< ciso
brief />
Threat and Trends Reports Banner

All news in category “Threat and Trends Reports”

1913 articles · page 9 of 96

Talos Threat Source: Phishing Frameworks and Trends

📰 Cisco Talos highlights a newly discovered real-time phishing framework named JWR, likely related to The Outsider phishing-as-a-service. JWR uses WebSockets to capture live keystrokes and steer victims through fraudulent checkout and login flows, often delivered via SMS lures impersonating toll or postal authorities. Operators can harvest payment data, 2FA codes, identity documents, and device fingerprints, enabling MFA bypass and extensive follow-on fraud. Talos recommends user education on smishing, monitoring for unusual authentications, and adopting phishing-resistant MFA like FIDO2.
read more →

AI watermark removers proliferate with unverifiable claims

🛡️ A rapid market has emerged for tools claiming to remove invisible AI watermarks after Anthropic enabled hidden marks in Claude outputs. Some projects strip metadata and hidden characters reliably, but none can currently be proven to defeat Anthropic's model-level watermark because the vendor has not published the detector or full technical details. Many commercial sites promise full removal, often measuring results against ordinary AI detectors rather than the undisclosed Claude watermark; independent code review shows gaps and unaddressed payloads. The ecosystem — open repos, web tools and agent skills — creates a potentially risky supply-chain surface if integrated directly into pipelines.
read more →

Ransomware Q2 2026: Spread and Shifting Threats

🔍 Data leak sites recorded 2,139 ransomware victims in Q2 2026, effectively flat versus Q1 and up 33% year over year. The top 10 groups still accounted for most victims, but active groups rose to a record 93. Leaked chats from The Gentlemen showed a nine-person core using AI coding tools to rapidly build a top-tier operation, highlighting the need to prioritize initial access, exfiltration detection, and exposure reduction.
read more →

July 2026 Cyber Threats: Ransomware and GenAI Risks

🔒 July 2026 saw a marked uptick in cyber incidents, with weekly attacks averaging 2,336 per organization and ransomware victims rising sharply. Education, Latin America, and Business Services were among the most affected, while GenAI use exposed sensitive data through risky prompts. Email remained a primary entry point as organizations confront multi-vector threats and growing operational exposure.
read more →

Perimeter Recovery Masks Weak Interior Defenses

🔍 Picus Labs' Blue Report 2026 shows perimeter defenses improved in H1 2026, with prevention rising to 69% and logging at a four-year high of 58%. However, post-compromise prevention inside networks remains weak at 37%, and quiet techniques like reconnaissance and credential theft largely evade controls. The findings highlight signature-dependent gaps and declining IOC-based prevention, urging validation of exposures and stronger detection engineering.
read more →

Legacy software bugs that lingered for decades

📰 This article reviews a series of long-dormant vulnerabilities—some more than 30 years old—unearthed and finally patched in recent years. It highlights how AI-powered analysis and deep inspections have accelerated the discovery of latent flaws across widely used projects such as libpng, PostgreSQL, Nginx, and the Linux KVM module. The piece explains the origins, exploitation risk, and remediation status of each bug, emphasizing supply-chain and infrastructure impacts and urging administrators to apply available patches.
read more →

Cloudflare: Massive rise in >1 Tbps DDoS attacks

🛡️ Cloudflare reported it mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, a more than fivefold increase from Q1's 130 such events. The company, which protects roughly 20% of the web, also defended against a record 31.4 Tbps attack by the Aisuru/Kimwolf botnet. In H1 it mitigated 23.2 million network-layer attacks and handled 29.64 trillion malicious HTTP requests, while noting most attacks remained small and short-lived.
read more →

Cloudflare DDoS Threat Report H1 2026 Summary

📊 Cloudflare's H1 2026 DDoS Threat Report from Cloudforce One summarizes DDoS activity across January–June 2026. The report details mitigation of 23.2 million network-layer attacks and 29.64 trillion HTTP requests, highlights April as a peak month, and describes growth in hyper-volumetric and reflection-based vectors like CLDAP. It emphasizes the necessity of automated, always-on protection.
read more →

Using GitHub telemetry as an EDR-style detector

🔍 Researchers at Black Hat USA 2026 demonstrated that GitHub’s native telemetry can be used like an EDR to detect supply-chain attacks by monitoring event streams, webhooks, API data, and Git history. Their open-source GitHub Threat Detector implements behavioral detections from recurring attacker techniques—such as forged commit metadata, mass tag poisoning, workflow abuse, and OIDC token misuse—into correlated rules. The tool uses a PostgreSQL-backed activity store for historical correlation and includes production and beta detection rules, though it faces practical limits from disabled webhooks and API rate limits.
read more →

UK Manufacturing Cyber Resilience Falls Short

🛠️ A new Make UK report finds that around 30% of UK manufacturers experienced a cyber incident in the past year, often through their supply chain. The study highlights significant operational and financial impacts, including production delays and material shortages, while many firms still lack formal response plans, CISO roles or clear cyber insurance coverage. The report urges board-level attention and improved supplier assurance.
read more →

Weekly recap: AI autonomy, Metabase zero-day

⚡ This week’s recap highlights AI models acting autonomously to target open-source projects, a critical zero-day in Metabase allowing unauthenticated SQL injection, and new CPU-level attacks bypassing Spectre v2 defenses. It also covers webmail CSS attacks, vishing campaigns by UNC6671 against financial firms, Chinese router backdoors in Zbtlink devices, and shifting ransomware behaviors.
read more →

Rise of polyglot file attacks and defenses

🛡️ Files created with the polyglot technique are increasingly used in cyberattacks to evade filters and confuse investigators. Attackers craft files that can be interpreted as multiple formats (for example, PNG or ZIP) so different applications or scanners see different contents. Real-world campaigns have used EXE/ZIP, PDF/DOC, MSI/JAR, DLL/HTML and multi-archive polyglots to deploy malware like PhantomPyramid, StrRAT, Ratty and IcedID. Defenses rely on consistent security hygiene and targeted testing of detection tools.
read more →

SOC playbook for OAuth client ID spoofing detection

🔎 This article explains how OAuth client ID spoofing can evade per-application volume thresholds by rotating or fabricating the client ID field, turning valid credential checks into stealthy attacks. It outlines key Entra ID error codes (AADSTS50034, AADSTS50126, AADSTS700016) and shows why AADSTS700016 paired with many distinct client IDs is a critical triage signal. The piece describes two large campaigns that produced millions of spoofed IDs, provides a Kusto detection query to correlate cardinality and error sequences, and recommends a short response runbook (reset, revoke, review) plus long-term mitigation by retiring ROPC.
read more →

Seven key trends shaping the cybersecurity market

🛡️ AI is reshaping the cybersecurity market as VC funding soars and incumbents race to integrate agentic AI features, driving robust M&A activity. New AI-centric product categories such as LLM security, model integrity, and AI governance are emerging while platforms and managed services gain momentum. Quantum security and DSPM are rising priorities as organizations seek integrated, AI-native defenses.
read more →

Real emails and clipper attacks hijacked payments

🛡️ Gen Threat Labs examined two H1 2026 campaigns where attackers used legitimately compromised accounts and local system manipulation to intercept payments. The first campaign abused corporate mailboxes to deliver JavaScript droppers that progressed through PowerShell and shellcode to modify proxy and browser settings for banking fraud. The second used a Rust-based clipboard clipper that replaced copied crypto addresses and read C2 pointers from Binance Smart Chain smart-contract data.
read more →

AI-driven HTTP desync research uncovers new techniques

🛡️ PortSwigger's AI-assisted system HTTP Terminator, developed by James Kettle, autonomously generated and validated novel HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. The team also ran a human-guided cascade that discovered a now-patched zero-day in Apache Traffic Server (CVE-2026-63078) and reported findings across banks, government infrastructure, and security products. PortSwigger released the tool as open source and recommends avoiding HTTP/1.1 upstream or tightly allow-listing methods where removal isn't possible.
read more →

Common dangerous file extensions used in email attacks

🛡️ Cybercriminals frequently disguise malicious files as benign documents or archives to trick recipients into executing malware. Kaspersky researchers analyzed malicious email blasts from early 2026 to identify the 15 most abused extensions — from .exe, .dll and .scr to script, web, archive, and Office formats. The report explains how double extensions, hidden extensions, macros, embedded scripts, and password-protected archives are used to evade detection and deliver payloads. It emphasizes keeping software patched, disabling unnecessary macros and scripts, and using advanced security solutions to detect disguised threats.
read more →

Rising Costs and AI Risks in Data Breaches

🔍 IBM’s 2026 Cost of a Data Breach report, from March 2025 to February 2026, finds the average breach cost rose to $6 million, with AI-enabled attacks comprising one in four incidents. The study of 600 organizations highlights that AI both increases attack speed and, when used defensively, can reduce costs by nearly $2 million. Key issues include poor access controls for AI models, compromised APIs and cloud misconfigurations, and long detection-to-containment times that inflate costs.
read more →

Ransomware Incidents Spike 19% in July 2026

📈 Comparitech's July analysis found ransomware attacks rose 19% month-on-month, with 799 claimed incidents making July the second busiest month of 2026. Finance, technology, healthcare and education saw the largest increases, and US-targeted attacks jumped 31% from June. The Gentlemen and Qilin groups accounted for a third of attacks, while notable incidents included disruptions to a US healthcare provider and Romania's land registry.
read more →

Why exposure management is replacing vulnerability management

🔍 Traditional vulnerability management finds issues, but that doesn't equal reduced risk. Modern environments are interconnected, and attackers chain weaknesses, identities, and permissions to reach valuable targets. The Gartner CTEM framework shifts the focus from individual findings to the broader exposures attackers can exploit. Organizations must prioritize reducing exposure, not just counting or patching vulnerabilities.
read more →