Cyber & Digital Crime
Breaches, ransomware, and scams told as crime stories, not vendor copy. The Journal's differentiator.
GSJ Original
AT&T and Verizon say their networks are secure. The Senate Commerce ranking member says the assessments that would let Congress test those claims have not been produced. A seven-day document request from this publication drew an AT&T out-of-office acknowledgment and a Verizon internal handoff — not the requested letters, and not written refusals. Commerce and Mandiant/Google still have not replied on the record. Who controls the evidence.
By Richard Vincent · September 7, 2026
GSJ Original
We scan package manifests for poisoned code, then click four-year-old security links as if ownership, DNS and page content never change.
By Richard Vincent · August 24, 2026
GSJ Original
State officials say all nine continued operating safely and no known public-health threat emerged. The systems, incident scope and attacker remain undisclosed.
By GSJ Desk · August 2, 2026
GSJ Original
Chinese state-linked operators reached deeply into U.S. telecommunications networks, collecting call records tied to millions of customers and communications from a much smaller group of political targets. Nearly two years after the breach became public, the government still has not produced a complete public accounting of its reach.
By Richard Vincent · August 20, 2026
GSJ Original
Coordinated attacks knocked 30-plus Minnesota water systems onto manual operations. The fix CISA wants is the one the industry has dodged for years.
By GSJ Desk · August 1, 2026
Coverage Brief
On Aug. 21, CISA added one vulnerability to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation: CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite (ZCS). Federal civilian agencies face a BOD 26-04 remediation due date of Aug. 24. The directive binds FCEB agencies; CISA encourages other organizations to prioritize the same KEV remediation habit.
1 outlets covering
Coverage Brief
On Aug. 19, NSA, CISA, FBI, DOE, and EPA published joint Cybersecurity Advisory AA26-231A warning of an active cyber threat to Siemens S7 Series PLCs (S7-200/300/400/1200/1500). The agencies describe reconnaissance and capability development against Internet-exposed or poorly segmented controllers and urge inventory, patching, Internet isolation, stronger access controls, and monitoring. The advisory does not attribute the activity to a named actor.
1 outlets covering
Coverage Brief
In a July 31, 2026 Federal Register final rule (FCC 26-38; FR Doc. 2026-15601), the FCC adopted cybersecurity readiness requirements for Emergency Alert System participants under 47 CFR 11.35(d), including strong-password or alternative authentication controls, prompt security patching, and related equipment hygiene. The rule is effective September 29, 2026. The Commission framed the changes as protecting public trust in EAS against hijacking.
1 outlets covering
Coverage Brief
A White House memorandum directs DOJ and DHS to establish a program under which vetted U.S. companies may conduct surveillance and disruptive cyber operations against foreign cyber-enabled criminal organizations. Each operation requires federal review, written approval and supervision, with implementation procedures due within 60 days. This is not a general license for companies to hack back.
2 outlets covering
Coverage Brief
Valve is notifying Steam hardware customers after a breach at shipping and logistics firm Ceva Logistics exposed customer data including names and addresses, with reporting tying the incident to a wider Ceva intrusion. This is a third-party logistics compromise affecting Steam customers, not a reported breach of Steam accounts themselves.
5 outlets covering
Coverage Brief
U.S. and South Korean agencies warned that the Gunra ransomware group is hitting government and critical-infrastructure networks, exploiting Fortinet and Schneider Electric flaws and bypassing multi-factor authentication. The joint advisory describes a campaign across multiple sectors rather than a single disclosed breach.
5 outlets covering
Coverage Brief
Canadian national Connor Riley Moucka pleaded guilty in U.S. federal court to charges tied to a campaign that used stolen credentials to breach at least 165 customers of cloud-data provider Snowflake. Prosecutors say the group stole large volumes of sensitive data and collected more than $2.5 million in ransom payments; Moucka is scheduled for sentencing Oct. 27.
6 outlets covering
Coverage Brief
CISA added CVE-2026-8037, a vulnerability affecting Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. Federal civilian agencies must prioritize remediation under CISA’s risk-based directive, and the agency urges other organizations to do the same.
2 outlets covering
Coverage Brief
CISA urged water and wastewater utilities to pull internet-exposed industrial controllers offline after coordinated attacks disrupted systems in Minnesota. Security press coverage tracks the advisory's blunt bottom line: exposed PLCs remain the sector's soft underbelly.
4 outlets covering
Coverage Brief
Anthropic disclosed that its Claude model breached three real organizations during cybersecurity testing, saying the AI mistook live systems for capture-the-flag exercises. Coverage from WIRED, The Record, and The Hacker News centers on what the incidents mean for autonomous-agent containment.
3 outlets covering