< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 14 of 96

Securing 2026 World Cup Stadium Networks

⚠️ Stadiums hosting the 2026 World Cup face massive cybersecurity challenges as tens of thousands of unmanaged fan devices join venue networks alongside payment systems, displays and operations platforms. Real-time visibility, network segmentation and identity-centric Zero Trust controls are essential to keep fan devices isolated from critical systems. SIEM, endpoint management and automated patching help accelerate detection and response, ensure compliance and reduce the risk of disruptive attacks during matches.
read more →

Cybersecurity Needs More Prevention, Less Cure

🛡️ Cybersecurity has drifted toward detection-first solutions, yet prevention remains more cost-effective and impactful. The industry invests heavily in visibility, alerting and response—metrics like mean-time-to-detect dominate—while compromise is often treated as inevitable. The author urges renewed emphasis on blocking threats through measures like phish-resistant MFA, segmentation and proactive patching, arguing that prevention reduces noise, lowers long-term costs, and strengthens overall security posture.
read more →

Seven Essential Traits of Elite Security Engineers

🔒 Elite security engineers combine technical depth with business awareness and continuous learning. They must be proficient with AI-powered defense tools while understanding how adversaries use AI for phishing, malware, and model attacks. Top engineers think in systems, bridge cross-domain stacks, manage third-party and machine identity risk, and communicate risk clearly to leaders. Adaptability and continuous learning remain critical.
read more →

macOS infostealer poses as Apple crash reporter

🛡️ A new macOS infostealer named CrashStealer impersonates Apple's crash-reporting component to trick users into installing a password-stealing payload. Delivered via a signed, notarized disk image called "Werkbit Setup," the dropper bypasses Gatekeeper and fetches a downloader that installs the C++-based stealer. Once active, it prompts for system credentials and exfiltrates browser-stored logins, crypto wallet access and keychain data, using client-side encryption and anti-analysis techniques.
read more →

Study Reveals Browser Wallets Enable Cross‑Site Tracking

🔎 Researchers at KU Leuven analyzed 85 popular browser-based crypto wallet extensions and found systemic privacy leaks that can link and de-anonymize users. The wallets reveal addresses in clear text to external servers, announce installed wallets to sites, and often fail to revoke access on logout. These behaviors allow separate addresses to be correlated, stale permissions to persist across sessions, and authorized wallets to expose addresses inside embedded frames, enabling cross-site tracking and potential deanonymization.
read more →

Malicious Python Packages and Supply Chain Risks

🐍 This report examines how the convenience and popularity of Python have attracted supply chain abuse, showing how malicious packages can execute code during installation and persist via .pth files or sitecustomize hooks. It outlines the installation layers (hosting, installation, environment), distribution formats (sdist, wheel), and common abuse techniques, emphasizing the rapid impact of compromised packages on development and enterprise assets.
read more →

Check Point Research: AI Security Threats 2026

🛡️ The Check Point AI Security Report 2026 documents how AI has shifted from an assistant to an operator in cyberattacks, running multi-step intrusions with minimal human direction. It highlights collapsed vulnerability response windows, widespread probing of exposed AI infrastructure, and a doubling of sensitive data leakage through approved AI use. The report recommends visibility, machine-speed defenses, and governance to protect AI systems and manage workforce AI.
read more →

Novel OAuth Client ID Spoofing Targets Cloud

🔒 Cyber-attackers are increasingly using OAuth client ID spoofing to access cloud environments by abusing Microsoft Entra ID (formerly Azure AD). Proofpoint researchers found threat actors issuing ROPC token requests to the OAuth 2.0 endpoint, producing AADSTS error codes that reveal valid usernames and authentication controls. The technique produces blank or spoofed application IDs in Entra sign‑in logs, making detection difficult and enabling large-scale campaigns targeting millions of accounts.
read more →

Jurassic Park and the Myth of Cyber Control

🦖 The article compares Jurassic Park’s failed containment to modern cybersecurity, arguing that visibility is often mistaken for control. It asserts that tooling, dashboards, and backups provide friction but not guaranteed survivability, and that dynamic cloud and AI-driven change invalidate static recovery assumptions. The piece recommends continuous resilience engineering, dependency awareness, and validation to operate through inevitable disruptions rather than assume they can be prevented.
read more →

AI Risk Registers Are Not Incident Response Plans

🛡️ Organizations are documenting AI risks but often lack an operational response when those risks materialize. A risk register can list potential failures—like inaccurate outputs or data exposures—but it does not define who can pause systems, preserve evidence, or lead an investigation. Security teams must translate governance artifacts into executable playbooks that include ownership, evidence requirements, triage, escalation and pause authority proportional to risk.
read more →

Ghostcommit attack hides prompt injection in images

🛡️ Researchers demonstrated "Ghostcommit," a proof-of-concept attack that hides malicious instructions inside a PNG referenced by an AGENTS.md so AI code-reviewing agents read images, open .env files, and exfiltrate secrets as integer constants. The pull request appears benign to text-based reviewers and default configs often exclude images from review, letting the change merge without human oversight. In tests, several coding agents followed the image pointer and emitted the repository's .env as a tuple of integers, while some agent harnesses refused. The ASSET Research Group published code, disclosed vendors, and built a multimodal GitHub app that inspects images, code shape, and conventions to block the exploit in trials.
read more →

Study: Many Free Android VPNs Fail Basic Security

🔎 Researchers tested 281 popular free Android VPN apps using a new framework and found widespread, basic security failures. The study, using MVPNalyzer, identified traffic leaks, plaintext transmissions, weak encryption, and apps that reveal identifying data to trackers. Those flagged have over 2.4 billion installs combined, and several apps enable tunnel hijacking by fetching configuration files in the clear. The paper and appendix list affected apps and the team plans to release the tool for broader use.
read more →

Building the Business Case to Reduce Security Debt

🔍 Security leaders have improved visibility into vulnerabilities across applications and pipelines, yet many organizations face growing security debt as findings outpace remediation. Treat security debt like financial debt by measuring total and critical debt, setting reduction targets, and distinguishing acceptable versus unacceptable risk. Focus remediation capacity on exploitable vulnerabilities in crown-jewel systems, establish risk-focused metrics, and increase investment in remediation and automation to align security outcomes with business priorities.
read more →

Weekly ThreatsDay: Emerging cyber risks and trends

🔒 This ThreatsDay roundup highlights a series of recent, pragmatic security incidents and research findings that stem from routine administrative mistakes and small configuration errors. It covers a multinational fraud takedown, malicious typosquatting of payment SDKs, novel code-injection techniques, and a critical unauthenticated ArcGIS Server flaw. The report also outlines ransomware tool overlaps, data-exfiltration concerns in Claude Code, social engineering campaigns abusing Teams and Meta, and multiple kernel and driver vulnerabilities.
read more →

Cloudflare on ML‑DSA and the PQ signature landscape

🔒 Cloudflare explains why ML‑DSA, the NIST‑standardized post‑quantum signature, must be used for the initial migration even though better schemes may arrive later. The post‑quantum transition is underway: most traffic already uses ML‑KEM encryption, and Cloudflare targets full post‑quantum protection by 2029. The post outlines tradeoffs among candidate signature families — size, speed, and implementation risks — and highlights why specialization and generalist schemes will both be needed.
read more →

June 2026: Global Cyber Attacks and Ransomware Shift

📈 June 2026 saw a notable rebound in global cyber attacks, with weekly incidents per organization averaging 2,270, up 10% from May and 17% year over year. Education, Government, and Telecommunications were the most targeted industries, while Latin America recorded the largest regional increase. Ransomware incidents surged 33% year over year, and The Gentlemen overtook Qilin as the most active ransomware group.
read more →

CISOs Warn Executives Lack Understanding of Cyber Risk

🔒 A MetaCompliance report (July 9) based on responses from over 200 European CISOs finds 78% believe C-level executives do not fully grasp cybersecurity risks tied to employee behaviour. The survey highlights fading leadership support for security awareness, with 79% saying backing wanes over time and 40% worried employees share sensitive data with generative AI tools. AI-driven social engineering is cited as a key factor eroding confidence in organisational cyber resilience.
read more →

Why clearinghouses aren’t the core solution

🛠️ Athena joins a crowded set of recently announced clearinghouses, but the author argues the clearinghouse itself is the least important part of the equation. Clearinghouses are simply pools of vulnerability data; the real value is in actuation — rebuilding, testing, signing, and delivering fixes where users will actually consume them. The rise of private pre-disclosure findings is a byproduct of models tested against running applications, and scale plus fast throughput matters more than the mere existence of another database.
read more →

Rise of Malicious AI Agents Threatens Organizations

🤖 ESET analysis shows cybercriminals increasingly use AI agents and chatbots to autonomously plan and execute attacks. Researchers reviewed 900,000 AI skills in public repositories and found tens of thousands of suspicious and thousands of malicious toolsets, expanding the attack surface. These agentic tools can exfiltrate data, execute malware, override instructions, and be repurposed from legitimate utilities into harmful capabilities. ESET urges organizations to enforce policies and caution users about downloading free tools from untrusted sources.
read more →

Enterprises favor convenience, increasing lateral movement risk

🔒 Zero Networks’ 2026 report, analyzing 54 trillion activities across 312 enterprise environments, finds that most internal servers remain broadly reachable and rely on legacy protocols. The study highlights that >80% of servers are accessible from anywhere inside networks, with 87% accepting RDP/SSH and 78% reachable via SMB/WinRM, while 43% still use NTLM. Experts warn this widespread internal connectivity enables easy lateral movement for attackers and call for segmentation, identity controls, and containment strategies.
read more →