< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports

1778 articles

Protecting Windows Named Pipes from Local Abuse

🔒 Named pipes are commonly used for interprocess communication on Windows but should never be treated as implicitly trusted. Developers often assume local IPC is safe, yet different users, sessions, and privilege levels may run on the same machine. Servers must verify client identities, apply explicit DACLs, authorize each operation, and validate message contents to avoid privilege escalation, confused-deputy issues, and denial-of-service. Remote accessibility and predictable pipe names further increase risk, so implement strict limits, timeouts, and local-only protections.
read more →

Supply Chain Risks in the Modern SDLC

🔍 Unit 42 details how supply chain attacks have escalated, shifting adversaries from finished applications to the developer tooling and CI/CD pipelines that build software. The report examines incidents like ChainDrop, Axios, and Shai-Hulud to show how malicious preinstall scripts, account hijacks, and memory scraping steal credentials and self-propagate. It argues that SBOMs alone are insufficient and recommends continuous visibility, execution controls, ephemeral CI servers, and short-lived credentials to stop autonomous malware.
read more →

Risk-First CISO Approach to Prioritizing AI Risks

🔒 AI gives defenders powerful discovery tools but grants attackers the same advantages, forcing CISOs to manage AI risks both externally and internally. External threats include AI-enhanced phishing, rapid exploit development, and autonomous agent attacks, while internal risks arise from uncontrolled employee use of consumer AI platforms, shared copilots, and compromised API billing. The author advocates a Risk-First approach: map AI use, prioritize controls like RBAC and data classification, improve continuous testing, and run tabletop exercises to prepare for AI-specific failures.
read more →

Ransomware Forces Shift Toward Enterprise Resilience

🔒 Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more →

ThreatsDay: Signed Drivers, AI Risks, and RCEs

🛡️ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more →

Communication Channels and Identity Risks in SaaS Era

🛡️ Enterprise collaboration platforms are now central to business workflows and have become part of the identity attack surface. Threat actors increasingly misuse trusted collaboration tools for identity phishing, impersonation, credential theft and malware delivery, often leveraging compromised accounts, external federation or guest access. Unit 42 observations show a significant rise in malicious activity tied to collaboration tools, and defenders may lack visibility into actions that occur after authentication. The report reviews techniques attackers use and offers detection and mitigation guidance, noting enhanced protection through Palo Alto Networks products.
read more →

Smashing Security Podcast Episode 481 Summary

🎙️ Smashing Security episode 481 features Graham Cluley with guest Jenny Radcliffe discussing recent social engineering incidents and emerging AI risks. They cover a prank call targeting UK PM Andy Burnham, the timing and effectiveness of social engineering, and demonstrations from Black Hat where researchers jailbroke a Unitree Go2 Pro robot dog using Google’s Gemini via kinetic prompt injection. The episode also notes other industry news and sponsor messages.
read more →

Five rules to reduce IP camera surveillance risks

🔒 This article explains where the threat to IP cameras comes from and outlines five practical rules to reduce the risk of becoming a target. It describes real-world incidents — mass hacks, livestreamed footage sales, and stalker cases — and highlights common failures such as unchanged factory passwords, insecure cloud implementations, and lack of firmware updates. The guidance covers device selection, local storage, network segmentation, and good security hygiene to lower exposure.
read more →

Revisiting Spectre Attacks on Cloudflare Workers

🔍 In 2024–2025 research, Cloudflare reassessed remote Spectre attacks against Cloudflare Workers and tested defenses introduced in 2021, notably Dynamic Process Isolation (DyPrIs). The team rebuilt a production proof-of-concept showing a reliable remote Spectre leak under production workloads, found a DyPrIs limitation, and implemented further mitigations including the V8 Sandbox and in-process isolation. The report emphasizes the attack was mitigated in production and no active exploitation was observed in the past three years.
read more →

Password spraying surge exploits MFA gaps

🔐 Huntress reported a 155x increase in password spraying in H1 2026, driven by a campaign abusing Azure CLI and IPv6 BYOIP ranges from LSHIY LLC. The attacker leveraged reused credentials and the deprecated ROPC OAuth grant to bypass MFA protections that were not applied to this flow. Rampant login attempts led to dozens of compromises while attackers rotated providers and IP ranges to evade blocking. Huntress recommends disabling ROPC, enforcing broad MFA and conditional access, and limiting Azure CLI access to necessary admins.
read more →

Back-to-School Cyber Risks Hit Education Hard

📚 Check Point Research reports that the education sector was the most targeted industry between January and July 2026, averaging 4,696 weekly attacks per organization—more than double the global cross-industry average. Attack volumes rose further in July, while APAC saw the highest regional pressure and Europe and Latin America recorded the fastest growth. Researchers also observed surges in newly registered education-themed domains and coordinated phishing campaigns targeting students and staff, often leveraging counterfeit sites and compromised legitimate pages.
read more →

Using Crime Script Analysis to Explain Cyber Attacks

🔍 Crime script analysis (CSA) breaks cyber attacks into sequences of actions, decisions, and situational requirements, making complex campaigns accessible to non-technical audiences. CSA complements models like MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain by offering a narrative view that highlights practical "choke points" for disruption. The post illustrates CSA with a business email compromise (BEC) example and explains how AI can both enable attackers and provide new detection opportunities. Practical mitigations include honeypot canary organizations, provider-side detection of malicious LLM use, email rate-limiting, and stricter payment verification processes.
read more →

UK Sees Record Rise in Fraud and Identity Crime

📈 Over 220,000 cases were filed with the UK’s National Fraud Database in H1 2026, the highest first-half total on record, according to Cifas. Identity fraud rose 9% YoY to nearly 130,000 incidents, driven by bank account and card scams which made up 68% of cases, while account takeovers and SIM-swap attacks also surged. Young adults feature prominently as both victims and perpetrators, with money muling cases up 69% and mule activity accounting for 30% of misuse filings.
read more →

RFC 9234: BGP Role Model and OTC Adoption

🛡️ RFC 9234 introduces a BGP Role capability and an Only to Customer (OTC) path attribute to encode neighbor relationships and prevent route leaks directly in the protocol. Cloudflare measured adoption by monitoring which peers send OTC to its network and discovered that two large Tier‑1 networks strip OTC. The post explains how Roles and OTC function, why OTC stripping undermines deployment, and offers guidance for operators to enable Roles for route leak protection.
read more →

AI-Driven Development Raises App Vulnerability Risk

🔍 Sonatype finds enterprise applications now contain 4.31 times more critical and high-severity vulnerabilities since AI-driven software development accelerated. The firm analyzed four years of development data and reports application creation has increased nearly fivefold in the AI era. While the median age of unresolved vulnerabilities has fallen 59%, indicating faster fixes, the growth in risk outpaces traditional security processes.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

ML-generated patterns fool vehicle detection systems

🛡️ A cybersecurity researcher developed noRecognition, a reinforcement learning model that generates patterns to defeat automated vehicle detection and license-plate recognition software. After 31 million tests, Bill Swearingen demonstrated the approach at DEF CON by wrapping a car in a pattern that prevented Flock's detection software from logging the vehicle, though the video still showed the car to human observers. The method has been tested against 11 open-source detection algorithms, and Swearingen says he continues to generate new patterns while withholding the strongest ones to avoid helping camera vendors adapt.
read more →

Data quality drives SOC AI performance gains

🔍 Security operations research shows that AI-driven SOC workflows depend more on the fidelity of underlying telemetry than on specific LLM choices. The Provably Better Data project evaluated multiple LLMs across controlled CTF and incident response benchmarks using Corelight, firewall, Snort, and NetFlow telemetry normalized to OCSF. Results found that high-fidelity protocol-aware logs produced 2–4x better outcomes in accuracy, evidence coverage, and investigation time, and reduced analyst rework and hallucinations. The study advises SOC leaders to prioritize data quality and structured telemetry when investing in AI automation.
read more →

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

Infostealers Harvest 1.7 Billion Credentials in H1 2026

🔍 Flashpoint reports 7.4 million devices infected by infostealer malware in H1 2026, marking a 27% increase from the previous half-year. The company recorded 1.7 billion harvested credentials, with Vidar, StealC and Lumma as the top variants, and highlighted a shift to automated credential-processing ecosystems. The report also details rising vulnerability disclosures and growing underground AI-driven threats.
read more →