Iranian cyber threats against U.S. water, energy and telecom infrastructure are escalating. Here’s what’s happening, what’s at risk and how defenders should respond.
Featured
Root Evidence analyzed 253,912 CVEs and found AI is accelerating vulnerability discovery, but not exploitation — exposing a vulnerability management model increasingly overwhelmed by noise.
Network segmentation, credential hygiene, behavioral monitoring, automated containment. The OpenAI incident didn't invent these requirements. It proved that skipping them in agent environments has consequences.
Community Corner
See allFrom the CYBR.SEC.Community
What Radio Jamming Taught Me About DDoS
From Army signal intelligence and radio jamming to modern DDoS defense, the same lessons in reconnaissance, timing, disruption and adaptation reveal how attackers overwhelm networks — and how defenders can stay ahead.
The Agent Died. The Delegation Didn't.
Once the work can move from agent to agent, killing the agent is no longer the same thing as stopping the work.
Returning Continuity: What AI Is Teaching Us About Cybersecurity
Yesterday's me made a move. Today's me inherits the consequences. Tomorrow's me will inherit a different world again.
The Human Factor in IAM: Why Identity Programs Succeed or Fail
Most IAM failures don't start with a broken platform. They start with a person making a reasonable decision under bad conditions.
AI Created the Vulnpocalypse. AI Will Also Fix It.
AI has broken traditional vulnerability management by accelerating vulnerability discovery and exploitation, but it may also be the only technology fast enough to help defenders regain the advantage.
Latest Articles
See all
Critical Infrastructure SecurityCYBR.SEC.CONAbove the Packet: Field Notes from the Meaning LayerAdventures in Threat HuntingAI SOCSOCAgentic AI
Iran (and Everyone Else) Is Coming for U.S. Critical Infrastructure. Are We Ready?
Iranian cyberattacks are hitting U.S. critical infrastructure as water, energy and telecom systems face growing threats. Plus: AI SOCs, vulnerability overload, CYBR.SEC.CON 2026 — and more.
LaunchPadCYBR.SEC.CONAI Security
Singulr AI Targets the Growing Enterprise AI Control Gap
CYBR.SEC.CON LaunchPad finalist Singulr AI is tackling the enterprise AI control gap with runtime governance, security and controls designed to let companies adopt AI and agents without losing visibility or control.
LaunchPadCYBR.SEC.CON
Astelia Says Vulnerability Prioritization Is Solving the Wrong Problem
CYBR.SEC.CON LaunchPad finalist Astelia uses attack-path reachability to determine which vulnerabilities can actually lead to a breach, helping enterprises cut through millions of findings and focus remediation where it matters.
LaunchPadCYBR.SEC.CON
MokN Targets Stolen Credentials Before They Hit the Dark Web
CYBR.SEC.CON LaunchPad finalist MokN “phishes the phishers” to uncover stolen credentials while attackers are actively using them, closing a blind spot left by traditional dark-web monitoring.
AI SOCSOC
The AI SOC Buying Guide Nobody Has Yet
AI-driven SOC platforms promise faster investigations, lower costs and fewer repetitive tasks for security analysts. But before CISOs buy in, they need to understand the baselines, business context, pricing and access controls. (Sponsored by Command Zero)
AI SOCSOC
AI Attacks Are Closing the SOC’s Human-in-the-Loop Window
As attackers automate cyberattacks at machine speed, SOC teams may soon have to let AI agents act without human approval — making RBAC, business context and autonomous-response guardrails critical security controls. (Sponsored by Command Zero)
Incident ResponseConfirmation BiasCYBR.Signal
Don't Let Confirmation Bias Derail Incident Response
A construction site in Texas offers a powerful reminder that the biggest mistake in incident response isn't missing an attack, but letting confirmation bias convince you one exists before the evidence does.
Podcasts & Video
See all
Podcast
A Grave Case of Confirmation Bias
Podcast
Separating the Wheat from the Chaff with Alfred Huger
Video
From AI Hacking Hype to Enterprise Reality: What Mythos Actually Changes
Justin “Hutch” Hutchens examines the gap between sensationalized narratives around “AI hacking” and the pragmatic, risk-informed reality of AI adoption in enterprise environments.
Video
Stealing Trust: Modern Social Engineering from Phishing to AI-Powered Vishin
The talk “Stealing Trust: Modern Social Engineering from Phishing to AI-Powered Vishing” by Chris Russell explores the evolution and increasing sophistication of social engineering attacks, emphasizing how adversaries now leverage artificial intelligence to automate and personalize deception.
Video
Offense for Defense
Tim Medin’s talk “Offense for Defense” is a practical, engaging, and humorous guide for blue teamers, defenders, and IT professionals on leveraging offensive security tools and mindsets to proactively strengthen their organizations—without needing to become full-time red teamers.
Video
Hacking Transit: Repurposing Surplus Devices for Fun and Shenanigans
Transit hardware hacking shows how surplus public transportation devices can be reverse engineered, repurposed and explored to uncover how real-world systems work — and where unexpected security weaknesses may hide.
Video
A Brief Introduction to Cognitive Warfare
Cognitive warfare turns the human mind into an attack surface, using disinformation, emotion, identity and social manipulation to exploit cognitive biases, erode trust and shape how people perceive reality.