< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 3 of 96

Phishing’s new realism: evolving email threats

📧 Modern email phishing now evades traditional telltale signs, using polished language, QR codes, AI-tailored lures and token-theft flows to bypass training and defenses. Attackers exploit live sessions, device hops and legitimate sites to harvest OAuth tokens or trick users into pasting commands, while deepfakes and delayed fraud increase believability. Organizations must pair awareness with verification, layered controls and MDR capabilities to detect and contain these subtler social engineering campaigns.
read more →

SOC Operations Should Build Shared Operational Memory

🔍 AI is lowering the cost of retrying failed intrusions by accelerating troubleshooting and scripting, turning what was once time-consuming research into near-instant iteration. Public reporting through 2025–2026 shows state-backed and criminal actors incorporating generative AI into reconnaissance, exploit development, and automation, though confirmed widespread deployment remains unclear. The practical impact is faster attacker experimentation while defenders still suffer handoffs, telemetry gaps, and decision latency that lengthen response cycles.
read more →

Trust Risks in Consultancy Scams and AI Malware

🔍 In this Threat Source briefing, Talos warns practitioners about social engineering that leverages flattering offers — such as paid consultancy or fake recruitment — to coax security professionals into abusing trusted access. The piece describes a staged consultation that escalates to requests for internal insights and special reports, and highlights emerging AI-integrated malware research from Talos. It outlines CAIRN, an open-source toolkit for hunting AI artifact tradecraft, and summarizes recent threats and notable incidents.
read more →

Storm-2570: Cross-ecosystem ransomware tradecraft

🔍 Microsoft details activity attributed to the Storm-2570 ransomware affiliate, showing how the actor operates across multiple RaaS ecosystems (Qilin, DragonForce, Anubis, BERT) while using consistent post-compromise tooling and techniques. The report highlights repeated use of remote management software like MeshAgent, tunneling utilities, credential theft tools, lateral movement methods, and cloud exfiltration utilities. It emphasizes analyzing actor behavior across the attack chain to detect and disrupt intrusions before payload deployment, and provides detection and defense recommendations.
read more →

SectopRAT variant hidden in legitimate Windows software

🛡️ The FortiGuard Incident Response team investigated a Windows intrusion where a SectopRAT .NET RAT was concealed inside a legitimate audio application. The malware used a tampered DLL and a multi-stage loader that extracted an encrypted payload from a DB file, initialized the .NET runtime in memory, and executed a heavily obfuscated RAT. The variant communicates over AES-encrypted channels with a hardcoded C2 and backup domains, supports 29 control commands, and steals browser, email, gaming, and cryptocurrency wallet credentials.
read more →

Most Organizations Face Microsoft 365 Governance Incidents

📊 ShareGate's State of Microsoft 365 report found 77% of global organizations experienced at least one Microsoft 365 governance incident in the past year. The survey of nearly 1,800 IT professionals across nine countries highlights failures such as lingering access for former users, audit and compliance gaps, and sensitive data reaching unintended recipients. Rapid AI adoption and overconfidence in AI controls, plus limited proactive monitoring, are cited as key drivers of increased risk.
read more →

ClickFix: Emerging dominant initial-access vector

🛡️ ClickFix is now the leading initial-access technique in enterprise telemetry, operating without exploits, attachments, or downloads. The attack uses malicious pages that copy a command to the clipboard and instruct users to paste it into native system interpreters, evading conventional detectors. Its infrastructure leverages on-chain resolution and distributed resolvers to survive takedown, and payload delivery is fingerprint-gated to evade sandboxes. Effective defenses focus on constraining clipboard writes and forcing interpreters through authenticated proxies.
read more →

Aviation’s lesson for security in the AI era

✈️ Aviation recognized the human vigilance limit and built machines that act decisively on clear, observable danger rather than asking fatigued humans to be perfect. AI shifts many knowledge workers into that high-load role, erasing obvious phishing cues and increasing opportunities for adversaries to exploit attention decay. Security must focus controls on high-consequence actions — payments, bank-detail changes, credential resets — using mechanisms that trigger on the act itself. The hard part remains earning trust in machines that must judge intent in adversarial contexts without generating prohibitive false alarms.
read more →

How Bitcoin ATM scams work and how to avoid them

🚨 Crypto ATMs let users buy or sell cryptocurrency with cash or card, but scammers exploit them to steal funds via urgent impersonation calls. Fraudsters instruct victims to withdraw cash and use a Bitcoin ATM or scan a QR code that directs payments to the criminal's wallet, which is nearly impossible to reverse. If contacted unexpectedly, never follow instructions to use a crypto ATM; verify via official channels and report incidents immediately.
read more →

Data Quality Now Top Barrier for Threat Hunters

📊 The SANS 2026 Threat Hunting Survey found that data quality and quantity have overtaken skills as the primary barrier for threat hunting programs, cited by 50% of 500 respondents worldwide. Skilled staff remain a close second at 45%, while formally defined methodologies fell to 37%, raising concerns about repeatability and defensibility. Other common constraints include budget, data standards, tool limits, and processes, and ransomware remains the most encountered threat.
read more →

Guide to Major Hardware and Firmware Vulnerabilities

🔒 This article surveys high-impact hardware and firmware vulnerabilities discovered since Meltdown and Spectre, explaining how speculative execution and other low-level design features enable side-channel leaks. It summarizes notable CPU and DRAM exploits, outlines required mitigations such as microcode, BIOS/UEFI and OS updates, and highlights cases where only silicon revisions can fully resolve the risk. The piece emphasizes long-lived exposure and coordination challenges among vendors.
read more →

Smashing Security Ep 486: Vibe‑Coded Shops Risk

📰 Smashing Security episode 486 features Graham Cluley and guest Dave Bittner discussing misconfigured AI-built websites, notably a New Zealand store using Base44 that left its site editable by anyone. The episode covers humorous consequences (crusty socks, Princess Diana plates, a Laser Kiwi) and broader concerns about low‑expertise users adopting AI site builders without proper security settings. The hosts also mention past Base44 flaws and consider the risks to small businesses adopting these tools.
read more →

Cloud Intrusions Escalate to Machine-Speed Threats

🔍 The 2026 Cloud-Native Threat Landscape Report, based on FortiCNAPP intelligence, shows that adversaries are automating cloud attacks to find, exploit, and monetize vulnerabilities at unprecedented speed. The report documents billions of reconnaissance, brute-force, and exploitation attempts and stresses that identity compromise and misconfigurations remain prime intrusion vectors. It urges security teams to adopt AI-driven, automated defenses across the entire application lifecycle to detect and respond at machine speed.
read more →

InfraTrust report: Management systems under attack

🛡️ The September InfraTrust Pulse warns attackers are increasingly targeting infrastructure management systems across vendors, with many critical flaws exploited before or soon after disclosure. Between Aug 25 and Sep 17, InfraTrust tracked 158 advisories covering 1,699 vulnerabilities, including 42 critical and several with CVSS 10.0. The report highlights chained exploits against Cisco FMC and ISE, active exploitation of SonicWall and Check Point flaws, and supply-chain and firmware weaknesses.
read more →

Kubernetes YAML can hand over a GCP organization

🛡️ When developers declare cloud resources via Kubernetes GitOps, controllers like Google Kubernetes Config Connector (KCC) act on their behalf using a platform service account. KCC authenticates with Google Cloud through a single service account that may have broad project, folder, or organization-level roles. If a user can create IAM-related resources in a namespace KCC watches, they can escalate privileges by having KCC apply bindings using its powerful account.
read more →

AI-driven malware removes humans from attack loop

🛡️ Cisco Talos reports a new malware family called CLOSEDQUORUM that uses a panel of large language models (LLMs) to fully automate command-and-control decisions and credential theft. The binary compiles tactical knowledge into model-readable prompts and constrains responses to JSON-formatted executable choices, enabling unattended execution against LSASS memory, browser-saved passwords, and crypto wallets. Researchers found the sample via the CAIRN toolkit and note the approach trades human limits for model and API weaknesses, and has not yet been confirmed in the wild.
read more →

Hidden SSID Risks and Better Wi‑Fi Protections

🔒 Hiding a Wi‑Fi SSID may seem like added security, but it’s ineffective and can expose sensitive data. Devices trying to connect to hidden networks broadcast known SSIDs, allowing attackers to capture names and map routers via BSSID. Hidden SSIDs also degrade performance and drain battery, especially in 6GHz. Use WPA3 with a long password, disable WPS, and avoid revealing SSIDs for stronger protection.
read more →

Fake AI subscription sites pose enterprise data risks

🛡️ Malwarebytes found polished websites impersonating reputable AI tools and selling subscriptions, using genuine Google authentication to appear legitimate. These sites request uploads of documents or recordings and charge from $10/month to $2,000/year while concealing real operator details. Researchers suspect a single kit and operator power multiple clones, and warn of shadow IT risk when departments buy without IT involvement.
read more →

Mixed Device Segments Increase Lateral Movement Risk

🔍 Forescout's analysis of 47,700 real-world network segments found many contain mixed device types—IT, OT, IoT and IoMT—broadening attack surfaces and increasing lateral movement risk. The study shows only a minority of OT or IoMT segments are isolated, with common co-location like IP cameras alongside workstations enabling single-point compromises. Forescout recommends continuous visibility, device prioritization, tighter segmentation and policy-based controls to prevent breaches spreading to critical systems.
read more →

Akamai: AI Spurs Major Rise in Bot and API Risk

🔍 Akamai's State of the Internet report, published on September 22, shows AI contributed to a 300% jump in bot traffic and a 113% rise in daily API attacks between 2024 and 2025. The report highlights that 87% of organizations experienced API incidents in 2025 and that AI browser extensions and unmonitored personal accounts increase enterprise data exposure. It warns that AI agents and MCP-style capabilities enable attackers to execute high-impact actions without traditional breaches.
read more →