Skip to content
Artwork for Cybersecurity Headlines
NewsTech NewsTechnology

Cybersecurity Headlines

CISO Series

Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.

Play
  • 34 episodes
  • daily
  • Avg 11 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Friday · 33 min

    The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report

    Read the full stories at CISOSeries.com. This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.

  • Friday · 7 min

    Manchester Airports breach, ATF agency breach, clothier Carhartt breach

    Manchester Airports Group suffers cyber incident ATF suffers data breach Clothing retailer Carhartt suffers data breach Get the show notes here: https://cisoseries.com/cybersecurity-news-manchester-airports-breach-atf-agency-breach-clothier-carhartt-breach/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

  • Thursday · 6 min

    Chinese hackers hit US agencies, Ring locks out police, Boston Scientific feels cyber pain

    China contractor hack hits US agencies Ring throws away the key Boston Scientific feels cyber pain Get the show notes here: https://cisoseries.com/cybersecurity-news-august-27-2026/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

  • Wednesday · 6 min

    China's hackers pick DeepSeek, OpenAI blocks Russian influence push, webpages mess with local AI

    China's hackers pick DeepSeek OpenAI blocks a Russian influence push A webpage can mess with local AI Get the show notes here: https://cisoseries.com/cybersecurity-news-august-26-2026/ Huge thanks to our episode sponsor, ThreatDown If your current security posture is struggling to keep pace with fast-moving, identity-based threats, your business is exposed. Today's security expertise gap is real, but it doesn't have to be a permanent vulnerability. ThreatDown helps SMBs move from reactive defense to proactive, 24/7 intelligence, delivering enterprise-grade protection without the headcount. Enterprise-grade defense. Built for businesses like yours.

  • Tuesday · 6 min

    SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing

    SynkLoader throws in the kitchen sink NIST flags multi-cloud sprawl ReliaQuest blocks a ShinyHunters swing Get the show notes here: https://cisoseries.com/cybersecurity-news-august-25-2026/ Huge thanks to our episode sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.

  • Monday · 8 min

    UK power plant hack, AI zero click, children's hospital breach

    UK power plant disabled for four days by Iran-linked hackers Zero-click Grok and Gemini chat history theft possible through cryptographic context injection Canada's Hospital for Sick Children suffers another cyberattack Get the show notes here: https://cisoseries.com/cybersecurity-news-uk-power-plant-hack-ai-zero-click-childrens-hospital-breach/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

  • August 21 · 34 min

    The Department of Know: Living off Azure, OpenAI's "defender window," and AI-driven PLC attacks

    Read the full sotry at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Bil Harmer, CISO, Supabase, and David B. Cross, CISO, Atlassian. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here.

  • August 21 · 8 min

    CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach

    CISA warns of hackers exploiting critical MLflow vulnerability ICS operators warned of AI-driven attacks on Siemens PLCs Electronic health record company CareCloud confirms millions affected by breach Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-mlflow-warning-siemens-plcs-warning-carecloud-confirms-breach/ Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

  • August 20 · 6 min

    OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed

    OpenAI rewrites safety rules after threshold warning US charges 17 in Iranian hacking campaign Microsoft fixes Windows Defender crash bug Get the show notes here: https://cisoseries.com/openai-safety-rules-iranian-hackers-defender-crashes/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 19 · 8 min

    AI "mind virus," malware living off Azure, an Irregular post-mortem

    Persistent prompts prove potentially pernicious The malware is coming from inside Microsoft Irregular releases AI sandbox escape post-mortem Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 18 · 7 min

    North Korean IT worker lands federal job, Azure records go up for sale, GitHub goes down

    Federal agency hires North Korean IT worker Millions of Azure records allegedly for sale GitHub outage hits Actions and Copilot Get the show notes here: https://cisoseries.com/cybersecurity-news-north-korean-it-worker-lands-federal-job-azure-records-go-up-for-sale-github-goes-down/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 17 · 8 min

    SAP Commerce flaw exploited, Mirai boosts capabilities, Shell investigates breach

    Max severity SAP Commerce Cloud flaw now targeted in attacks New Mirai variant adds stealth capabilities to botnet code Shell investigates potential incident after Clop data theft claims Get the show notes here: https://cisoseries.com/cybersecurity-news-sap-commerce-flaw-exploited-mirai-boosts-capabilities-shell-investigates-breach/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 14 · 33 min

    The Department of Know: Ransomware gangs, Copilot apps, and drones phone home

    Read the full stories at CISOSeries.com This week's Department of Know is hosted by Sarah Lane, with guests Peter Gregory, author of over 50 books on cybersecurity, and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

  • August 14 · 8 min

    Akira's innovative attack, WhatsApp's scam alert, White House TCO strategy

    Akira affiliate's innovative "crash mode" attack almost worked WhatsApp rolls out scam alert feature White House looks to private sector for help against offensive hacking Show notes: https://cisoseries.com/cybersecurity-news-akiras-innovative-attack-whatsapps-scam-alert-white-house-tco-strategy/ Huge thanks to our sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

  • August 13 · 7 min

    UK tackles AI bioweapon risk, DeadLock goes on-chain, evil twin flies home from DEF CON

    UK eyes AI gene-synthesis guardrails DeadLock puts ransomware on the blockchain An evil twin flies home from DEF CON Episode show notes: https://cisoseries.com/uk-tackles-ai-bioweapon-risk-deadlock-goes-on-chain-evil-twin-flies-home-from-def-con/ Huge thanks to our sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

  • August 12 · 6 min

    Water systems get cyber lifeline, hackers jump into Polish power plant, local governments knocked offline

    Water systems get a federal cyber lifeline Hackers jump into Polish power plant Cyberattacks knock local governments offline Episode show notes: https://cisoseries.com/water-systems-cyber-lifeline-hackers-polish-power-plant-local-governments-offline/ Huge thanks to our sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

  • August 11 · 6 min

    Sandworm's poisoned VPN, Royal Navy drones phone China, OpenAI loosens cyber limits

    OpenAI loosens cyber limits for vetted defenders Sandworm's fake recruiters plant a poisoned VPN Royal Navy drones phone home to China Episode show notes: https://cisoseries.com/openai-loosens-cyber-limits-sandworms-poisoned-vpn-navy-drones-phone-china/ Huge thanks to our sponsor, ThreatLocker An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

  • August 10 · 7 min

    OpenAI slows Astra, Irregular won't talk, Senate confirms Cassady

    OpenAI slows release of Astra model citing cyber capabilities Irregular won't say if there were more rogue incidents U.S. cyber ambassador nominee Cassady confirmed in Senate Episode shownotes: https://cisoseries.com/cybersecurity-news-openai-slows-astra-irregular-wont-talk-senate-confirms-cassady/ Huge thanks to our sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.

  • August 7 · 8 min

    Faked bug reports, Meta's rogue AI, China investigates Palo Alto

    Apple's bug bounty program overwhelmed by fake AI generated reports China launches cybersecurity review into Palo Alto Networks products Meta AI hacks external systems during cybersecurity testing Get the show notes here: https://cisoseries.com/cybersecurity-news-faked-bug-reports-metas-rogue-ai-china-investigates-palo-alto/ Huge thanks to our episode sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

  • August 6 · 6 min

    AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon

    AI safety tests spill onto the real internet Private Relay flaw unmasks IP addresses Weak telcos left door open for Salt Typhoon Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-safety-tests-reach-the-internet-private-relay-flaw-unmasks-ips-weak-telcos-invite-salt-typhoon/ Huge thanks to our episode sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

Showing 1–20 of 34 episodes