< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports

1783 articles · page 6 of 90

Q2 2026 Brand Phishing: Top Impersonated Companies

📊 Microsoft remained the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts. The top five—Microsoft, LinkedIn, Google, Apple, and Amazon—accounted for over half of observed attacks, while ChatGPT entered the top ten for the first time. Technology, social networks, and banking were the most targeted industries, and common tells included distorted logos, dead buttons, and mismatched links.
read more →

Synthetic Machine Identity Fraud and Emerging Risks

🔒 Synthetic identity fraud for machines involves attackers fabricating service accounts or credentials rather than stealing existing ones. These fabricated NHIs blend real environmental attributes with fake data to appear legitimate, evading detection because no human owner flags misuse. Techniques include rogue service accounts, DCShadow-style fake domain authorities, and shadow credentials implanted into existing objects. Defenses focus on ownership, secrets rotation, least privilege, and continuous behavioral verification.
read more →

AI agents under attack: incidents and risks 2026

🔍 Enterprises face rising attacks that exploit AI agents already present in their environments. These agents — coding assistants and CLI tools like Claude Code CLI, Gemini CLI, and Amazon Q CLI — can read files, run commands, and install packages, making them attractive targets when run with auto-approval. Real-world incidents, including the s1ngularity Nx npm compromise and the AgentJacking/Sentry experiments, show how prompt injection, compromised tool metadata, and unsecured MCP servers can lead to secret harvesting and covert exfiltration. Defenders must treat agents as potentially untrusted and adapt controls and monitoring accordingly.
read more →

AI Empowers More Convincing Ransomware Attacks

📈 A Proofpoint survey shows AI has materially increased ransomware effectiveness by enabling more convincing phishing, impersonation and credential-theft campaigns. The 2026 AI-Era Ransomware Report found AI involvement common across incidents and identified human interaction—malicious links, attachments and credential harvesting—as frequent entry points. Respondents cited legitimate-looking lures and control failures as key reasons attacks bypassed defences.
read more →

Eclypsium InfraTrust highlights top infrastructure fixes

🛡️ Eclypsium launched InfraTrust and a monthly InfraTrust Pulse to aggregate vendor infrastructure advisories and guide administrators on which flaws to patch first. The inaugural July 2026 Pulse tracked 61 advisories from 14 vendors, flagging six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities. The report emphasizes prioritizing flaws by exploitability, exposure, and real-world risk rather than CVSS alone.
read more →

2026 Exposure Gap Report: Remediation Insights

🔍 The 2026 Exposure Gap Report finds that while many organizations can identify and prioritize exposures, turning those insights into timely remediation is inconsistent. Some sectors, like Utilities, remediate in roughly 12.6 hours, whereas Healthcare averages about 158 hours. The report highlights that delays often begin before remediation—during validation and ownership assignment—and that connected workflows enable faster, repeatable remediation at scale.
read more →

Ransomware Landscape Expands with New Groups Weekly

🛡️ The Black Kite Ransomware Report 2026 finds 146 active ransomware groups as of June 2026, up from 105 a year earlier, with 61 new groups emerging in 2026 alone. The study highlights a fragmented ecosystem where groups often have short lifespans—averaging 4.9 months—and a small number of operators still account for a large share of disclosed victims. Black Kite urges organizations to prioritize rapid patching of critical vulnerabilities and strengthen identity and vendor controls to mitigate attacks.
read more →

Global Internet Traffic Shifts During the 2026 World Cup

📈 Cloudflare Radar analyzed HTTP, DNS, and security signals across its global network during the June–July 2026 World Cup to measure how matches changed Internet activity. Using a four-week median baseline and log2 ratios, the study compared per-country deviations by kickoff time, revealing large spikes for overnight matches and smaller evening bumps. The report ranks matches and teams by worldwide impact and examines regional behaviors, streaming effects, and distinct halftime and hydration-break patterns.
read more →

Open-source Android AI agents enable host command risk

🛡️ Researchers demonstrated seven attacks against five open-source Android agent frameworks, showing that benign-seeming apps with draw-over and storage permissions can inject unseen text into models and escalate to host command execution. The study, posted on arXiv in July, tested AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA, finding widespread vulnerabilities including screenshot race conditions, command injection via unsanitized adb calls, broadcast leaks, and UI spoofing. Some projects already use safer patterns, but none implemented all recommended mitigations.
read more →

Bit2Watt: GPU workloads can threaten power grids

⚠️ Three Zhejiang University researchers describe "Bit2Watt," a technique showing that ordinary GPU workloads can be modulated to produce fast, controllable power oscillations. They demonstrate two methods: a synthetic kernel (SWMA) that toggles compute intensity and an LLM-training modulation (LTMA) that embeds oscillations into real training runs. Experiments measured kHz-range power components on GPUs and simulations showed that synchronized modulation across many devices could destabilize local grids and create denial-of-service or covert channels. The work highlights a visibility gap between compute and power operators and suggests combined hardware and monitoring defenses.
read more →

Weekly cyber recap: critical bugs, active exploits

⚠️ This week saw small inputs produce severe outcomes: unauthenticated RCEs in WordPress Core, SonicWall SMA zero-days exploited in the wild, OpenSSL DoS via an 11-byte payload, and a SharePoint RCE added to CISA's KEV catalog. Other notable items include the OkoBot malware framework targeting crypto wallets, the NadMesh botnet harvesting cloud keys, and a long list of high-priority CVEs that require immediate patching and investigation.
read more →

Exposure Window: The Metric That Really Matters

🛡️ This piece examines how Anthropic's Mythos accelerated vulnerability discovery but did not create the core problem: the exposure window. It explains that while AI has pushed discovery and prioritization to machine speed, mobilization—the organizational steps to actually fix vulnerabilities—remains slow. The article argues security teams must adopt speed-based metrics and attack-path analysis to reduce the blast radius and convert remediation into a measurable business risk.
read more →

AI Increases SOC Strain, Forcing Operational Change

🔍 Security operations centers (SOCs) are confronting rising alert volumes, faster AI-enabled vulnerability discovery, and increasing machine-generated outputs that create new cognitive burdens for analysts. Experts warn AI amplifies existing weaknesses—staffing shortages, alert fatigue, and technical debt—while also offering tools to manage scale. Mature SOCs with robust processes may adapt, but less-prepared teams risk burnout and overwhelm.
read more →

Search for Clean Residential Proxies in Carding

🔍 Flare researchers examined nearly 2,900 underground posts to map how carders assess residential proxies and build fraud-ready digital identities. The analysis shows proxies are judged by reputation and history rather than just being residential, and are commonly paired with antidetect browsers, device fingerprints, and billing consistency. Providers’ restrictions and takedowns have pushed demand for “finance-compatible” IPs and increased operational complexity for attackers.
read more →

Alan Turing’s World War II Voice Encryption Revealed

📜 Newly surfaced wartime papers, sold as the “Bayley papers” in November 2023, reveal details of Alan Turing’s top-secret 1943–1945 voice-encryption project called Delilah. The cache includes handwritten notes by Turing and annotations by his assistant Bayley, who preserved the documents until his death in 2020. The material outlines a portable system for encrypting speech and provides rare engineering insight into Turing’s wartime cryptologic work.
read more →

The Gentlemen Tops Ransomware Incidents in Q2

🛡️ ReliaQuest's July analysis shows The Gentlemen ransomware gang conducted 300 attacks in the three-month period, surpassing Qilin's 289 incidents. Researchers tracked 1,368 victim claims across 99 countries from 11 ransomware groups, with DragonForce, Akira and LockBit also active. ReliaQuest attributes The Gentlemen's rise to aggressive affiliate recruitment, pre-packaged intrusion kits and AI-accelerated tooling.
read more →

The SaaS blind spot: visibility gaps in cloud apps

🔍 Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps — audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews — can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more →

ACR Stealer campaigns use ClickFix lures and fileless tradecraft

🔍 Microsoft Defender Experts observed heightened ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering to lure users into running commands that ultimately harvest browser credentials, tokens, and sensitive documents. Two prevalent campaigns were detailed: one using WebDAV-delivered DLLs, staged PowerShell, Python loaders, and optional blockchain-backed dead-drop C2 resolution; the other using fileless MSHTA, obfuscated PowerShell, and steganography-assisted in-memory execution. Both aim to exfiltrate credentials and enterprise data, and Microsoft recommends monitoring for ClickFix lures, suspicious WebDAV/MSHTA activity, obfuscated PowerShell, and attempts to access browser credential stores while leveraging Defender capabilities to detect and respond.
read more →

Unit 42 2026 IR Report: AI as an Attack Multiplier

🔍 Unit 42’s 2026 Global Incident Response Report examines how AI is accelerating and streamlining attacker operations. Drawing on hundreds of engagements, the report finds AI shortens development cycles and automates reconnaissance while core attack techniques remain consistent. It stresses defenders can apply existing controls but should prioritize prevention and AI-aware skills.
read more →

AI as a Force Multiplier in Incident Response

🔍 Unit 42’s 2026 Global Incident Response Report examines how threat actors integrate AI to accelerate attacks. Drawing on hundreds of engagements, the report finds AI shortens development cycles, automates content generation and streamlines reconnaissance, compressing attack lifecycles. Despite this speed, adversaries continue to rely on established TTPs like credential theft, phishing and ransomware, meaning defenders can apply existing controls while adapting to AI-driven efficiencies.
read more →