< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 12 of 96

Ransomware Q2 2026: EDR-Kill Becomes Standard

🔍 Halcyon’s Q2 2026 Ransomware Evolution Report warns that shutting down endpoint detection and response (EDR) tools—known as EDR-kill—has become routine among leading ransomware groups, reducing defenders’ time to react. The Gentlemen, a prolific emerging group, incorporates reversed techniques from other gangs and explicitly includes EDR/antivirus shutdowns in attack chains. The report also notes a decline in claimed attacks but a marked rise in sophistication, faster operations, AI-assisted tactics, and the use of ransomware for state-aligned objectives.
read more →

The containment paradox in ransomware response

🔒 This article examines a recurring operational gap in ransomware incident response: SOC analysts often have the authority to isolate systems, but business owners hold accountability for service availability. It argues that isolation can itself become the damage when applied to business-critical systems and proposes a governance-based remedy: a no-touch register tied to a RACI model and time‑boxed escalation with pre-agreed safe-state fallbacks. The piece rebuts the objection that operational vetoes slow response by showing how narrow, timed vetoes protect crown-jewel services without paralyzing detection and containment.
read more →

Insurance Phishing Evolves into Real-Time Account Hijacks

🔍 Recent research shows insurance-targeted phishing has shifted from credential harvesting to real-time session hijacking. Attackers use paid Google Ads and disposable hosting to lure victims to realistic portals and then relay OTPs and credentials to authenticate on the legitimate service while the victim is logged in. CTM360 identified a bespoke kit, InsureOTP Kit, and exposed backend infrastructure revealing live session management and operator workflows. Defenders must expand detection beyond malicious pages to include ad monitoring, infrastructure analysis, and attacker workflow intelligence.
read more →

BGP ORIGIN Attribute Manipulation and Impact

📘 Cloudflare examines the BGP ORIGIN attribute, a mandatory path attribute intended to signal how a route was injected into BGP. Their experiments show widespread modification of ORIGIN values—predominantly to IGP—by many networks, including Tier-1s, altering route selection and diverting traffic for commercial advantage. The report describes methodology, measurements across IPv4/IPv6, and the resulting routing and economic impacts.
read more →

Why chat agents can read your unsent messages

💬 Live chat widgets on many websites include a real-time typing preview that lets agents see everything you type, even drafts you never send. This feature is common across popular customer support platforms and is used to speed responses and monitor quality, but it can expose sensitive information without your consent. Users rarely notice the feature and most chat widgets lack an option to disable it. To reduce risk, avoid entering personal data in chat boxes and use security tools to block malicious sites and tracking.
read more →

ChatGPT Enters Top 10 Most Impersonated Brands

🛡️ OpenAI’s ChatGPT has appeared in the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, according to Check Point. The report highlights a fake “ChatGPT Plus payment failed” email that mimicked an OpenAI billing notice to steal full credit card details. Microsoft remains the most impersonated brand, followed by LinkedIn, with Google, Apple and Amazon also in the top five. Check Point recommends inline phishing prevention, AI-powered detection and consolidated email/workspace protection to mitigate brand phishing.
read more →

Tycoon2FA takedown reshapes phishing landscape

🔎 Microsoft reports that disruption of the Tycoon2FA phishing-as-a-service platform drove a sharp decline in traditional phishing techniques, with platform-linked volume falling 92% from pre-takedown averages. The takedown reduced QR code and CAPTCHA-gated phishing and forced attackers to adapt, shifting to channels like Microsoft Teams and automated BEC campaigns. Microsoft recommends stronger email filtering and phishing-resistant authentication such as passkeys, FIDO keys, and multifactor protections to mitigate evolving threats.
read more →

Threat Source newsletter: Q2 2026 vulnerability trends

📈 This edition of the Threat Source newsletter reviews Q2 2026 vulnerability trends, noting a 49% YoY increase in tracked CVEs and roughly 200 CVEs per day by June. The author contrasts a shifting AI model landscape with slower real-world impact, highlights concerns about keyword-sensitive AI-CVE counts, and advocates prioritizing patches using EPSS rather than raw CVSS scores. Additional coverage includes Cisco Talos' discovery of the Rust-based msaRAT, new Antares SLMs for vulnerability localization, major incidents impacting land registries and WordPress sites, and tactical detection recommendations.
read more →

Weekly ThreatsDay Bulletin: Multifaceted Cyber Risks

🛡️ This week's ThreatsDay Bulletin catalogs varied, evolving threats that masquerade as useful software or ordinary files. Highlights include npm and PyPI supply-chain risks, a rogue VS Code extension, a fake Claude app delivering SectopRAT, and Android apps posing as civil-defense tools that instead enable surveillance. The report also details PLC-targeting activity linked to Iranian-affiliated actors and new AI-related exploitation techniques.
read more →

Email Threat Landscape Q2 2026: Key Findings

📊 Microsoft reports that Q2 2026 saw a sharp decline in phishing tied to the Tycoon2FA PhaaS disruption, while threat actors shifted tactics into Teams-based social engineering and vishing. Credential phishing remained the dominant payload objective, and notable campaigns demonstrated large-scale automation and multi-stage delivery chains. The post reviews QR code and CAPTCHA-gated phishing trends, BEC anomalies, and mitigation recommendations.
read more →

Q2 2026 Brand Phishing: Top Impersonated Companies

📊 Microsoft remained the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts. The top five—Microsoft, LinkedIn, Google, Apple, and Amazon—accounted for over half of observed attacks, while ChatGPT entered the top ten for the first time. Technology, social networks, and banking were the most targeted industries, and common tells included distorted logos, dead buttons, and mismatched links.
read more →

Synthetic Machine Identity Fraud and Emerging Risks

🔒 Synthetic identity fraud for machines involves attackers fabricating service accounts or credentials rather than stealing existing ones. These fabricated NHIs blend real environmental attributes with fake data to appear legitimate, evading detection because no human owner flags misuse. Techniques include rogue service accounts, DCShadow-style fake domain authorities, and shadow credentials implanted into existing objects. Defenses focus on ownership, secrets rotation, least privilege, and continuous behavioral verification.
read more →

AI agents under attack: incidents and risks 2026

🔍 Enterprises face rising attacks that exploit AI agents already present in their environments. These agents — coding assistants and CLI tools like Claude Code CLI, Gemini CLI, and Amazon Q CLI — can read files, run commands, and install packages, making them attractive targets when run with auto-approval. Real-world incidents, including the s1ngularity Nx npm compromise and the AgentJacking/Sentry experiments, show how prompt injection, compromised tool metadata, and unsecured MCP servers can lead to secret harvesting and covert exfiltration. Defenders must treat agents as potentially untrusted and adapt controls and monitoring accordingly.
read more →

AI Empowers More Convincing Ransomware Attacks

📈 A Proofpoint survey shows AI has materially increased ransomware effectiveness by enabling more convincing phishing, impersonation and credential-theft campaigns. The 2026 AI-Era Ransomware Report found AI involvement common across incidents and identified human interaction—malicious links, attachments and credential harvesting—as frequent entry points. Respondents cited legitimate-looking lures and control failures as key reasons attacks bypassed defences.
read more →

Eclypsium InfraTrust highlights top infrastructure fixes

🛡️ Eclypsium launched InfraTrust and a monthly InfraTrust Pulse to aggregate vendor infrastructure advisories and guide administrators on which flaws to patch first. The inaugural July 2026 Pulse tracked 61 advisories from 14 vendors, flagging six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities. The report emphasizes prioritizing flaws by exploitability, exposure, and real-world risk rather than CVSS alone.
read more →

2026 Exposure Gap Report: Remediation Insights

🔍 The 2026 Exposure Gap Report finds that while many organizations can identify and prioritize exposures, turning those insights into timely remediation is inconsistent. Some sectors, like Utilities, remediate in roughly 12.6 hours, whereas Healthcare averages about 158 hours. The report highlights that delays often begin before remediation—during validation and ownership assignment—and that connected workflows enable faster, repeatable remediation at scale.
read more →

Ransomware Landscape Expands with New Groups Weekly

🛡️ The Black Kite Ransomware Report 2026 finds 146 active ransomware groups as of June 2026, up from 105 a year earlier, with 61 new groups emerging in 2026 alone. The study highlights a fragmented ecosystem where groups often have short lifespans—averaging 4.9 months—and a small number of operators still account for a large share of disclosed victims. Black Kite urges organizations to prioritize rapid patching of critical vulnerabilities and strengthen identity and vendor controls to mitigate attacks.
read more →

Global Internet Traffic Shifts During the 2026 World Cup

📈 Cloudflare Radar analyzed HTTP, DNS, and security signals across its global network during the June–July 2026 World Cup to measure how matches changed Internet activity. Using a four-week median baseline and log2 ratios, the study compared per-country deviations by kickoff time, revealing large spikes for overnight matches and smaller evening bumps. The report ranks matches and teams by worldwide impact and examines regional behaviors, streaming effects, and distinct halftime and hydration-break patterns.
read more →

Open-source Android AI agents enable host command risk

🛡️ Researchers demonstrated seven attacks against five open-source Android agent frameworks, showing that benign-seeming apps with draw-over and storage permissions can inject unseen text into models and escalate to host command execution. The study, posted on arXiv in July, tested AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA, finding widespread vulnerabilities including screenshot race conditions, command injection via unsanitized adb calls, broadcast leaks, and UI spoofing. Some projects already use safer patterns, but none implemented all recommended mitigations.
read more →

Bit2Watt: GPU workloads can threaten power grids

⚠️ Three Zhejiang University researchers describe "Bit2Watt," a technique showing that ordinary GPU workloads can be modulated to produce fast, controllable power oscillations. They demonstrate two methods: a synthetic kernel (SWMA) that toggles compute intensity and an LLM-training modulation (LTMA) that embeds oscillations into real training runs. Experiments measured kHz-range power components on GPUs and simulations showed that synchronized modulation across many devices could destabilize local grids and create denial-of-service or covert channels. The work highlights a visibility gap between compute and power operators and suggests combined hardware and monitoring defenses.
read more →