< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports

1778 articles · page 2 of 89

DecryptAds reveals who’s tracking you online

🔍 DecryptAds is a free service that scrapes and correlates public adtech files (ads.txt, app-ads.txt, buyers.json, sellers.json) to reveal which companies can run ads or harvest data from websites and apps. The site presents consolidated profiles, legal dossiers, and geo-risk warnings to help researchers and security teams trace malvertising, ad fraud, and opaque ad-supply chains. Its API and quiet-removals feed enable automation and visibility into removed sellers and reseller relationships.
read more →

Reframing cyber backlogs: roles, priorities, and outcomes

🔍 Security teams should oversee risk rather than perform every remediation task. Assign clear roles: security maintains the authoritative risk inventory, prioritizes findings, escalates missed commitments and verifies closure, while infrastructure, cloud, application and business owners execute fixes. Executives resolve resource conflicts and accept residual risk. Backlogs typically reflect organizational failures in ownership, capacity and decision-making rather than purely technical deficiencies.
read more →

Five key security takeaways from Black Hat 2026

🔐 AI dominated Black Hat and DEFCON discussions, highlighting both its value as a defense tool and the risks posed by autonomous agents and malicious AI skills. Speakers urged moving beyond reactive patching toward durable designs, memory-safe languages like Rust, and automated remediation. Researchers revealed AI-based supply-chain attacks, methods to use GitHub telemetry for detections, and human-led AI research uncovering new vulnerabilities. A NAT-based attack class called NatJack was disclosed, prompting vendor patches.
read more →

Solar eclipse caused measurable internet traffic dips

🌑 Cloudflare Radar analyzed HTTP request volumes during the August 12 total solar eclipse that crossed Iceland, northern Spain and Portugal, comparing five-minute slices to a same-weekday baseline. The data show pronounced traffic declines aligned with maximum obscuration, with regions along the path of totality dropping roughly 15–30% and rebounds occurring within minutes. Variations reflect local factors like time of day, cloud cover, and population distribution, while calculations used precise geometric obscuration of the sun and moon.
read more →

Weekly ThreatsDay: GhostJacking and New Attacks

📰 This ThreatsDay Bulletin aggregates a week of security updates across cloud services, AI agents, malware, data breaches, scams, and novel attack techniques. It summarizes campaigns like City-Forum targeting guest access in Salesforce and ServiceNow, the ShipMonk customer data exposure, and Cursor's pre-trust code execution flaw. The bulletin also highlights vishing platforms, AI agent hijacking (GhostJacking), defensive prompt-injection use, and other noteworthy incidents.
read more →

Talos Threat Source: Phishing Frameworks and Trends

📰 Cisco Talos highlights a newly discovered real-time phishing framework named JWR, likely related to The Outsider phishing-as-a-service. JWR uses WebSockets to capture live keystrokes and steer victims through fraudulent checkout and login flows, often delivered via SMS lures impersonating toll or postal authorities. Operators can harvest payment data, 2FA codes, identity documents, and device fingerprints, enabling MFA bypass and extensive follow-on fraud. Talos recommends user education on smishing, monitoring for unusual authentications, and adopting phishing-resistant MFA like FIDO2.
read more →

AI watermark removers proliferate with unverifiable claims

🛡️ A rapid market has emerged for tools claiming to remove invisible AI watermarks after Anthropic enabled hidden marks in Claude outputs. Some projects strip metadata and hidden characters reliably, but none can currently be proven to defeat Anthropic's model-level watermark because the vendor has not published the detector or full technical details. Many commercial sites promise full removal, often measuring results against ordinary AI detectors rather than the undisclosed Claude watermark; independent code review shows gaps and unaddressed payloads. The ecosystem — open repos, web tools and agent skills — creates a potentially risky supply-chain surface if integrated directly into pipelines.
read more →

Ransomware Q2 2026: Spread and Shifting Threats

🔍 Data leak sites recorded 2,139 ransomware victims in Q2 2026, effectively flat versus Q1 and up 33% year over year. The top 10 groups still accounted for most victims, but active groups rose to a record 93. Leaked chats from The Gentlemen showed a nine-person core using AI coding tools to rapidly build a top-tier operation, highlighting the need to prioritize initial access, exfiltration detection, and exposure reduction.
read more →

July 2026 Cyber Threats: Ransomware and GenAI Risks

🔒 July 2026 saw a marked uptick in cyber incidents, with weekly attacks averaging 2,336 per organization and ransomware victims rising sharply. Education, Latin America, and Business Services were among the most affected, while GenAI use exposed sensitive data through risky prompts. Email remained a primary entry point as organizations confront multi-vector threats and growing operational exposure.
read more →

Perimeter Recovery Masks Weak Interior Defenses

🔍 Picus Labs' Blue Report 2026 shows perimeter defenses improved in H1 2026, with prevention rising to 69% and logging at a four-year high of 58%. However, post-compromise prevention inside networks remains weak at 37%, and quiet techniques like reconnaissance and credential theft largely evade controls. The findings highlight signature-dependent gaps and declining IOC-based prevention, urging validation of exposures and stronger detection engineering.
read more →

Legacy software bugs that lingered for decades

📰 This article reviews a series of long-dormant vulnerabilities—some more than 30 years old—unearthed and finally patched in recent years. It highlights how AI-powered analysis and deep inspections have accelerated the discovery of latent flaws across widely used projects such as libpng, PostgreSQL, Nginx, and the Linux KVM module. The piece explains the origins, exploitation risk, and remediation status of each bug, emphasizing supply-chain and infrastructure impacts and urging administrators to apply available patches.
read more →

Cloudflare: Massive rise in >1 Tbps DDoS attacks

🛡️ Cloudflare reported it mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, a more than fivefold increase from Q1's 130 such events. The company, which protects roughly 20% of the web, also defended against a record 31.4 Tbps attack by the Aisuru/Kimwolf botnet. In H1 it mitigated 23.2 million network-layer attacks and handled 29.64 trillion malicious HTTP requests, while noting most attacks remained small and short-lived.
read more →

Cloudflare DDoS Threat Report H1 2026 Summary

📊 Cloudflare's H1 2026 DDoS Threat Report from Cloudforce One summarizes DDoS activity across January–June 2026. The report details mitigation of 23.2 million network-layer attacks and 29.64 trillion HTTP requests, highlights April as a peak month, and describes growth in hyper-volumetric and reflection-based vectors like CLDAP. It emphasizes the necessity of automated, always-on protection.
read more →

Using GitHub telemetry as an EDR-style detector

🔍 Researchers at Black Hat USA 2026 demonstrated that GitHub’s native telemetry can be used like an EDR to detect supply-chain attacks by monitoring event streams, webhooks, API data, and Git history. Their open-source GitHub Threat Detector implements behavioral detections from recurring attacker techniques—such as forged commit metadata, mass tag poisoning, workflow abuse, and OIDC token misuse—into correlated rules. The tool uses a PostgreSQL-backed activity store for historical correlation and includes production and beta detection rules, though it faces practical limits from disabled webhooks and API rate limits.
read more →

UK Manufacturing Cyber Resilience Falls Short

🛠️ A new Make UK report finds that around 30% of UK manufacturers experienced a cyber incident in the past year, often through their supply chain. The study highlights significant operational and financial impacts, including production delays and material shortages, while many firms still lack formal response plans, CISO roles or clear cyber insurance coverage. The report urges board-level attention and improved supplier assurance.
read more →

Weekly recap: AI autonomy, Metabase zero-day

⚡ This week’s recap highlights AI models acting autonomously to target open-source projects, a critical zero-day in Metabase allowing unauthenticated SQL injection, and new CPU-level attacks bypassing Spectre v2 defenses. It also covers webmail CSS attacks, vishing campaigns by UNC6671 against financial firms, Chinese router backdoors in Zbtlink devices, and shifting ransomware behaviors.
read more →

Rise of polyglot file attacks and defenses

🛡️ Files created with the polyglot technique are increasingly used in cyberattacks to evade filters and confuse investigators. Attackers craft files that can be interpreted as multiple formats (for example, PNG or ZIP) so different applications or scanners see different contents. Real-world campaigns have used EXE/ZIP, PDF/DOC, MSI/JAR, DLL/HTML and multi-archive polyglots to deploy malware like PhantomPyramid, StrRAT, Ratty and IcedID. Defenses rely on consistent security hygiene and targeted testing of detection tools.
read more →

SOC playbook for OAuth client ID spoofing detection

🔎 This article explains how OAuth client ID spoofing can evade per-application volume thresholds by rotating or fabricating the client ID field, turning valid credential checks into stealthy attacks. It outlines key Entra ID error codes (AADSTS50034, AADSTS50126, AADSTS700016) and shows why AADSTS700016 paired with many distinct client IDs is a critical triage signal. The piece describes two large campaigns that produced millions of spoofed IDs, provides a Kusto detection query to correlate cardinality and error sequences, and recommends a short response runbook (reset, revoke, review) plus long-term mitigation by retiring ROPC.
read more →

Seven key trends shaping the cybersecurity market

🛡️ AI is reshaping the cybersecurity market as VC funding soars and incumbents race to integrate agentic AI features, driving robust M&A activity. New AI-centric product categories such as LLM security, model integrity, and AI governance are emerging while platforms and managed services gain momentum. Quantum security and DSPM are rising priorities as organizations seek integrated, AI-native defenses.
read more →

Real emails and clipper attacks hijacked payments

🛡️ Gen Threat Labs examined two H1 2026 campaigns where attackers used legitimately compromised accounts and local system manipulation to intercept payments. The first campaign abused corporate mailboxes to deliver JavaScript droppers that progressed through PowerShell and shellcode to modify proxy and browser settings for banking fraud. The second used a Rust-based clipboard clipper that replaced copied crypto addresses and read C2 pointers from Binance Smart Chain smart-contract data.
read more →