act now”. The surprising public intervention by Read More …

Water company’s leaky security earns near-£1M fine

The UK’s data protection watchdog has fined South Staffordshire Water’s parent company nearly £1 million over security failings exposed by the Cl0p ransomware attack in 2022. Issuing the fine of £963,900 ($1.3 million), the Information Commissioner’s Office (ICO) said the Read More …

ASD: Careful Adoption of Agentic AI Services

Agentic artificial intelligence (AI) systems increasingly operate across critical infrastructure and defence sectors and support mission-critical capabilities. As agentic AI systems play a growing operational role, it is crucial for defenders to implement security controls to protect national security and Read More …