< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles

Ransomware Evolution: Extortion Without Encryption

🔒 In a shift noted by Kaspersky experts, ransomware operators are increasingly abandoning encryption and focusing on extortion through access and data theft. The PAYLOAD campaign demonstrated this by abusing Active Directory and GPOs to display ransom notes, change wallpapers, disable accounts, and prove access without encrypting files. Attackers favor data exfiltration because backups negate the leverage of encryption, while leaks threaten reputation and regulatory fines. Standard cyberhygiene remains essential to mitigate these evolving extortion tactics.
read more →

Edge PQC Growth Masks Broader Quantum Readiness Gaps

🔒 F5 Labs finds 54% of the top 1M websites now support post-quantum key exchange, but much of that progress stems from CDNs enabling PQC rather than enterprises upgrading their own infrastructure. The study examined only front-end connections and did not assess origin servers, internal APIs, or service-to-service links, leaving many internal attack paths exposed. Experts urge organizations to inventory cryptographic dependencies, prioritize long-term confidential data, and adopt hybrid PQC and automated certificate management to achieve true readiness.
read more →

Talos Threat Update: Ensuring Critical Processes

🛡️ This week’s Threat Source newsletter highlights real-world defensive decisions and emerging threats observed by Cisco Talos. Pierre Cadieux recounts isolating legacy check-printing systems to balance business continuity and risk mitigation. Talos also details CAIRN research on malware using natural-language prompts to evade AI-assisted analysis, classified as A3: AI-Analysis Evasion. The bulletin rounds out with vulnerability news, notable breaches, ransomware activity, and guidance for defenders.
read more →

Weekly ThreatsDay: RaaS, supply chain, and AI risks

🛡️ This week’s ThreatsDay bulletin highlights a range of active cyber threats, from a rogue ransomware affiliate and exposed attacker infrastructure to malicious developer packages and phishing campaigns that abuse legitimate services. The report covers targeted malware delivered via messaging apps, supply-chain compromises in npm and RubyGems, and vulnerabilities in medical device cryptography readiness. It also notes novel tactics like Solana memos as dead drops and prompt-injection attacks against AI assistants.
read more →

September 2026 Cyber Threat Landscape Report

🛡️ September 2026 saw a sharp rise in global cyber activity: weekly attacks averaged 2,803 per organization, up 48% year over year, with education the most targeted sector. Phishing rates increased to 1 in 91 emails and ransomware incidents rose 53% year over year. GenAI prompt usage expanded, with 1 in 39 prompts posing a high risk of sensitive data leakage, highlighting growing exposure across industries and regions.
read more →

AI Agent Skills Fueling a New Malware Supply Chain

🧾 VirusTotal expanded its study to 35,878 AI agent skills and found that 52.9% pose security or abuse risks, with 18.5% (6,637) classified as malicious. Most malicious skills (62%) contain no executable code and rely on natural-language instructions, making detection difficult for traditional AV and static scanners. The team introduces CARO-A, a naming scheme to capture type, ecosystem, family, and locus, and benchmarks detectors including a Jev-like model that achieved 81.3% detection at 97.7% precision. VirusTotal offers an agentic analysis endpoint for partners to integrate real-time verdicts and CARO-A labels.
read more →

State of AI Analysis Evasion in Malware

🛡️ Cisco Talos describes a new malware archetype, A3: AI-Analysis Evasion, where adversaries embed natural-language instructions in binaries to influence automated LLM-based pipelines. The post traces four families (FRUITSHELL, PLOTSAFE, HOLLOWCLAD, MANTLEMAZE) across 84 samples collected from January 2025–July 2026, showing techniques from simple comments to template-spraying across model chat formats. Talos evaluated these strings against local LLMs and found direct-instruction comments often reduced suspicion, while more complex attempts sometimes backfired. Defenders are advised to treat extracted text as evidence, not instruction, and to construct prompts that explicitly separate analyst queries from sample content.
read more →

Focus on phishing at the server layer, not domains

🔍 The author recounts timing an attacker who deployed a credential-harvesting operation in under 24 minutes, highlighting that defenders focus on blocking cheap, replaceable domains while attackers bear true cost at the server. Modern phishing kits act as adversary-in-the-middle proxies, relaying genuine MFA flows and hiding origins behind CDNs. The author describes how a cookie set by the proxy exposed the relay IP, which led to a mapped estate of related infrastructure and multiple impersonation campaigns. The piece argues defenders should hunt by server and hosting ranges, detect relay-origin sign-ins, and revoke sessions first to disrupt attackers effectively.
read more →

Samsung Galaxy S26 Hacked Multiple Times at Pwn2Own

🔒 On day two of Pwn2Own Ireland 2026, researchers earned $232,500 after exploiting 45 distinct zero-day vulnerabilities. The Samsung Galaxy S26 was compromised three times by teams including KAIST Hacking Lab, PetoWorks, and Mobile Hacking Lab. Other notable wins included a rapid Sonos Era 300 exploit and a $40,000 award for breaching Dynamo in the AI Infrastructure category. ZDI enforces vendor 90-day patch windows after disclosure.
read more →

Five-Year CISO Trends Shift Security to Workflows

🛡️ The 2026 Voice of the CISO report reveals a multi-year shift: resilience, AI governance, human risk, and board scrutiny are converging where work actually happens. While some metrics improved year-over-year, longer-term trends show fluctuating attack expectations, persistent human risk, and AI evolving from experiment to mandate. CISOs face resource gaps as governance demands outpace budgets and expertise.
read more →

Security professionals still rely on passwords often

🔐 A Yubico and Okta study finds 48% of cybersecurity professionals use usernames and passwords for personal accounts and 43% for work accounts, despite rating them as among the least secure methods. Device-bound passkeys were viewed as most secure but used by only 25% at work and 20% personally, while password managers saw 24% workplace adoption. The report highlights fragmented authentication practices, limited MFA mandates, and legacy onboarding defaults as factors driving insecure choices.
read more →

Pwn2Own Ireland Yields 32 Zero‑Day Finds

🔍 On day one of Zero Day Initiative’s Pwn2Own Ireland 2026, ethical hacking teams discovered 32 zero-day vulnerabilities across smartphones, smart home devices, printers and AI tools, earning over $368,000 in prizes. Notable successes included exploits against Sonos Era 300, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, OpenAI Codex and Garmin Index BPM. Findings will be responsibly disclosed to vendors with a 90-day patch window as the contest continues.
read more →

Rapid domain impersonation around Jev launch

🔍 TypeSafe launched the decision-model Jev in mid-September 2026 and within days attracted widespread lookalike domain registrations. Researchers monitored newly registered domains from August 14 to September 28 and found 167 Jev-related lookalikes, many designed for hyphenation, typos, or reseller plays. Several domains were configured with hosting and mail, elevating the risk of phishing, credential theft, and API key capture. The report highlights how quickly brand protection must act during intense public attention.
read more →

Scams and fake GTA VI leaks targeting gamers

🎮 Scammers are exploiting excitement around GTA VI’s November 19, 2026 release with fake leak sites, fraudulent preorders, and token schemes. Some sites claim to sell early builds or demo access for high prices, push dubious “human verifications” to harvest traffic or downloads, or collect personal and payment data via cloned storefronts. Others promote a $GTAVI crypto token promising access to the game, while many mimic Rockstar’s branding to fool users. Check domains carefully, avoid downloading archives from untrusted sources, and never pay or provide sensitive information to suspicious sites.
read more →

Most Medical Devices Unready for PQC Transition

🔒 A Forescout investigation across 50+ healthcare delivery organizations found most medical devices cannot be upgraded to post-quantum cryptography, leaving sensitive healthcare data at risk of future quantum-enabled decryption. Only 6% of IoMT and 16% of medical OT devices use SSH implementations that could support PQC, compared with around 50% of traditional IT devices. The report highlights exposed systems holding EMRs and PACS and urges immediate inventory, segmentation, TLS 1.3 enforcement and vendor engagement to prepare for quantum threats.
read more →

MCP Marketplaces Expose Enterprises to Risk

🔎 In 2024, the MCP standard gained broad adoption as a connector for models, agents, and IDEs, but the surrounding marketplaces lack security controls. OX Security analyzed 15,465 publicly indexed MCP servers and found weak governance, servers hosted in risky jurisdictions, personal machines using consumer tunneling, and dangling domains that can be hijacked. The report warns enterprises to treat trust as an attack surface and to adopt vetting, code signing, and origin verification until marketplaces do.
read more →

Google pause spotlights AI-driven triage challenge

🔍 Google paused certain bug bounty submissions after a surge of largely automated, low-quality reports stretched its validation capacity. The company had already tightened rules and raised evidence requirements to reduce false positives, but high volumes of AI-generated findings continue to challenge triage workflows. Experts warn that unchecked report floods can waste engineering time and that organizations should treat triage as a security capability, requiring reproducible evidence and reachability checks. AI can discover real vulnerabilities but also produces plausible, costly false leads that must be filtered before remediation.
read more →

UK police urge public to adopt passkeys now

🔒 The UK’s Report Fraud service has launched a public campaign urging internet users to adopt passkeys after reporting a sharp rise in funds stolen via email and social media account takeovers. Losses from such cybercrime rose to £6.3m in 2025/6, up from £1.2m the prior year, while reports of account takeover increased by 34%. Officials and experts say passkeys — which use device PINs or biometrics and keep private keys on the device — are more resilient to phishing and credential theft than passwords.
read more →

AI-driven surge in n-day exploits outpaces zero-day

🔍 Google’s Threat Intelligence Group reports attackers are increasingly weaponizing disclosed flaws, with AI accelerating exploit development. GTIG recorded 141 exploited CVEs between January and August 2026 versus 127 in all of 2025, while monthly disclosures doubled. High-risk exploits and time-to-exploit have risen, and perimeter appliances remain prime targets. Organizations must adopt threat-driven triage and automated remediation to manage the growing volume.
read more →

UK schools improving incident recovery but gaps persist

🔒 New government data shows UK schools are recovering faster from cyber incidents, with the proportion experiencing incidents falling from 34% to 27% over three years. Two-thirds (66%) of schools can now recover immediately, up from 55%, and critical damage has dropped to 7%. However, many institutions still treat cybersecurity as an IT-only issue and nearly half of schools have yet to implement essential protections like policies, risk assessments and backups.
read more →