< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 13 of 96

Weekly cyber recap: critical bugs, active exploits

⚠️ This week saw small inputs produce severe outcomes: unauthenticated RCEs in WordPress Core, SonicWall SMA zero-days exploited in the wild, OpenSSL DoS via an 11-byte payload, and a SharePoint RCE added to CISA's KEV catalog. Other notable items include the OkoBot malware framework targeting crypto wallets, the NadMesh botnet harvesting cloud keys, and a long list of high-priority CVEs that require immediate patching and investigation.
read more →

Exposure Window: The Metric That Really Matters

🛡️ This piece examines how Anthropic's Mythos accelerated vulnerability discovery but did not create the core problem: the exposure window. It explains that while AI has pushed discovery and prioritization to machine speed, mobilization—the organizational steps to actually fix vulnerabilities—remains slow. The article argues security teams must adopt speed-based metrics and attack-path analysis to reduce the blast radius and convert remediation into a measurable business risk.
read more →

AI Increases SOC Strain, Forcing Operational Change

🔍 Security operations centers (SOCs) are confronting rising alert volumes, faster AI-enabled vulnerability discovery, and increasing machine-generated outputs that create new cognitive burdens for analysts. Experts warn AI amplifies existing weaknesses—staffing shortages, alert fatigue, and technical debt—while also offering tools to manage scale. Mature SOCs with robust processes may adapt, but less-prepared teams risk burnout and overwhelm.
read more →

Search for Clean Residential Proxies in Carding

🔍 Flare researchers examined nearly 2,900 underground posts to map how carders assess residential proxies and build fraud-ready digital identities. The analysis shows proxies are judged by reputation and history rather than just being residential, and are commonly paired with antidetect browsers, device fingerprints, and billing consistency. Providers’ restrictions and takedowns have pushed demand for “finance-compatible” IPs and increased operational complexity for attackers.
read more →

Alan Turing’s World War II Voice Encryption Revealed

📜 Newly surfaced wartime papers, sold as the “Bayley papers” in November 2023, reveal details of Alan Turing’s top-secret 1943–1945 voice-encryption project called Delilah. The cache includes handwritten notes by Turing and annotations by his assistant Bayley, who preserved the documents until his death in 2020. The material outlines a portable system for encrypting speech and provides rare engineering insight into Turing’s wartime cryptologic work.
read more →

The SaaS blind spot: visibility gaps in cloud apps

🔍 Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps — audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews — can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more →

The Gentlemen Tops Ransomware Incidents in Q2

🛡️ ReliaQuest's July analysis shows The Gentlemen ransomware gang conducted 300 attacks in the three-month period, surpassing Qilin's 289 incidents. Researchers tracked 1,368 victim claims across 99 countries from 11 ransomware groups, with DragonForce, Akira and LockBit also active. ReliaQuest attributes The Gentlemen's rise to aggressive affiliate recruitment, pre-packaged intrusion kits and AI-accelerated tooling.
read more →

ACR Stealer campaigns use ClickFix lures and fileless tradecraft

🔍 Microsoft Defender Experts observed heightened ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering to lure users into running commands that ultimately harvest browser credentials, tokens, and sensitive documents. Two prevalent campaigns were detailed: one using WebDAV-delivered DLLs, staged PowerShell, Python loaders, and optional blockchain-backed dead-drop C2 resolution; the other using fileless MSHTA, obfuscated PowerShell, and steganography-assisted in-memory execution. Both aim to exfiltrate credentials and enterprise data, and Microsoft recommends monitoring for ClickFix lures, suspicious WebDAV/MSHTA activity, obfuscated PowerShell, and attempts to access browser credential stores while leveraging Defender capabilities to detect and respond.
read more →

Unit 42 2026 IR Report: AI as an Attack Multiplier

🔍 Unit 42’s 2026 Global Incident Response Report examines how AI is accelerating and streamlining attacker operations. Drawing on hundreds of engagements, the report finds AI shortens development cycles and automates reconnaissance while core attack techniques remain consistent. It stresses defenders can apply existing controls but should prioritize prevention and AI-aware skills.
read more →

AI as a Force Multiplier in Incident Response

🔍 Unit 42’s 2026 Global Incident Response Report examines how threat actors integrate AI to accelerate attacks. Drawing on hundreds of engagements, the report finds AI shortens development cycles, automates content generation and streamlines reconnaissance, compressing attack lifecycles. Despite this speed, adversaries continue to rely on established TTPs like credential theft, phishing and ransomware, meaning defenders can apply existing controls while adapting to AI-driven efficiencies.
read more →

Patch surge strains defenders amid AI‑driven finds

🔥 This week’s Threat Source highlights a record Microsoft Patch Tuesday that fixed 622 vulnerabilities, including two zero‑days being actively exploited. Cisco Talos discloses UAT‑11795, a Russian‑speaking group using trojanized installers to deliver the Python-based Starland RAT and an in-memory PowerShell implant called WLDR agent. The newsletter outlines detection guidance and emphasizes the operational stress on IT teams facing accelerated vulnerability discovery driven by frontier AI research.
read more →

Weekly roundup: emerging cyber threats and takedowns

🛡️ This week’s roundup highlights a wave of opportunistic attacks where familiar software and weak defaults are abused to escalate damage quickly. Reports include malicious NuGet packages that deliver spyware via game cheats, trojanized installers distributing sophisticated RATs, and a fast-spreading Rust ransomware incident that encrypted a network within 24 hours. Additional items cover actively exploited CVEs added to CISA’s KEV, guidance for coordinated vulnerability disclosure, large-scale fraud and money‑laundering disruptions in Europe, evasive Windows bind-link techniques, fake GitHub repos spreading an infostealer, and misuse of Chrome Sync for covert surveillance.
read more →

Operational Guardrails for AI-Assisted Vulnerability Management

🛡️ This article from Mandiant Consulting outlines practical guidance for safely integrating AI agents into vulnerability discovery and remediation workflows. It emphasizes grounding AI adoption in established frameworks such as NIST RMF, OWASP for LLMs, and Google’s SAIF, and prescribes layered defenses including deterministic policy engines, sandboxed agent workloads, zero data retention agreements, and human-led red teaming. The post also stresses threat modeling, least-privileged machine identities, supply chain vigilance for agent skills, and runtime observability to prevent data exfiltration and prompt-injection risks.
read more →

AI Helps Find Bugs but Humans Must Prove Them

🛡️ AI is accelerating offensive security by producing many potential findings quickly, but generated reports are not the same as validated evidence. AI tools can read code, generate payloads, and suggest attack paths, yet validation still requires human knowledge of systems, reachability, and exploitability. Low-quality AI submissions are already increasing triage burden, so teams must separate leads from proven findings and apply rigorous validation before driving engineering action.
read more →

When AI gets a body, it inherits an attack surface

🤖 Embodied AI systems—robots, arms, humanoids—turn models into cyber-physical assets that inherit hardware, firmware, supply-chain and remote-access risks the vendor demo hides. Buyers should evaluate five areas: provenance (hardware/firmware BOM and update authority), access (remote paths and teleoperation), integrity (sensor spoofing and model manipulation), evidence (independent field data) and accountability (contractual responsibility and liability).
read more →

SANS warns of growing AI governance gap

🛡️ The SANS Institute’s 2026 AI Survey Insights shows rapid AI adoption in security, with 78% of organizations using AI versus 50% in 2025, yet confidence and effectiveness lag. The survey of 536 practitioners and 57 leaders found rising shortcomings in detection and response and increased AI-enabled attacks, including deepfakes and adversarial exploits. SANS highlights a governance shortfall—half of leaders report formal programs while many remain in early policy stages—and urges investment in validation infrastructure, operational governance, and immediate workforce upskilling.
read more →

Smashing Security podcast episode 476 recap

🎧 In episode 476 of the Smashing Security podcast Graham Cluley and Geoff White discuss Geoff's new podcast season on the Conti ransomware gang, personal scam attempts, and a startling prank targeting e-rickshaws in India. They describe how an app called BatBMS — intended for battery management — has been misused to remotely disable electric rickshaws, creating safety and livelihood risks for drivers. The hosts also cover sponsors and lighthearted anecdotes about smartphone pranks.
read more →

AI-Aggregated Executive Profiles Increase Attack Surface

🔎 AI tools now synthesize publicly available executive information into coherent, queryable profiles that attackers can use for social engineering. These profiles collapse traditional OSINT timeframes from days to minutes and lower the skill needed to target executives. Security teams must monitor AI outputs, reduce unnecessary public exposure, and integrate AI-profile risk into executive protection programs. Training executives to view their own AI-generated profiles and assigning security ownership are essential countermeasures.
read more →

CISOs Must Rethink Vulnerability Management Now

🔍 Security experts urge enterprises to shift from scheduled patch cycles to risk-based, continuous approaches such as just-in-time patching, citing AI-driven vulnerability discovery and exploitation that outpace traditional models. Vendors warn that AI tools can rapidly surface and validate flaws, widening the gap between discovery and remediation and overwhelming teams. Compensating controls like virtual patching can help, but they are stopgaps; organizations need continuous asset visibility, real-time exploitation intelligence, and prioritization based on exposure and exploitability.
read more →

Compromised Logins Drive Most Ransomware Intrusions

🛡️ New Sophos analysis shows identity-based attacks and stolen credentials are now the leading initial access vector in ransomware incidents, responsible for 79% of cases. Malicious email and phishing remain significant contributors, while exploitation of known vulnerabilities has decreased. The report urges stronger identity controls, widespread MFA, and adoption of ITDR to reduce risk.
read more →