惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
U
Unit 42
aimingoo的专栏
aimingoo的专栏
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
罗磊的独立博客
MongoDB | Blog
MongoDB | Blog
Stack Overflow Blog
Stack Overflow Blog
博客园_首页
M
MIT News - Artificial intelligence
博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
IT之家
IT之家
C
Check Point Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
D
Docker
Microsoft Security Blog
Microsoft Security Blog
Google DeepMind News
Google DeepMind News

Latest from TechRadar in Security

Robots are fighting wars and helping to quash riots — China is arming riot police with squads of AI controlled drones and Ukraine wants to man the frontlines with 25,000 robots US security agency still using Mythos despite ban – government using new security tool despite Pentagon's… Struggling to launch Teams? Microsoft recalls update causing failed startup and infinite loading loops –… NIST is cataloging so many vulnerabilities it can only assign severity scores to the highest priority threats How to meaningfully measure the effectiveness of cyber resilience 'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale… How EU organizations can turn sovereign cloud theory into action 'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to… 'They mopped the floor with me and pulled every childish game they could': Disgruntled researcher releases second major Windows zero-day — claims Microsoft 'would ruin my life, and they did' 'As threats evolve, Gemini keeps our defenses one step ahead': Google claims its AI helped it block over 8.3… Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe Solving the shadow IT crisis in travel Agentic swarms will change how everyone uses AI – but how can organizations deploy them securely? Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains China completes testing on ‘deep-sea electro-hydrostatic actuator’ capable of slicing undersea cables as deep as 3.5 kilometers – new compact subsea vessel testing bridges the ‘last mile’ and could deploy in 2026 Many are still leaving the door open': Security experts warn FIFA World Cup partners could be putting customers at… 'Anyone with $10 could have walked straight through': Report warns this legit-looking software is actually… An ancient Microsoft Excel security flaw could let hackers hijack your entire system, so patch now 'This is not a traditional coding error': Experts flag potentially critical security issues at the heart of Anthropic's MCP, exposes 150 million downloads and thousands of servers to complete takeover Your OpenClaw agents can empty your inbox and leak your data. Here's how to secure them Russia hits European thermal power plant in attempted ‘destructive’ cyberattack – Pro-Kremlin hackers are engaging in ‘riskier and more reckless behavior’ in latest attempt to cripple Western critical infrastructure Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… Dozens of WordPress plugins hijacked to target thousands of sites 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… McGraw Hill becomes latest to see its Salesforce data hacked Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy
The war in Iran is reaching cyberspace - here’s how...
Ashu Savani · 2026-04-16 · via Latest from TechRadar in Security

Since day one, the war between the United States and Iran has played out in cyberspace. Now, we’re seeing cyber warfare reaching U.S. healthcare companies, banks and other enterprises.

As in other recent geopolitical skirmishes, in this conflict cyber-attacks are playing a role far beyond passive espionage.

Article continues below

But it’s critical to know that the biggest vulnerability usually isn’t the sophistication of attackers. Instead, it’s the lack of cybersecurity readiness among the organizations they target.

Co-founder of TryHackMe.

The enterprise execution gap

Playbooks and plans may help us feel prepared, but where many organizations go wrong is assuming this kind of paperwork equates to true preparedness.

To respond effectively to a real attack, there’s a choreography that has to happen in cross-departmental coordination, high-stakes decision-making and leadership communications. Only in practicing the actual execution can organizations truly prepare, and attackers are counting on you not to.

To put it another way, if you're not already testing your teams in simulated cyber warfare scenarios, they're not going to be ready when the real attack strikes.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Geopolitically motivated Advanced Persistent Threats (APTs) often entail a long-term attack where intruders tied to a hostile nation gain unauthorized, undetected access to a network to steal sensitive data or sabotage systems. Unlike typical hit-and-run attacks, APTs are highly targeted, lasting months or years to achieve specific objectives like espionage or intellectual property theft.

For example, in December 2023 a cyberattack on Ukraine’s largest telecom provider, Kyivstar, knocked out mobile and internet services for millions of users throughout the country. It was later revealed by investigators that the attackers had gained access to the network months before the official disruption – dating back to May 2023.

That day it was Kyivstar, but any number of other companies could have fallen victim to this patient, calculated attack.

When what appears to be a minor anomaly could actually be the beginnings of a sophisticated nation-state attack, there’s zero room for hesitation. Teams need to develop a muscle memory that equips them to respond efficiently.

The strongest security asset: humans

Everyone’s thinking it: but what about AI? Can AI help protect against cyber warfare?

Sure. But your best bets are still the humans running it.

AI tools can bring anomalies to light faster and analyze vast amounts of activity, but at the end of the day, good security is as much about people as it is about technology. The strongest security teams aren’t just technically adept, they’re effective communicators.

Even in nation-state-driven APTs, many attacks begin with a basic security control failing or being bypassed – such as someone clicking a rogue link or downloading a compromised file.

Simply getting the entirety of an enterprise organization to reliably cooperate with security protocols and priorities offers a huge blanket of protection, and it’s an incredibly human task. AI can help security teams operate more efficiently and allow humans to be more proactive, but it’s no silver bullet against persistent threats.

Consider a global financial services company operating during these rising tensions with Iran. The firm has strong cybersecurity policies on paper and an array of state-of-the-art AI security tools, but doesn’t regularly coordinate and make decisions alongside the wider organization.

A SOC analyst notices several unusual login attempts and anomalous activity from an employee workstation. The activity is flagged and eventually confirmed as a breach. However, since there are no clear communication protocols between security teams and the broader organization, such as leadership and the teams responsible for the affected systems, response decisions stall.

Deciding whether to isolate the system, hold an update or notify impacted teams bounce to and from the SOC and leadership teams, without clear direction.

By the time containment steps are approved and communicated enterprise wide, attackers have already moved deeper into the network and accessed personal data.

In the post-incident review, the problem isn’t a lack of security tools or policies. It’s that the organization has a disconnection between its defenders and those they are protecting. Strong, effective cyber defense depends just as much on strong communication and decision making across the business as a whole as it does on the technical detection.

Creating security certainty in an uncertain geopolitical environment

International tensions will continue to drive cyber activity, whether organizations are prepared or not.

The companies that recover fastest treat cyber readiness as a continuous feedback loop between the tech and its people. They optimize their response through constant practice exercises, identify weaknesses early, and refine how their teams coordinate, communicate, and escalate potential threats across the business.

By repeating the simulation cycle frequently to identify weaknesses during exercises, and converting findings into improvements such as updating playbooks, refining detection rules and overall communication protocols, teams will face continuous maturity rather than siloed preparedness to specific situations.

Enterprises cannot control global politics, but they can control their readiness. Those that survive any form of cyber-attack are those three steps ahead – those that practice responding before the crisis ever arrives, versus scrambling to contain damage in response.

In an era where geopolitical events can quickly translate into cyber incidents, preparation isn’t just about tools, it’s about how well people perform when an incident unfolds.

We've ranked the best firewall for small business.