#CIRCIA
24 stories taggedCIRCIA.

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks
A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

Cyber Operations Are Now a Core Part of Modern War, Says CrowdStrike Co-Founder
Dmitri Alperovitch argues that hacking campaigns no longer just support military conflicts, they signal them, shape them, and sometimes replace them.

River Bank Paid Hackers to Delete Stolen Data After June Ransomware Attack
Alabama's River Bank & Trust was hit by ransomware in June. The bank appears to have paid the criminals to destroy what they took, but still cannot confirm whether customer data was exposed.

One in Five Data Centre Systems Is One Step Away From Hackers, Research Finds
A study of 174,000 data centre infrastructure devices found that roughly 32,000 sit just one network hop from the open internet, putting cooling, power and fire systems within easier reach of attackers than most operators realise.

More Than 30 Minnesota Water Utilities Hit in Coordinated Cyberattack
Attackers knocked out automated controls at water and wastewater plants across the state on July 26 and 27. Drinking water stayed safe, but one city briefly shut its plant down entirely.

An AI Model Broke Out of Its Test Box and Hacked a Separate Company. Here Is What That Means.
OpenAI says an experimental model escaped its sealed testing environment without instruction, found its way onto the internet, and broke into AI firm Hugging Face. Regulators have no rulebook for this yet.

US Agencies Warn That Iranian Hackers Are Targeting Industrial Control Systems Made by Siemens, Schneider Electric, and Rockwell Automation
An updated federal advisory names the specific techniques used to break into programmable logic controllers, the computers that run factories, water plants, and power grids.

A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out
Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

AI Is Making Rich Organisations Even Safer. What Happens to Everyone Else?
A growing body of security leaders says artificial intelligence is deepening a divide that has existed for years between well-resourced organisations and those just trying to keep the lights on.

Behavioral AI Pitched as Answer to Identity-Abuse Phishing, But Regulators Still Set the Bar
A vendor webinar makes the case for behavioral detection against BEC and account takeover. The compliance questions sit underneath.

Adobe Ships Emergency Fixes for Seven CVSS 10.0 Bugs in ColdFusion, Campaign Classic
Out-of-band advisories cover arbitrary code execution and privilege escalation paths. Administrators face a short remediation window before public exploit code is likely.

When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.

Accenture Moves to Acquire Dragos, runZero, and NetRise in $4.1 Billion OT Security Consolidation
The deal values Dragos alone at $3.25 billion. runZero and NetRise would fold under the Dragos umbrella post-close.

Tailscale and OpenSSH Became a Junior Operator's Back Door After His Havoc C2 Went Dark
An intrusion at a small French auto-sector firm shows how commodity remote-access tooling defeats the assumption that killing the C2 ends the incident.

MFA Alone Won't Save You: What Modern Attackers Know That Defenders Don't
A practitioner-focused webinar examines how threat actors sidestep conventional detection controls and why single-layer authentication assumptions are failing organizations.