Skip to content
Artwork for Cybersecurity Headlines
NewsTech NewsTechnology

Cybersecurity Headlines

CISO Series

Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.

Play
  • 40 episodes
  • daily
  • Avg 11 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Friday · 34 min

    The Department of Know: Astra launches, CISA cuts programs, McKesson breached

    Read the full stories at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

  • Friday · 8 min

    Court records breach, Breeze Comet hits Brazil, Aesto records breach

    U.S. and Canadian court records breached in Thomson Reuters incident Cybercrime Breeze Comet causing problems in Brazil Aesto record system hit by data breach Get the full show notes here: https://cisoseries.com/cybersecurity-news-court-records-breach-breeze-comet-hits-brazil-aesto-records-breach/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

  • Thursday · 7 min

    153M licenses for sale, Anthropic reverses course, Astra enters the red zone

    Dark web shop stocks 153 million driver's licenses Nexus, a new dark web service, claims it's selling scans of more than 153 million US and Canadian driver's licenses, plus over 10 million ID cards, three million travel and international IDs, and at least 579,000 medical cards. The images appear tied to Louisiana-based IDScan.net, which provides identity verification to retailers, rental-car companies, and others. KrebsOnSecurity matched some records to licenses scanned during Hertz rentals. IDScan says it's investigating and hasn't determined the breach's nature or scope. The FBI's New Orleans office has opened an inquiry. (KrebsOnSecurity) Anthropic puts 30-day data retention in reverse After customer pushback, Anthropic is revising a policy that stored 30 days of traffic from its Fable and Mythos models. Under new Enterprise Frontier Safeguards, customers can keep data in their own cloud and block Anthropic employees from reviewing it while automated abuse monitoring continues. Anthropic calls that privacy equivalent to zero data retention. Developed with more than 100 customers, including Salesforce, the system is due later this year. (CNBC) Astra enters OpenAI's cyber red zone OpenAI says Astra is its first model to reach a "Critical" cybersecurity threshold, meaning it can find unknown flaws and build exploits across well-defended systems without step-by-step human help. It's due soon, but the advanced cyber capabilities will start with a small test group before expanding through Daybreak Blue. OpenAI says Astra refused 91.5% of cyber jailbreak requests, versus 59% for GPT-5.6 Sol, and monitoring can pause suspicious activity. The Information reports Astra's latent reasoning may hide parts of its process, raising doubts about chain-of-thought monitoring. (WIRED, The Information) Get the full show notes here: https://cisoseries.com/153m-licenses-for-sale-anthropic-reverses-course-astra-red-zone/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

  • Wednesday · 8 min

    Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability

    Anthropic announces safety changes and new models USPS installs "untested" IT systems for mail-in ballots Thousands of Exchange servers vulnerable to hijacks Get the full show notes here: https://cisoseries.com/cybersecurity-news-fable-5-1-released-usps-untested-it-exchange-hijack-vulnerability/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

  • Tuesday · 6 min

    Claude sessions hijacked, AI jolts global finance, agents get too many keys

    Claude sessions get hijacked Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into accounts and burn through paid usage without needing a password or two-factor code. The company is signing affected users out, removing stored payment methods and refunding unauthorized charges. But revoking the session doesn't remove the malware, so victims still need to clean the device, change credentials and revoke other active sessions. (BleepingComputer) AI could jolt global finance Bank of England governor Andrew Bailey is warning G20 officials that frontier AI could destabilize the global financial system by making cyberattacks faster, cheaper and easier to scale across borders. Bailey says many countries still lack protocols for how advanced models are developed and released. He also warned that a successful attack on a small number of heavily used technology providers could undermine confidence across the entire system. (The Guardian) AI agents get too many keys New research from Cequence Security and Enterprise Management Associates found a sizable confidence gap around AI agent permissions. 94% of surveyed organizations believe their agents don't have more access than necessary, but only 33% actually enforce least privilege. 65% have seen an agent act outside its intended role, and 29% say that caused measurable business impact. (Security Magazine) Get the full show notes here: https://cisoseries.com/claude-sessions-hijacked-ai-jolts-global-finance-agents-get-too-many-keys/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

  • Monday · 7 min

    ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach

    ServiceNow warns of three maximum severity security vulnerabilities PaperCut zero-day exploited in attacks Healthcare giant McKesson discloses breach Get the full show notes here: https://cisoseries.com/cybersecurity-news-servicenow-vulnerabilities-warning-papercut-zero-day-mckesson-healthcare-breach/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website. KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.

  • August 28 · 33 min

    The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report

    Read the full stories at CISOSeries.com. This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.

  • August 28 · 7 min

    Manchester Airports breach, ATF agency breach, clothier Carhartt breach

    Manchester Airports Group suffers cyber incident ATF suffers data breach Clothing retailer Carhartt suffers data breach Get the show notes here: https://cisoseries.com/cybersecurity-news-manchester-airports-breach-atf-agency-breach-clothier-carhartt-breach/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

  • August 27 · 6 min

    Chinese hackers hit US agencies, Ring locks out police, Boston Scientific feels cyber pain

    China contractor hack hits US agencies Ring throws away the key Boston Scientific feels cyber pain Get the show notes here: https://cisoseries.com/cybersecurity-news-august-27-2026/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

  • August 26 · 6 min

    China's hackers pick DeepSeek, OpenAI blocks Russian influence push, webpages mess with local AI

    China's hackers pick DeepSeek OpenAI blocks a Russian influence push A webpage can mess with local AI Get the show notes here: https://cisoseries.com/cybersecurity-news-august-26-2026/ Huge thanks to our episode sponsor, ThreatDown If your current security posture is struggling to keep pace with fast-moving, identity-based threats, your business is exposed. Today's security expertise gap is real, but it doesn't have to be a permanent vulnerability. ThreatDown helps SMBs move from reactive defense to proactive, 24/7 intelligence, delivering enterprise-grade protection without the headcount. Enterprise-grade defense. Built for businesses like yours.

  • August 25 · 6 min

    SynkLoader throws in the kitchen sink, NIST flags multi-cloud sprawl, ReliaQuest blocks a ShinyHunters swing

    SynkLoader throws in the kitchen sink NIST flags multi-cloud sprawl ReliaQuest blocks a ShinyHunters swing Get the show notes here: https://cisoseries.com/cybersecurity-news-august-25-2026/ Huge thanks to our episode sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers leverage AI-driven automation to target mid-size business, your legacy defenses are no longer enough. You need the expertise to detect and respond to modern threats, without the overhead of building an in-house security team. ThreatDown provides proactive, Managed Detection and Response, 24/7, so your business can scale safely. Enterprise-grade defense. Built for businesses like yours.

  • August 24 · 8 min

    UK power plant hack, AI zero click, children's hospital breach

    UK power plant disabled for four days by Iran-linked hackers Zero-click Grok and Gemini chat history theft possible through cryptographic context injection Canada's Hospital for Sick Children suffers another cyberattack Get the show notes here: https://cisoseries.com/cybersecurity-news-uk-power-plant-hack-ai-zero-click-childrens-hospital-breach/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of operational agility. You don't have to choose between moving fast and staying protected. ThreatDown bridges the expertise gap, replacing fragmented, legacy tools with proactive, 24/7 MDR that scales with your business. ThreatDown. Enterprise-grade defense. Built for businesses like yours.

  • August 21 · 34 min

    The Department of Know: Living off Azure, OpenAI's "defender window," and AI-driven PLC attacks

    Read the full sotry at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Bil Harmer, CISO, Supabase, and David B. Cross, CISO, Atlassian. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and proof on one Agentic Trust Platform—and continuously monitors your controls, keeping you audit-ready all year round. Find your Calm-pliance here.

  • August 21 · 8 min

    CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach

    CISA warns of hackers exploiting critical MLflow vulnerability ICS operators warned of AI-driven attacks on Siemens PLCs Electronic health record company CareCloud confirms millions affected by breach Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-mlflow-warning-siemens-plcs-warning-carecloud-confirms-breach/ Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

  • August 20 · 6 min

    OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed

    OpenAI rewrites safety rules after threshold warning US charges 17 in Iranian hacking campaign Microsoft fixes Windows Defender crash bug Get the show notes here: https://cisoseries.com/openai-safety-rules-iranian-hackers-defender-crashes/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 19 · 8 min

    AI "mind virus," malware living off Azure, an Irregular post-mortem

    Persistent prompts prove potentially pernicious The malware is coming from inside Microsoft Irregular releases AI sandbox escape post-mortem Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 18 · 7 min

    North Korean IT worker lands federal job, Azure records go up for sale, GitHub goes down

    Federal agency hires North Korean IT worker Millions of Azure records allegedly for sale GitHub outage hits Actions and Copilot Get the show notes here: https://cisoseries.com/cybersecurity-news-north-korean-it-worker-lands-federal-job-azure-records-go-up-for-sale-github-goes-down/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 17 · 8 min

    SAP Commerce flaw exploited, Mirai boosts capabilities, Shell investigates breach

    Max severity SAP Commerce Cloud flaw now targeted in attacks New Mirai variant adds stealth capabilities to botnet code Shell investigates potential incident after Clop data theft claims Get the show notes here: https://cisoseries.com/cybersecurity-news-sap-commerce-flaw-exploited-mirai-boosts-capabilities-shell-investigates-breach/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at enterprise scale and delivers a 526% ROI over three years. 16,000+ companies trust Vanta, including Snowflake, Atlassian, and Ramp. Visit Vanta.com/CISO to learn more.

  • August 14 · 33 min

    The Department of Know: Ransomware gangs, Copilot apps, and drones phone home

    Read the full stories at CISOSeries.com This week's Department of Know is hosted by Sarah Lane, with guests Peter Gregory, author of over 50 books on cybersecurity, and Michael Bickford, former CISO, New York State Gaming Commission, Unisys Security Consulting. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

  • August 14 · 8 min

    Akira's innovative attack, WhatsApp's scam alert, White House TCO strategy

    Akira affiliate's innovative "crash mode" attack almost worked WhatsApp rolls out scam alert feature White House looks to private sector for help against offensive hacking Show notes: https://cisoseries.com/cybersecurity-news-akiras-innovative-attack-whatsapps-scam-alert-white-house-tco-strategy/ Huge thanks to our sponsor, ThreatLocker AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

Showing 1–20 of 40 episodes