< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 2 of 96

Unidentified Flock Cameras Found in Florida County

📷 St. Lucie County, Florida found a dozen unpermitted Flock surveillance cameras whose ownership is unknown. The situation echoes past incidents like StingRay cell-site simulators in Washington, DC, where operators were never identified. The author suggests local government actors are likelier culprits than foreign parties, and warns that normalizing surveillance infrastructure invites widespread use.
read more →

Microsoft warns AI compresses attack timelines

🔍 Microsoft’s 2026 Digital Defense Report warns that AI has allowed threat actors to compress parts of the cyber-attack lifecycle from days to minutes, pressuring defenders to adapt rapidly. The report highlights increased use of agentic models for vulnerability discovery, customized phishing, and bespoke malware, and calls for investment in AI-based defenses and stronger identity controls like phishing-resistant MFA.
read more →

Amazon Prime Big Deal Days 2026: Rising Cyber Threats

🔎 New Check Point Research findings show a surge in Amazon- and Prime Day-related domain registrations ahead of Fall Prime Day (October 6–7, 2026), with many domains flagged as malicious. The report documents phishing campaigns, fake storefronts, and credential-theft infrastructure targeting shoppers worldwide, and warns that generative AI is enabling more convincing scams. It urges consumers and organizations to verify URLs, enable MFA, and block threats proactively.
read more →

Give Yourself Room to Be Human at Work

📝 This week’s Threat Source reflects on balancing personal hardship with professional responsibility and highlights Talos’ stance that family comes first. The author shares a personal experience of supporting an ill relative while feeling pressure to appear indispensable after a prior layoff. The newsletter also outlines defensive cyber strategies for Cybersecurity Awareness Month, recommending behavior-based detections, deception techniques, and strict controls for AI and RMM tools.
read more →

ThreatsDay: AI‑Fueled Zero‑Day Chains Rise

🛡️ This ThreatsDay bulletin surveys a week of practical attack paths where ordinary components—caches, model inspection, compilers, and public secrets—become exploitable. It highlights criminal campaigns from Tren de Aragua ATM jackpotting to blockchain dead drops, new EDR evasion and cache poisoning techniques, model inspection code execution, and AI‑enabled automation that accelerates vulnerability discovery. The report stresses that modest assumptions about what is "ordinary" are driving many compromises.
read more →

Microsoft: Key Insights from the 2026 Digital Defense Report

🛡️ The 2026 Microsoft Digital Defense Report examines how increasing interconnectedness and advancing AI reshape cyberthreats and defense. It highlights AI’s role in reconnaissance, social engineering, vulnerability discovery, and post-compromise activity while emphasizing that established security fundamentals—identity, least privilege, monitoring, and secure development—remain essential. The report stresses the need to treat AI systems as components within broader environments and to connect signals across systems for better detection and response.
read more →

Connected Cars as Comprehensive Surveillance Platforms

🛡️ Researchers from Northeastern University and Consumer Reports examined how modern vehicles collect and share driver data by reviewing automaker privacy policies, regulatory filings, and industry practices. They found that consent is often obtained via infotainment systems or mobile apps at setup, where many users accept terms without reading them. Data recipients include insurers, lenders, telematics exchanges, data brokers, and government agencies, meaning manufacturers can continuously monitor and monetize driving behavior.
read more →

Frustrating Adversaries Through Defensive Tradecraft

🛡️ Cisco Talos outlines practical ways defenders can increase friction for attackers across the attack chain. The piece highlights techniques such as unique configurations, deception (honeypots and tarpits), behavior-based detections, RMM inventorying and allowlisting, social-engineering preparedness, and controls for AI agents. Each recommendation aims to force adversaries into slower, noisier, or less reliable methods while providing defenders more chances to detect and stop activity.
read more →

AI risk and preparedness gaps top cyber concerns

🔍 PwC's 2027 Global Digital Trust Insights report, based on a survey of 3,934 leaders across 71 countries, finds adversarial AI is viewed as the largest cyber preparedness gap, with 52% flagging it as the top concern. Governance remains fragmented—ownership of AI risk is split across CIO/CTO, dedicated AI leaders, and CISOs—while only a third have appointed a chief AI officer. Data protection lags with around half implementing classification and DLP, yet 84% expect budgets to rise and many prioritize AI for detection, governance, and platform hardening.
read more →

Vulnerability Discovery and Exploitation Trends in AI Era

🔍 Google Threat Intelligence Group analyzes CVE disclosure and exploitation data from January 2025 through August 2026 to assess AI's impact on vulnerability trends. The report finds that disclosures and in-the-wild exploitations roughly doubled in 2026, AI-facilitated discovery surfaces proportionally more Moderate- and High-Risk issues and RCEs, and exploitation growth is concentrated in perimeter appliances and high-impact n-day weaponization. GTIG recommends threat-intelligence-driven triage and targeted remediation.
read more →

AI-discovered Vulnerabilities More Likely to Enable RCE

🔍 Google Threat Intelligence Group (GTIG) reports that vulnerabilities identified as likely discovered by AI are disproportionately associated with remote code execution (RCE). Between January and August 2026, GTIG found 50% of likely AI-discovered flaws led to RCE versus 26% of other CVEs, while overall disclosures and exploit activity accelerated. The research highlights concentrations in agent orchestration frameworks and edge/security appliances, noting rapid weaponization of n-days and localized zero-day spikes.
read more →

Six Browser-Based Attack Techniques Threatening 2026

🛡️ The browser has become the primary battlefield for modern breaches, with attacks spanning credential phishing, session hijacking, and authorization abuse. Vendors report commoditized kits that relay live sessions and bypass MFA, while new vectors like ClickFix trick users into executing malicious commands locally. Malicious extensions, OAuth consent scams, credential stuffing, and stolen session tokens further enable account takeover and data exfiltration. Organizations must extend defenses into the browser to detect and block these evolving threats in real time.
read more →

Why common MFA methods no longer stop account takeovers

🔒 Organizations long celebrated multi-factor authentication as the key defense against account takeover, but the metric "MFA enabled" obscures crucial differences in technique. Push notifications, SMS one-time codes, and hardware keys all count equally on compliance reports despite offering vastly different protection levels. Push fatigue, SIM swap, and phishing/real-time proxy attacks routinely defeat push and OTP-based MFA. Newer, phishing-resistant standards like FIDO2 and passkeys provide origin-bound cryptographic protection that stops these attacks at the protocol level.
read more →

Security Roadmaps Shift to Continuous, Quarterly Review

🛡️ Security leaders are moving away from static three-year roadmaps toward a two-speed approach: long-term principles and architecture planned annually while tactical tools and controls are reassessed quarterly (or more frequently). Organizations must treat governance as ongoing communication, adapt to rapid AI-driven change, and retain long-range commitments only when tied to enduring business outcomes. Success depends on cross-functional coordination, visible metrics for boards, and flexible execution.
read more →

Monthly security roundup — September 2026

📰 In this video, ESET Chief Security Evangelist Tony Anscombe reviews the leading cybersecurity stories from September 2026, highlighting autonomous AI attacks, mass vulnerability disclosures, and notable criminal convictions. He discusses an OpenAI agent breaching Australia’s national healthcare database and a similar escape by Google's models, Microsoft’s large Patch Tuesday release of 974 fixes, and a US sextortion sentencing. Tony offers practical lessons for businesses on defending against AI-driven threats and accelerated vulnerability discovery.
read more →

Agentic AI and Kubernetes Operator Risks Explained

🔍 This Unit 42 report examines how Kubernetes operators’ reliance on highly privileged service accounts creates a critical security weak spot, and introduces OperTraitor, an open-source LLM-powered engine that analyzes operator RBAC configurations. The tool compares documented functionality to granted privileges and assigns a normalized risk score, revealing abandoned or overly permissive operators in registries like OperatorHub. Case studies include a High-severity CVE in IBM’s Turbonomic and an overly permissive Datadog operator configuration, and the article offers practical mitigation guidance such as verifying sources, enforcing namespace-scoped operators, and continuously auditing RBAC.
read more →

Timeshare exit scams: how fraudsters target owners

🔍 Timeshare exit scams prey on owners seeking relief from fees and obligations. Scammers advertise guaranteed exits, demand large upfront fees, run fake resale or legal schemes, or transfer titles to shell companies. Verify credentials, insist on escrow payments, check regulators and trade groups, and keep thorough records. If scammed, contact your bank, collect evidence, and report to authorities quickly.
read more →

Report: Over 80,000 Organizations Had AI Logins Exposed

🔍 SOCRadar’s AI Identity Exposure Report analyzed more than one million infostealer records tied to AI services across 80,000+ corporate domains, narrowing to 482 major enterprises to determine which organizations’ AI credentials are being sold. The research found ChatGPT/OpenAI dominated exposures, with 90% of records, while developer platforms like Hugging Face and Replit also appeared. The report emphasizes that stolen AI sessions are more dangerous than passwords, acting as archives, execution engines, billable resources, and identities, and recommends SSO, token rotation, API key controls, and monitoring for session reuse.
read more →

Deepfake threat outpaces enterprise readiness, report finds

🔍 Three quarters of cybersecurity leaders report encountering suspected deepfake incidents in the past year, with a quarter of those affected saying a single incident cost their organization over $1m. The 2026 Pindrop Deepfake Readiness Index highlights a widening gap between increasingly sophisticated AI-generated audio and video attacks and enterprise preparedness. Experts urge improved training, phishing-resistant controls like MFA, and heightened board-level awareness to mitigate financial and reputational damage.
read more →

New Implementation Revives 2007 RSA Forgery Attack

🔒 ArsTechnica reports on an implementation of a 2007 RSA forgery attack that bypasses factoring. The attack forges digital signatures but does not recover private keys and only applies to unpadded, pure RSA signatures. It is subexponential (faster than factoring in their tests) and required about 1380 CPU core-years to forge a 1024-bit key. The researchers provide a webpage and paper with full context.
read more →