< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 6 of 96

Practical pen testing for GenAI, LLM and RAG apps

🛡️ This article outlines a practical, application-focused approach to penetration testing GenAI systems, emphasizing that prompts can be attack vectors. It recommends mapping architecture components (prompts, retrieval, embeddings, tools, APIs), defining strict rules of engagement and using canaries and synthetic data. Testers should treat prompt injection as multi-turn campaigns, evaluate RAG/vector stores and upstream ML pipelines, and automate repeatable attacks with controlled Python harnesses to preserve evidence and enable regression testing.
read more →

Post-Quantum Cryptography and National Security Risks

🔒 Quantum computing advancements are turning theoretical cryptographic vulnerabilities into imminent threats, prompting an urgent shift to post-quantum cryptography (PQC). The technology will likely remain concentrated within nation-states and large corporations, creating adoption gaps among smaller organizations and critical infrastructure. This disparity could be exploited for intelligence collection, economic espionage, or prepositioning for conflict.
read more →

Safe word guidance to deter AI voice scams

🔒 AI-driven voice scams are increasingly common and convincing, lowering the barrier for fraudsters using deepfake audio. Scammers can clone a loved one’s voice from seconds of online recordings and use it in emotional schemes like virtual kidnappings. A simple, pre-agreed safe word between family members can effectively reveal fake calls, while backup steps include calling back on a known number and preserving evidence. If scammed, victims should stop contact, notify their bank, change passwords and report incidents to authorities.
read more →

GPUThor: Amplified Rowhammer Risk to GPUs

🔍 A University of Toronto paper describes GPUThor, an advanced Rowhammer-style attack targeting GDDR6 video memory on Nvidia Ampere accelerators. The researchers show a novel access pattern that defeats TRR mitigation by exploiting its refresh cadence, producing far more bit flips than prior GPU attacks. Results include large numbers of multi-bit errors and observed denial-of-service effects, though arbitrary code execution remains unproven. The work highlights ongoing risks to shared GPU infrastructure used in cloud and AI workloads.
read more →

From Prompting to Autonomy: Adversarial AI Trends

🛡️ Since the May 2026 report, Google Threat Intelligence Group (GTIG) observed adversaries shift from simple prompting to agentic AI workflows and AI-enabled automation, compressing defender response windows. In Q2 2026, threat actors executed an agent-enabled mass credential harvesting campaign within six hours and UNC6780 exploited AI coding assistants and LLM security scanners to compromise open source supply chains. GTIG also noted increasing targeting of proprietary AI models, exfiltration of API credentials, and misuse of cloud compute for unauthorized AI workloads.
read more →

Threat actors increasingly exploit AI coding tools

🔍 A Google Threat Intelligence Group (GTIG) report warns that AI-assisted coding tools have become a primary target for threat actors, contributing to large-scale software supply chain compromises in 2025–2026. GTIG highlights a financially motivated group, UNC6780, using Dustmaker malware to compromise PyPI, npm and Docker Hub packages, extract tokens from GitHub Actions runners, and hide malicious files in AI assistant workspaces. The report also describes espionage and extortion targeting proprietary AI research and models, and growing adversary experimentation with agentic AI to accelerate attacks.
read more →

Cloud Security Index Shows Provider Risk Divergence

🔍 Intruder's 2026 Cloud Security Index analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles differ dramatically by provider. Weak IAM and missing logging are nearly universal, while exposed services, permissive firewalls, weak encryption, and misconfigured services vary widely. AWS shows high prevalence in exposed services and permissive network controls, Azure's top issues center on storage and identity, and Google Cloud's dominant problems are IAM-related. Larger organizations generally have fewer exposure-style misconfigurations but worse IAM issues, and midmarket firms take the longest to remediate.
read more →

Attackers conceal phishing lures with invisible Unicode

🔍 Microsoft researchers revealed a large-scale phishing campaign that used ASCII smuggling by inserting invisible Unicode tag characters into finance-related lure words to evade email filters. The operation peaked at about 2.37 million daily messages in late February and remained active, though diminished, through May 2026. Messages relied on domains promoting funding and loans and were sent via infrastructure tied to the ActiveCampaign platform. Microsoft recommends normalizing or stripping tag-block and other invisible code points before applying keyword or AI-based detection.
read more →

Small coin-sized implant can subvert Boeing 737

🔎 Security researchers demonstrated a compact, coin-sized device that can be inserted into an externally accessible hatch on a Boeing 737 to interface with the ARINC 429 bus. The implant, assembled from off-the-shelf parts for under US$100, can inject false signals that alter takeoff/landing calculations, autopilot routes, and displayed data, while potentially hiding changes from pilots. Researchers disclosed the issue to Boeing in 2020 and recommended physical sealing, electrical protection, and cryptographic authentication as mitigations.
read more →

ThreatsDay roundup: phishing kits, AI risks, breaches

🛡️ This ThreatsDay bulletin surveys recent campaigns exploiting trusted tools and social engineering, from Microsoft Teams vishing to resilient phishing-as-a-service kits. It highlights ransomware affiliate playbooks, signed-software sideloading, a large ID-theft marketplace, and supply-chain risks tied to llms.txt misconfigurations. The report also notes Dropbox disclosed ~5,000 account compromises linked to legacy Lenovo IDs.
read more →

Behind the Intelligence: Investigative Tradecraft

🛡️ This edition of the Threat Source newsletter explains the hidden work behind producing usable threat intelligence, highlighting the investigative detours, persona-based adversary engagement, and the human behaviours that shape both attackers and defenders. It spotlights a Beers with Talos episode featuring Azim Khodjibaev, who maintained multiple personas to infiltrate dark-web communities, and raises concerns about AI guardrails that hinder defensive workflows during incidents.
read more →

ASCII smuggling used to evade phishing filters

🛡️ Microsoft researchers observed a high-volume phishing campaign that used invisible Unicode tag characters (U+E0000–U+E007F) — a technique popularized in AI prompt-injection research as ASCII smuggling — to split finance lure words and evade email filters. The activity spiked on February 9, 2026, and persisted on weekdays for about three months before declining. Microsoft Defender for Office 365 telemetry shows most messages were caught by layered protections rather than a single Unicode-specific signal. The tactic leverages invisible tag characters to disrupt tokenization and literal keyword matching, making it harder for ML/NLP-based filters to detect phishing lures.
read more →

Investigation of Amazon Bedrock LLMjacking Incident

🛡️ FortiGuard Labs examines an AWS incident where a long-lived IAM access key with Administrator privileges was abused to create identities, subscribe to foundation models on AWS Marketplace, and invoke those models for profit. The report outlines the concept of LLMjacking, the steps observed in the compromise, and why valid cloud credentials make detection challenging. It also lists FortiCNAPP (Lacework) detections and recommended posture changes to reduce risk.
read more →

Researching employment scams and insider risks

🔎 Impressive and sobering work highlights the need for rigorous background checks and continuous verification for remote employees. The analysis emphasizes vigilance for signs of insider threats, noting that operatives can blend into organizations for months or years while exfiltrating data or preparing theft. The use of controlled sandbox environments demonstrated how deep visibility and proactive investigation can disrupt such campaigns before they inflict real harm.
read more →

Shai‑Hulud Infostealer Expands Credential Reach

🔍 GitGuardian researchers observed a Shai‑Hulud infostealer worm variant in August that now scans 469 locations for credentials across developer environments, CI/CD tooling, cloud configs, and AI tool settings. Earlier variants checked 189 paths, indicating attackers increasingly hunt for existing reusable authority rather than breaking trust relationships. Defenders are urged to prioritize removing long‑lived publishing tokens, adopt short‑lived identity‑backed publishing, and treat secrets detection as credential risk management.
read more →

INTERPOL: Cybercrime Industrialization Threatens Africa

🔎 INTERPOL’s African Cyberthreat Assessment Report 2026, with contributions from FortiGuard Labs, finds cybercrime in Africa has shifted into an industrialized, borderless ecosystem driven by specialized service providers, shared infrastructure, automation, and AI. The report links rapid digital adoption to rising exploitation, noting reported losses doubled from 2024 to 2025 and credentials are often the initial foothold. It calls for integrated identity-centric defenses, faster intelligence-to-protection workflows, and stronger public-private collaboration to enable disruption.
read more →

When the patch tsunami meets maintenance windows

🔧 AI-driven vulnerability discovery has collapsed discovery timelines from months to hours, but operational technology (OT) remediation still moves at plant speed. OT systems face physical, economic and contractual constraints that make rapid patching impractical, so defenders must prioritize containment, compensating controls and documented retirement plans. Preparation, vendor engagement and exercised surge plans are essential.
read more →

AI-assisted exploit development threatens industrial control

🔎 Researchers at Forescout evaluated how large language models aid ICS vulnerability research by attempting to port an exploit between PLC models. They found AI could combine reverse-engineering tools, generate analysis scripts, and produce working exploit code, but the process still required substantial human guidance and took 8.5 hours. While not yet enabling unskilled attackers, AI can lower the time and expertise barrier for experienced embedded-systems hackers and may change attackers’ ROI for targeting complex low-level flaws.
read more →

Threat actors favor repeatable playbooks over novelty

🔍 Microsoft and Bitdefender telemetry show attackers increasingly rely on simple, repeatable methods such as ClickFix and living-off-the-land techniques rather than bespoke exploits. These approaches scale because they are platform-agnostic, require no new tooling, and reuse built-in binaries and publicly released exploits. The result is higher throughput of incidents with falling per-victim returns, incentivizing low-cost, repeatable campaigns.
read more →

Securing Water Sector Infrastructure in the AI Era

🔒 This Cloud CISO Perspectives issue outlines the rising cyber risks to water utilities and presents practical, prioritized steps for OT and IT leaders. It emphasizes basic cybersecurity hygiene—asset inventory, replacing default credentials, backups, segmentation, and vendor access controls—while urging incident planning integration with existing all-hazards systems. The piece also highlights the role of AI as a force multiplier for defenders and the need for unified governance between IT and OT.
read more →