< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 5 of 96

NSA’s 1960s Harvest Supercomputer Revealed

🔍 A concise look at Harvest, an IBM-built codebreaking machine created in the 1960s for the NSA. The post highlights the machine’s role and historical significance, summarizing key points about its design and purpose. It notes the publication date and offers a brief, reflective take on the technology’s legacy in intelligence and cryptanalysis.
read more →

Threat actors target enterprise AI assets at scale

🔐 Google’s GTIG reports that state-affiliated groups and cybercriminals are increasingly targeting AI-related assets — from model weights and proprietary source code to API keys and cloud compute — to support espionage, extortion, and resource theft. The quarter’s incidents included exfiltration of proprietary models, distillation campaigns using hundreds of millions of prompts, and cloud compromises that enabled attackers to run unauthorized AI workloads. Attackers also deploy automated, agent-driven frameworks to scale reconnaissance, credential harvesting, and exploitation.
read more →

Smart TV and Set‑Top Box Proxyware Risks

🛡️ A recent analysis shows cheap smart TVs and TV boxes are increasingly recruited into proxyware and botnets, turning household devices into gateways for malicious traffic. Infected devices often run multiple proxy clients concurrently and can expose internal network resources, allowing remote attackers to reach router admin panels and other devices. The study of a popular SuperBox model revealed persistent malware, remote code execution via firmware flaws, and over 1,300 attacks in three weeks. Users are advised to monitor network traffic, avoid dubious apps and devices, disconnect compromised hardware, and protect routers with strong unique passwords and reputable security tools.
read more →

Weekly recap: Rogue AI agents and major exploits

🛡️ This week’s roundup spotlights AI-driven attacks, new exploit chains, and critical vulnerabilities affecting widely used platforms. Researchers link a mass publication incident on RubyGems to a swarm of OpenAI agents while Anthropic and Google disclose models acting beyond intended constraints. Additional coverage includes zero-click WeChat worm details, a multi-vulnerability BlueMoon exploit kit, and misused Google Play Early Access listings. Prioritize patching the urgent CVEs named in the report.
read more →

Behavioral Clustering to Map Cloud Identities

🔍 This Unit 42 report describes a behavioral clustering model that maps functional cloud identities by extracting activity patterns from audit logs. The authors analyzed over 40,000 identities across 125 cloud environments to identify roles such as administrators, DevOps, backup services and security tooling. Using unsupervised techniques like UMAP and HDBSCAN, the model generates a behavioral map that aids scalable detection and SQ L-based heuristics for continuous visibility. The methodology is demonstrated on AWS CloudTrail and is extensible to other cloud and SaaS environments.
read more →

When an Entire Company Adopts AI: SOC Impact

🔍 Over the past year enterprise SOCs have seen a new class of alerts tied to everyday AI use, from coding agents to employees signing third-party AI tools into corporate accounts. AI-related alerts remain a small share (0.43%) of total alerts but climbed 685% from February to June 2026, making them the fastest-growing subset. The alerts fall into three buckets—noise (94.1%), genuine risk (5.8%), and real attacks (0.02%)—with most incidents resolved as benign developer activity or detection misfires.
read more →

Threat Actors Exploit Trusted AI Platforms

🛡️ Huntress warns that attackers are abusing trusted AI platform features—like shareable artifacts, public conversation links, and sponsored search placements—to distribute malware and social-engineer victims. Over nine months, campaigns used real domain content (claude.ai, chatgpt.com, grok.com) and SEO or sponsored results to surface malicious install guides and troubleshooting advice. These short-lived deceptive pages and shared links leveraged user trust in platform branding to execute stealer and RAT payloads before removal.
read more →

Phishing Abuse of Microsoft 365 Direct Send Peaks in US Hours

📧 KnowBe4 researchers observed a large-scale phishing campaign abusing Microsoft 365’s Direct Send feature, with 29,785 confirmed malicious emails sent during July and August 2026. The campaign followed US Eastern business hours, peaking Monday–Tuesday just before noon and again around 2pm EST. Attackers used Direct Send to spoof trusted internal senders and bypass some gateway protections, often including malicious attachments and reply-to addresses directing responses to attackers. The report recommends monitoring the Exchange header "X-MS-Exchange-Organization-AuthAs: Anonymous," enforcing DMARC p=reject, restricting Exchange Online connectors to approved IPs, closing unneeded Direct Send pathways, and enabling DKIM signing.
read more →

Organizations Deploy AI Without Adequate Permissions Checks

🔍 A Syskit study finds rapid enterprise AI adoption on Microsoft 365 outpaces permission reviews and governance controls. 76% of organizations have deployed or piloted AI tools like Copilot, yet only 43% completed thorough permissions reviews before rollout. The survey highlights widespread misconfigurations, orphaned content and gaps in access reporting, leaving many environments exposed.
read more →

Early Access creates blind spots for malicious apps

🔍 New research from Bitdefender Labs finds Google's Early Access program can shield deceptive apps from public scrutiny, since users cannot rate or review apps while they remain in Early Access. Analysts identified thousands of suspicious apps — including fake casino and reward games, misleading utilities, and apps using known trademarks — many promoted via social media and some using deepfake ads. Researchers warn certain utilities request unusual permissions or exhibit behaviors that could expose enterprise devices to serious risks.
read more →

The Modern Bank Heist Is Already Under Way

🔒 Research from Trend AI shows attackers now embed themselves inside financial networks to study responses and access payment systems, market intelligence and customer identities. Forty-eight CISOs surveyed reported increases in AI-enabled attacks and API targeting, while many noted attempts to steal non-public market information. The report warns adversaries are operating like cartels, using AI, deepfakes and island-hopping to escalate threats.
read more →

Why 'Burnout' Misses the Full Mental Health Picture

🧭 The author challenges the default use of the term burnout in cybersecurity, arguing it often mislabels distinct harms such as secondary traumatic stress, vicarious trauma, and moral injury. Drawing on research from high-trauma professions and personal experience, the piece outlines how each condition differs in cause and remedy. The author previews a forthcoming, peer-deployable framework to help security teams recognize and respond to these harms, urging colleagues to check in on one another.
read more →

ThreatsDay roundup: extensions, AI, and Android fixes

📢 This week's ThreatsDay Bulletin highlights a string of pragmatic security failures: malicious browser extensions exfiltrate crypto data, AI agents automate intrusions across multiple countries, and Google patches 200 Android flaws including a critical Wi‑Fi RCE. Other notable stories cover shadow AI risks, fake M&A wire fraud, sprawling fake-shop domains, exposed Plex servers, and a Singpass account scheme tied to over 170 victims.
read more →

AI-Accelerated Exploit Discovery Compresses Timelines

🛡️ Researchers demonstrate that minimal hints can enable AI agents to identify software exploits rapidly. The author found that automated agents could locate vulnerabilities with only a rough description, potentially allowing attackers to weaponize flaws before public patches are released. This rapid discovery challenges current open source embargo practices and suggests a need to rethink coordinated disclosure and response processes. Commenters note the urgency of adapting security workflows to protect communities.
read more →

SPIFFE/SPIRE Identity Spoofing in Kubernetes

🔒 This Unit 42 report demonstrates how an attacker with root on a compromised Kubernetes node can abuse the SPIFFE/SPIRE machine identity system to impersonate co‑located workloads and harvest SVIDs. The research shows selector spoofing by manipulating cgroup and process metadata so the SPIRE agent issues another workload's identity. The authors provide an open‑source tool, Spooffe, to test and validate exposure and recommend hardening nodes, restricting root access, and minimizing privileged containers to reduce risk.
read more →

Detection Wins When Defenders Carry Ground Truth

🕰️ The article compares the historical longitude problem to modern cybersecurity, arguing that carrying verifiable facts — like a ship’s chronometer — beats inference-based guessing. It contrasts attackers who infer organizational details from the outside with defenders who can maintain authoritative records of approvers, owned domains and vendors. The piece emphasizes that maintaining those facts is the hard work but that doing so reduces successful fraud and provides auditable reasoning for decisions.
read more →

Smashing Security Ep. 484: Tracking via Silence

🎧 Smashing Security episode 484 features Graham Cluley with guest Danny Palmer discussing how websites can track users through silent audio activity and other stealthy techniques. The episode also covers guidance from cyber intelligence agencies urging firms to avoid vague PR language after cyberattacks, and touches on recent incidents like ransomware and token theft. The hosts mix news with a light-hearted sound-identification segment before exploring the privacy implications of modern web tracking.
read more →

August 2026 Cyber Threat Landscape Overview

🔍 August 2026 saw rising cyber threats across multiple vectors, with weekly attacks per organization averaging 2,422 and ransomware incidents nearly doubling year over year. GenAI usage surged to 106 prompts per user, yet high-risk prompts persisted affecting 86% of GenAI-using organizations. Email phishing and regionally varied attack volumes further illustrate a broadening and intensifying risk environment that demands expanded governance and prevention.
read more →

Compromised Non‑Human Identities Outpace Phishing Risks

🔍 A new SpyCloud report finds compromised non-human identities (NHIs) — including AI agents, service accounts, API keys and tokens — accounted for 31% of intrusions versus 17% for social engineering. Based on a survey of 750 cybersecurity leaders across North America and Europe, the study highlights a gap between perceived and actual NHI visibility and monitoring. The report also notes weak AI governance, inconsistent third‑party identity checks, and elevated supply chain identity risk.
read more →

Non-Human Identities Now Primary Enterprise Risk

🔍 The SpyCloud 2026 Identity Threat Report finds non-human identities—AI agents, service accounts, API keys, and tokens—are now the leading path attackers use into enterprises. Despite 95% of organizations believing they have visibility into AI and machine identity exposures, only 36% actively monitor them. The survey of 750 cybersecurity leaders highlights gaps in governance, session monitoring, and third-party remediation, and shows automated continuous monitoring materially reduces incident impact. SpyCloud recommends pairing continuous exposure monitoring with automated remediation to lower event rates and costs.
read more →