< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports

1778 articles · page 4 of 89

Risks and Attacks Targeting Passkey Authentication

🔒 This Unit 42 analysis examines novel attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The research demonstrates how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to authenticate without user interaction, bypass user verification, and extract synced passkey private keys. The article outlines three attack variants—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—showing practical exploit paths on Windows Chrome with TPM-equipped devices and emphasizing mitigation via Palo Alto Networks products.
read more →

Operationalize third‑party cyber risk, don’t rely on heroics

🔒 Third-party risk often fails in practice because security teams are looped in too late, turning reviews into last-minute blockers. The author recommends establishing formal intake, clear timelines, and joint workflows with procurement, legal, and finance so security can assess vendors before contracts are signed. Emphasis is placed on using contracts to enforce remediation and adapting processes for risks introduced by AI and shadow IT.
read more →

ESET H1 2026 report: AI skills and adaptable malware

🔍 ESET's H1 2026 Threat Report examines how attackers are scaling operations by adapting established techniques to new platforms and leveraging AI. The vendor analyzed nearly 900,000 AI skills and found tens of thousands of suspicious instances and thousands of malicious ones. AI is appearing inside malware, exemplified by Android PromptSpy using Google’s Gemini to interpret UIs and adapt behavior. The report also highlights social engineering trends like ClickFix, rising quishing, and persistent ransomware tactics such as EDR killers.
read more →

Why device code phishing became an industrial threat

🔒 Device code phishing — the abuse of the OAuth 2.0 device authorization grant — has rapidly evolved from a niche red-team tactic into a widespread criminalized attack. Exploiting the authorization step after authentication, it defeats all forms of MFA and has been commercialized in phishing-as-a-service kits. Push Security researchers outline the attack mechanics, ecosystem growth, cross-platform risk, and detection challenges for defenders.
read more →

Microsoft confirms AI-worm spreading via Copilot

📰 A Norwegian researcher disclosed a document-borne AI worm that can hide instructions inside files used by Microsoft Copilot and other apps, enabling prompt-injection that alters generated content and propagates into new documents. Microsoft says it has implemented mitigations and follows a defense-in-depth approach, while urging updates and caution. Experts warn the attack sidesteps many existing defenses because malicious behavior emerges only when Copilot processes content.
read more →

Talos Threat Source: Q2 IR Trends and Insights

🧭 This edition of the Threat Source newsletter ties a challenging Old Rag hike to cybersecurity resilience and introduces the Talos Q2 2026 Incident Response Trends report. The report highlights spikes in authentication abuse and advanced phishing techniques, including QR-based lures and ARToken platforms, while noting ransomware groups abusing legitimate remote management tools. It recommends phishing-resistant MFA, behavior-based monitoring, centralized logging, and prioritized patching.
read more →

ThreatsDay: AI-Driven Attacks and Widespread Malware

🛡️ This week’s ThreatsDay Bulletin surveys a wide set of active campaigns and vulnerabilities, from phishing that delivers XWorm and LunaSpy to custom ransomware (GenieLocker) and crypto-focused stealers. Reports detail fileless WebDAV execution, supply-chain hardening by GitHub, a My Eicher fleet takeover flaw, and AI-agent-driven autonomous exploitation across multiple CVEs. Enterprise and consumer impacts include large data exposures and targeted SaaS account takeovers.
read more →

After the Break-In: What Attackers Do Inside

🔍 This Huntress investigation examines a June intrusion that began via an SQL injection on a public web page. The attacker performed reconnaissance, enabled RDP, created an admin account, disabled Windows Defender, and installed backdoors and malicious IIS modules. They also deployed a hidden cryptocurrency miner and used silent PowerShell scripts to persist and evade detection. The report highlights why fixing the root cause is as important as removing attacker tools.
read more →

Sysadmin AI Expectations Fall Short by 2026

🔍 Action1 surveyed over 1,000 sysadmins worldwide to compare 2024 expectations of AI and automation against the state of adoption in 2026. The report finds substantial shortfalls in areas such as patch management, monitoring, vulnerability prioritization and incident remediation, with predicted full automation far exceeding current implementation. Adoption is, however, growing selectively: many admins use AI for analysis and recommendations under supervised models while retaining authority over critical decisions. Concerns remain around privacy, accuracy, cost and job impact.
read more →

Why silent phone calls are a growing threat

📞 Silent phone calls — a brief ring followed by muted silence — are increasingly common and can come from benign sources like misconfigured devices or overloaded call centers as well as robocallers, AI dialers, debt collectors, stalkers, and outright scammers. These calls are often used to verify active numbers, harvest short voice samples, or test lines before follow-up contact. While a single silent ring rarely causes direct harm, repeated interactions can enable voice deepfakes and social-engineering attacks. The article explains motives, risks, and practical steps to reduce exposure.
read more →

Why screenshots can no longer be trusted proof

🛡️ Screenshots are merely images of what appeared on a screen and can be easily fabricated or altered. They may provide context but do not reliably prove who created the content or whether an underlying transaction actually occurred. Consumers and businesses should treat screenshots as supporting material only and seek original records, transaction references, or verification from the issuing service. Organizations must update verification processes to avoid fraud, operational costs, and reputational or regulatory harm.
read more →

Survey Finds Major Gaps in Incident Response Readiness

🔍 New research shows that despite tools and teams, many organizations lack the coordination, visibility, and executive alignment to handle major cyberattacks effectively. The Vanson Bourne survey of 600 security leaders found 73% would not be "fully ready" for a significant incident and 76% experienced at least one attack in the past year. Key issues include stakeholder friction, blind spots across IT/OT/cloud, and delayed legal and communications involvement. The report recommends clearer decision rights, cross-functional exercises, validated visibility, measured AI adoption, and reassessment of external support.
read more →

IBM: Average Data Breach Cost Nears $5M

🔍 The 2026 IBM Cost of a Data Breach Report, published on July 29 and based on incidents at 602 organizations between March 2025 and February 2026, found the global average breach cost rose 12% to $4.99 million. Lost business and long-term reputational damage are key drivers of cost, while healthcare remains the most affected sector. The report also highlights a surge in AI-driven attacks, which added about $1 million to breach costs, and recommends zero trust and stronger data governance.
read more →

AI-Found Flaws Exploited at Similar Rates

🔍 VulnCheck's H1 2026 analysis finds that vulnerabilities discovered with AI tools are being exploited in the wild at roughly the same rate as those found without AI. Of 1,061 AI-attributed findings, 14 (1.3%) were confirmed exploited, closely matching the overall exploitation rate for the period. The report also notes that Anthropic's Project Glasswing produced over 23,000 findings but only 126 led to CVEs and one confirmed exploitation. The researcher concludes frontier AI currently appears to help defenders more than attackers.
read more →

Cyber-enabled cargo theft rises sharply in logistics

🚚 Cyber-enabled cargo theft is surging as logistics systems modernize and attackers exploit fragmented processes and weak security. The shift to connected vehicles, telematics and online freight systems has expanded the attack surface, enabling schemes like GPS spoofing, eBOL tampering and carrier impersonation. Criminal rings coordinate cyber intrusions with physical operations to divert high-value shipments, prompting increased attention from law enforcement and calls for industry collaboration.
read more →

AI-Enhanced Phone Farms Fuel Low-Cost Scams

📱Researchers found that off-the-shelf, AI-enhanced phone farms let operators run large-scale scams for a few thousand dollars a month. Human Security’s Satori team bought and reverse engineered a kit and documented its components: salvage hardware, cloud phone services, orchestration tools, and an AI layer that automates conversations. The report, published July 28, highlights how these elements lower barriers to entry and scale romance, ATO and investment fraud.
read more →

Risk‑Based Patching: Rethinking Vulnerability Prioritization

🛡️ CISA’s Binding Operational Directive (BOD) 26-04 shifts federal vulnerability management from uniform deadlines to risk-based remediation, prioritizing exposures most likely to be exploited. The directive recognizes that CVSS scores alone don’t capture exploitability, reachability or operational context. With AI accelerating attack lifecycles and expanding the attack surface via copilots and integrations, defenders must adopt continuous exposure mapping and validation. The article argues defenders need adversary-aware testing, business-aligned prioritization and a move from patch counts to exposure-centric strategies.
read more →

How attackers bypass multifactor authentication risks

🔒 This article examines prevalent methods attackers use to bypass multifactor authentication (MFA), from MFA fatigue and social engineering to cookie theft and targeting weak or non‑MFA accounts. It summarizes survey findings on uneven MFA adoption, highlights real-world incidents (Okta, Uber), and notes industry guidance favoring phishing‑resistant and passwordless approaches. The piece concludes with concrete defensive steps such as adaptive authentication, tightening access rights, and reviewing password reset workflows.
read more →

Q2 2026 Summary of Major Internet Disruptions

🛰️ In Q2 2026 Cloudflare Radar documented notable Internet disruptions worldwide, from Super Typhoon Sinlaku near Guam to frequent government-mandated shutdowns in Sudan. The quarter also included Iran’s partial restoration after an 88-day blackout, AWS region outages following drone strikes, a DNSSEC mishap affecting Germany’s .de zone, and a submarine cable cut impacting Saint Lucia. These incidents highlight the fragility and interdependence of global Internet infrastructure.
read more →

Phishing Now Leading Initial Access in Incidents

📈 Analysis of incidents from March to June 2026 shows phishing was the initial entry vector in just over half of cases requiring remediation, up markedly from the prior quarter. Cisco Talos researchers highlight increasingly sophisticated campaigns, including QR code-based credential harvesting and use of trusted cloud hosting to evade detection. The report also warns that advanced Phishing-as-a-Service kits and post-compromise toolsets are expanding capabilities and recommends phishing-resistant MFA, logging, patching, and stricter email controls.
read more →