< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 7 of 96

Monthly security roundup: August 2026 highlights

🔍 ESET Chief Security Evangelist Tony Anscombe reviews the major cybersecurity stories from August 2026, summarizing incidents that should concern businesses and critical infrastructure operators. He covers an OpenAI agent breach affecting Hugging Face, Iran-linked attacks on water and power systems, a Delta Airlines in‑flight Wi‑Fi spoofing report, and a Ukrainian takedown of fraudulent call centres. The video outlines lessons and mitigation steps for organizations.
read more →

Preparing cloud security for AI-driven attack agents

🔒 Cloud architectures built to resist human attackers now face a new class of threat: autonomous AI agents that can enumerate identities, chain misconfigurations, and exploit paths at machine speed. Recent incidents, including the OpenAI–Hugging Face example, illustrate how agents can escalate privileges by combining otherwise low-severity flaws. Experts warn organizations must shift from point-in-time vulnerability scanning to continuous, graph-based attack-path validation, enforce ephemeral credentials and strict workload identities, and adopt account-level segmentation to reduce blast radius.
read more →

Exotic file formats create detection blind spots

🛡️ This article examines how threat actors increasingly use less-obvious file types to bypass defenses and deliver malware. It outlines disk image formats (ISO, IMG, VHD, VMDK) that mount natively and can evade scanning, Office-related formats like .one and .xll that hide scripts or DLLs, and SVG files that can contain JavaScript. The piece also describes polyglot files and a notable IcedID campaign that chained ZIP→ISO→CHM→mshta to deploy payloads, and stresses the need for comprehensive scanning of these formats by security tools.
read more →

Why Identity Fabric Matters for Modern Security

🔍 An Identity Fabric unifies fragmented identity systems to provide runtime visibility across applications, APIs, and infrastructure. It bridges design-time policies with runtime behavior to reveal identity drift, orphaned credentials, and unobserved attack paths. The approach is essential for hybrid and multi-cloud environments, especially to govern non-human and AI identities and enable continuous least-privilege enforcement.
read more →

Designing Systems to Earn Customer Trust

🔒 Over years of building large-scale personalization and commerce systems, the author argues that compliance alone does not create customer trust. Real trust comes from ensuring customer intent is respected across distributed services, caches, pipelines and AI systems. The piece highlights five priorities: consistent customer intent, privacy as a distributed-systems problem, data minimization, designing for failure, and understanding AI's expanding trust boundary. Security leaders are urged to treat trust as an architectural and operational priority, with observability and metadata-driven controls.
read more →

CTEM reshapes continuous exposure and risk management

🔍 Continuous Threat Exposure Management (CTEM) expands traditional vulnerability management by delivering ongoing visibility across endpoints, networks, identities, cloud, applications, and users. It emphasizes broader scope, exploitability validation, and accountability for remediation to close real attack vectors rather than just tally vulnerabilities. Automation and contextual intelligence are core to CTEM, but human oversight remains essential. Teams must overcome tool fragmentation, organizational silos, and cultural resistance to adopt CTEM as an operational model rather than a single product.
read more →

What to do if you find someone’s bank card

🧾 Found a bank card? Don’t post photos or hand it to strangers. Contact the issuing bank, report the card as found, and then destroy it to prevent fraudulent use and avoid becoming a person of interest. For multi-use cards tied to schools or transit, return them to the institution’s office or security. Avoid keeping the card or leaving it where anyone can pick it up.
read more →

Weekly ThreatsDay: Botnets, Stealers, and RATs

🔍 This week’s ThreatsDay roundup highlights diverse active campaigns and new tooling, from a 296,000‑device IoT botnet to live operator phishing frameworks and AI‑assisted botnet orchestration. Researchers observed trojanized Electron apps, new stealers and RATs, a Rust backdoor tied to ransomware, and a loader using blockchain for C2. Also covered: a social‑engineering incident at ReliaQuest, an Android fraud bot for rent, and an unpatched disk‑encryption bypass in HP ThinPro.
read more →

Understanding JavaScript Obfuscation in Threats

🔎 This Talos blog post explains how obfuscated JavaScript transforms readable code into string arrays, encoded values, runtime decoders, and eval calls, making static reading ineffective. The author outlines common benign and malicious motivations for obfuscation and stresses safe handling: work on copies, avoid executing hostile scripts in useful environments, and use isolated analysis. The article introduces categories of techniques—string hiding, lookup tables, dynamic property access, dead code, runtime code generation, control-flow flattening, anti-analysis measures, and extreme forms like JSFuck—and offers practical counters like beautification, renaming, replacing execution sinks with logging, and using controlled runtime harnesses or headless browsers to recover payloads. It warns about automated obfuscators (npm packages) and Node-specific risks such as access to secrets, and emphasizes a structured, repeatable workflow that leverages tooling and AI on isolated snippets.
read more →

GPUThor Rowhammer Breaks ECC on NVIDIA Ampere GPUs

🛡️ Academic researchers disclosed GPUThor, a Rowhammer attack that induces widespread bit flips on NVIDIA Ampere-class workstation GPUs with GDDR6, defeating recommended ECC mitigations and enabling denial-of-service and host privilege escalation. The University of Toronto team hammered DRAM banks for extended periods on multiple RTX A-series cards, producing up to 377,552 flips per gigabyte on an A5000. The exploit requires running an unprivileged CUDA kernel and the researchers advise avoiding cross-tenant GPU sharing, monitoring ECC counters, and restricting untrusted CUDA workloads.
read more →

Four in Five AI Tools Operate Without IT Oversight

🔍 Security researchers warn major gaps in IT oversight and rising vulnerabilities are increasing risk across the AI agent ecosystem. Reco analyzed enterprise telemetry, MCP servers, and NVD disclosures in its report, The State of Agent Security 2026, finding 80% of AI tools lack governance and SMBs average 414 unsanctioned tools per 1,000 employees. The study found many MCP servers allow shell execution, file access and outbound network calls, with numerous tools exposed without authentication. Vulnerability disclosures have also surged, straining patch programs.
read more →

Cyber insurance claims costs rise despite fewer incidents

📈 Chubb’s 2026 Cyber Claims Report shows that average costs per cyber insurance claim rose markedly in 2025 even as claim volumes fell for large and middle-market companies. The insurer attributes the growing severity to higher data breach and privacy litigation costs and increased business interruption expenses. Regional differences were clear: the US saw much higher average costs than the UK and Europe, partly due to sizable third-party litigation expenses. SMEs experienced mixed trends, with claim frequency rising but costs moving in opposite directions across regions.
read more →

AI accelerates attacks on exposed internet-facing servers

🔍 Cisco Talos reports a Chinese-speaking cybercrime group, tracked as UAT-10147, is using AI-driven tools to compromise internet-facing Windows and Linux web servers. Researchers found AI-generated operational guidance, tooling to refine exploits, and automation that accelerates post-access activity, with a target list of about 170,000 URLs. The group exploits publicly disclosed vulnerabilities for financially motivated goals like data theft and SEO fraud.
read more →

AI-Enabled Malware: Prevalence, Detection, and Trends

🛡️ Palo Alto Networks Unit 42 analyzed 405 AI-integrated malware samples to measure real-world prevalence and detection efficacy. The dataset spans proof-of-concept code, security testing submissions, and AI-branded malware, but only 12 samples appeared on Cortex XDR-protected endpoints. Existing layered defenses — including behavioral analytics, WildFire sandboxing, and endpoint telemetry — detected and blocked all observed production samples.
read more →

Top AI Power Users Cast Outsized Enterprise Risk

🔍 New research from Akamai reveals that the top 5% of enterprise AI power users interact with models at roughly 12x the rate of the bottom 50%, creating disproportionate security exposure. These super-adopters embed unvetted tools, browser/IDE extensions, and autonomous agents into workflows, widening shadow AI, data leakage, and attack surfaces. Akamai’s report highlights governance gaps from personal logins to vulnerable extensions and offers a CISO checklist to regain visibility and control.
read more →

Protecting Windows Named Pipes from Local Abuse

🔒 Named pipes are commonly used for interprocess communication on Windows but should never be treated as implicitly trusted. Developers often assume local IPC is safe, yet different users, sessions, and privilege levels may run on the same machine. Servers must verify client identities, apply explicit DACLs, authorize each operation, and validate message contents to avoid privilege escalation, confused-deputy issues, and denial-of-service. Remote accessibility and predictable pipe names further increase risk, so implement strict limits, timeouts, and local-only protections.
read more →

Supply Chain Risks in the Modern SDLC

🔍 Unit 42 details how supply chain attacks have escalated, shifting adversaries from finished applications to the developer tooling and CI/CD pipelines that build software. The report examines incidents like ChainDrop, Axios, and Shai-Hulud to show how malicious preinstall scripts, account hijacks, and memory scraping steal credentials and self-propagate. It argues that SBOMs alone are insufficient and recommends continuous visibility, execution controls, ephemeral CI servers, and short-lived credentials to stop autonomous malware.
read more →

Risk-First CISO Approach to Prioritizing AI Risks

🔒 AI gives defenders powerful discovery tools but grants attackers the same advantages, forcing CISOs to manage AI risks both externally and internally. External threats include AI-enhanced phishing, rapid exploit development, and autonomous agent attacks, while internal risks arise from uncontrolled employee use of consumer AI platforms, shared copilots, and compromised API billing. The author advocates a Risk-First approach: map AI use, prioritize controls like RBAC and data classification, improve continuous testing, and run tabletop exercises to prepare for AI-specific failures.
read more →

Ransomware Forces Shift Toward Enterprise Resilience

🔒 Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more →

ThreatsDay: Signed Drivers, AI Risks, and RCEs

🛡️ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more →